Lee Parkes <[EMAIL PROTECTED]> writes:

>A colleague of mine is locked in a battle with a client about the use of NULL
>ciphers for OpenSSL. The client claims that he has/wants to allow NULL
>ciphers so that people in countries that ban the use of crypto can still use
>the website. My colleague wants to know if there is a list of such countries
>that he could use.

I've had a similar debate with banking users who only wanted integrity
protection and didn't care about confidentiality (or at least they didn't want
to invest the CPU time to provide confidentiality, since for their application
it wasn't warranted).


