Remove Terracotta Cluster

Cantor, Scott cantor.2 at osu.edu
Wed May 30 15:02:30 BST 2012


On 5/30/12 3:51 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>Does that also apply to HTTP-POST-SimpleSign or would that be an
>alternative?

SimpleSign just signs, it doesn't encrypt. Same issue. It is a partial
mitigation to the attack, but only if you were to require that binding.
The other partial mitigation (aside from convincing OpenSSL to support
AES-GCM) is signing responses, but that also has to be mandated (will be
supported in 2.5).

Now that you mention it, I probably didn't allow for SimpleSign as a
viable option if the new setting is used to block unsigned responses.

-- Scott



More information about the users mailing list