LWN.net Logo

TLS renegotiation vulnerability

TLS renegotiation vulnerability

Posted Nov 30, 2009 12:22 UTC (Mon) by robbe (guest, #16131)
Parent article: TLS renegotiation vulnerability

How can the MITM present the correct server certificate to the victim?
This problem is not mentioned at all in all the papers I skimmed, so this
is probably just me being daft.


(Log in to post comments)

TLS renegotiation vulnerability

Posted Dec 3, 2009 0:10 UTC (Thu) by xoddam (subscriber, #2322) [Link]

As I understand it, the certificate exchange is still between the client and the server; the MITM does nothing more than forward the data and insert a cleartext payload into a window of vulnerability. In this attack, the MITM does not need to know or have any certificate or cipher keys.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds