Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-23 Thread Gary Hook
For me... On 10/21/14, 1:30 PM, "Wouter Verhelst" wrote: >Hi Markus, > >On Tue, Oct 21, 2014 at 10:17:17AM +0200, Markus Armbruster wrote: >> >> >> Misunderstanding. I didn't mean to claim "STARTTLS is bad". If I >> wanted to say that, I would've said it directly. I was merely asking >> how

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-21 Thread Wouter Verhelst
Hi Markus, On Tue, Oct 21, 2014 at 10:17:17AM +0200, Markus Armbruster wrote: > Wouter Verhelst writes: > > On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: [...] > >> Furthermore, STARTTLS is vulnerable to active attacks: if you can get > >> between the peers, you can make them

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-21 Thread Markus Armbruster
Wouter Verhelst writes: > On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: >> Stefan Hajnoczi writes: >> >> > On Mon, Oct 20, 2014 at 08:58:14AM +0100, Daniel P. Berrange wrote: >> >> On Sat, Oct 18, 2014 at 07:33:22AM +0100, Richard W.M. Jones wrote: >> >> > On Sat, Oct 18, 2

Re: [libvirt] [Qemu-devel] spec, RFC: TLS support for NBDµ

2014-10-20 Thread Wouter Verhelst
On Mon, Oct 20, 2014 at 01:51:43PM +0200, Markus Armbruster wrote: > Stefan Hajnoczi writes: > > > On Mon, Oct 20, 2014 at 08:58:14AM +0100, Daniel P. Berrange wrote: > >> On Sat, Oct 18, 2014 at 07:33:22AM +0100, Richard W.M. Jones wrote: > >> > On Sat, Oct 18, 2014 at 12:03:23AM +0200, Wouter V