>>>>> "Miao" == Miao Fuyou <[EMAIL PROTECTED]> writes:

    Miao> Yes, peer entity authentication is seperate from integrity,
    Miao> this is addressed in section 3 of the current
    Miao> document. Client only authenticaiton is not available in
    Miao> TLS, so I think it is safe to say "peer entity authention"
    Miao> instead of sender authenticaiton.

No, because peer entity authentication confuses server auth and
client+server auth.

Also, TLS does have client only auth: any case where the server cert
is not actually verified but the client certificate is.

It's important for the TLS document to point out that authentication
is as much about whether you actually check the certificates as
whether you exchange them at a protocol level.


_______________________________________________
Syslog mailing list
Syslog@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/syslog

Reply via email to