Berend De Schouwer wrote:
>Don't you only need a little bit for the key? 128bit encryption is slow
>enough for a file system.
>
The default size of the RSA key signature generated by the 'ipsec
rsasigkey' is 2048 bytes, I think. I suppose that would fit on the BOOTROM.
>>>The mkinitrd already allows ip=rom or
>>>somesuch, so maybe the TFTP kernel can grab a key that way.
>>>
>
>Sorry, I should have said mknbi-linux.
>
>>I would see this as being even more insecure than local storage.
>> Someone can simply sniff the traffic for the ENCRYPTION key being sent
>>to the client IN THE CLEAR. Right?
>>
>
>No. That is if its DHCP.
>
Well, you originally appeared to want to do it via a TFTP transfer of
the encryption key for the workstation to use. I suppose that would be
necessary if the workstation has no local storage. But unless there is
a way to do TFTP encrypted somehow, then there is no point to sending
the key in the clear.
--
Jason A. Pattie
[EMAIL PROTECTED]
_____________________________________________________________________
Ltsp-discuss mailing list. To un-subscribe, or change prefs, goto:
https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help, try #ltsp channel on irc.openprojects.net