The SSL records include a message digest (MAC) of the application data 
within the record.  If you remove the application data, the SSL record is 
no longer valid.

If you think about it, this is obvious.  SSL guarantees the integrity of 
the application data.  If someone modifies or removes the application 
data, then the SSL layer should, of course, notice this.

        /r$

--
SOA Appliances
Application Integration Middleware

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to