Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-23 Thread Gary Hook
For me... On 10/21/14, 1:30 PM, Wouter Verhelst w...@uter.be wrote: Hi Markus, On Tue, Oct 21, 2014 at 10:17:17AM +0200, Markus Armbruster wrote: Misunderstanding. I didn't mean to claim STARTTLS is bad. If I wanted to say that, I would've said it directly. I was merely asking how you

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-21 Thread Markus Armbruster
Wouter Verhelst w...@uter.be writes: On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: Stefan Hajnoczi stefa...@redhat.com writes: On Mon, Oct 20, 2014 at 08:58:14AM +0100, Daniel P. Berrange wrote: On Sat, Oct 18, 2014 at 07:33:22AM +0100, Richard W.M. Jones wrote: On

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-21 Thread Wouter Verhelst
Hi Markus, On Tue, Oct 21, 2014 at 10:17:17AM +0200, Markus Armbruster wrote: Wouter Verhelst w...@uter.be writes: On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: [...] Furthermore, STARTTLS is vulnerable to active attacks: if you can get between the peers, you can make

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-20 Thread Wouter Verhelst
On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: Stefan Hajnoczi stefa...@redhat.com writes: On Mon, Oct 20, 2014 at 08:58:14AM +0100, Daniel P. Berrange wrote: On Sat, Oct 18, 2014 at 07:33:22AM +0100, Richard W.M. Jones wrote: On Sat, Oct 18, 2014 at 12:03:23AM +0200,