home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.novell
- Path: sparky!uunet!pmafire!news.dell.com!swrinde!zaphod.mps.ohio-state.edu!cs.utexas.edu!hellgate.utah.edu!fcom.cc.utah.edu!park.uvcc.edu!ns.novell.com!ithaca.Eng.Sandy.Novell.COM!mmm
- From: Mark_Muhlestein@Novell.COM (Mark Muhlestein)
- Subject: Re: Security Patches - How Secure???
- Message-ID: <Bxz62r.3zz@Novell.COM>
- Sender: usenet@Novell.COM (Usenet News)
- Nntp-Posting-Host: ithaca.eng.sandy.novell.com
- Organization: Novell, Inc.
- References: <1992Nov19.030232.10943@umr.edu>
- Date: Thu, 19 Nov 1992 18:01:39 GMT
- Lines: 14
-
- Brett Frankenburger asks a good question regarding the security
- patches, namely, is the user protected against someone monitoring the
- entire session.
-
- The simple answer is yes. The session key is based on the password,
- which is known by both the the user and the server but never
- transmitted on the wire. The packets are signed using the MD4 message
- digest algorithm, encrypted with the session key. This produces a
- "checksum" which provides a very high level of confidence in the
- authenticity of the sender.
-
- I hope this helps.
- --
- Mark_Muhlestein@novell.com
-