You might like to try the following references: SSL and TLS: Designing and Building Secure Systems -- by Eric Rescorla
Eric also wrote the informational "RFC HTTP Over SSL" ftp://ftp.isi.edu/in-notes/rfc2818.txt The IETF RFC for TLS is at ftp://ftp.isi.edu/in-notes/rfc2246.txt The RFC 2459 "Internet X.509 Public Key Infrastructure Certificate and CRL Profile ftp://ftp.isi.edu/in-notes/rfc2459.txt is useful. William Stallings is also a worthy reference - he published a helpful description of SSL a few years ago - Cisco published it in the IPJ - http://www.cisco.com/warp/public/759/ipj_1-1/ipj_1-1_SSL1.html. Microsoft have a version of it as well. Thanks & regards, Joe Otway __________________________________________________ Information Security Architect CSC Floor 15, 140 St George's Tce, Perth WA 6000, AUSTRALIA Ph: + 61 8 9327 8538 Mobile: + 61 04 07 021 188 Fax: + 61 8 9327 8417 Email: [EMAIL PROTECTED]
