On Mon, Dec 20, 1999 at 02:22:14AM -0500, Vin McLellan wrote:
> Without some alternative mode of server authentication, of course,
> Anon DH remains a pretty scary proposition -- all the more so because it
> implies a level of trustworthiness that it can not provide.
There is no reason for servers to refuse to negotiate Anon DH ciphers
if the client has those in the list of ciphersuites, unless client
verification has been requested (which, for unknown reasons, is not
allowed for these ciphersuites). Also, in theory, nothings speaks
against clients having Anon DH in their ciphersuite list unless server
authentication has been requested, but then as a measure of "security
by obscurity" most client programmers would not like the software to
reveal in the client hello message that they are not doing server
authentication.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]