Berend De Schouwer wrote:

>Don't you only need a little bit for the key?  128bit encryption is slow
>enough for a file system.
>
The default size of the RSA key signature generated by the 'ipsec 
rsasigkey' is 2048 bytes, I think.  I suppose that would fit on the BOOTROM.

>>>The mkinitrd already allows ip=rom or
>>>somesuch, so maybe the TFTP kernel can grab a key that way.
>>>
>
>Sorry, I should have said mknbi-linux.
>
>>I would see this as being even more insecure than local storage. 
>> Someone can simply sniff the traffic for the ENCRYPTION key being sent 
>>to the client IN THE CLEAR.  Right?
>>
>
>No.  That is if its DHCP.
>
Well, you originally appeared to want to do it via a TFTP transfer of 
the encryption key for the workstation to use.  I suppose that would be 
necessary if the workstation has no local storage.  But unless there is 
a way to do TFTP encrypted somehow, then there is no point to sending 
the key in the clear.

-- 
Jason A. Pattie
[EMAIL PROTECTED]



_____________________________________________________________________
Ltsp-discuss mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help,   try #ltsp channel on irc.openprojects.net

Reply via email to