Re: [apache-ssl] Session cache security

1999-03-13 Thread Ben Laurie
Holger Reif wrote: > > Ben Laurie schrieb: > > > > Bodo Moeller wrote: > > > > > > How are things in Apache-SSL with respect to the potential problem > > > discussed below? > > > > I don't believe it is necessary to take any action for various reasons. > > The most obvious is that if guessing ses

Re: [apache-ssl] Session cache security

1999-03-12 Thread Holger Reif
Ben Laurie schrieb: > > Bodo Moeller wrote: > > > > How are things in Apache-SSL with respect to the potential problem > > discussed below? > > I don't believe it is necessary to take any action for various reasons. > The most obvious is that if guessing session IDs gets you anywhere, > you've g