PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > comp.security.ssh > Authentication
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.security.ssh SSH secure remote login and tunneling tools.

Authentication

Réponse
 
LinkBack Outils de la discussion
Vieux 25/08/2007, 23h14   #1
Nate, Nano
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Authentication

So I understand the DSA/RSA authentication procedure and how it
provides authenication of a client from a servers perspective, but
what is there implemented in SSH to provide authentication of the
server from the clients perspective.? I know that on connection, the
server sends the client a key, identifying itself to the client. But
what prevents, a rogue client from grabbing the identification #, and
masking the servers IP, and setting up their own rogue server, with a
the same server id?
If this happend, the rogue server would most liekly not have he public
key of any client connecting to it, nor would any clients private keys
be comprimised b/c their keys are never transmitted. But the rogue
server, could present itself as the server u wanted. Is that left up
to the client to check, when they log in?

i.e: the client could place a file on the known good server, which
contains some text that only the client would know. then when they
logged in, they can authenticate the server, based on the existance
and content of the file, existing on the server.

  Réponse avec citation
Vieux 26/08/2007, 16h52   #2
Richard E. Silverman
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Authentication

>>>>> "NN" == Nate, Nano <nanonut@gmail.com> writes:

NN> So I understand the DSA/RSA authentication procedure and how it
NN> provides authenication of a client from a servers perspective, but
NN> what is there implemented in SSH to provide authentication of the
NN> server from the clients perspective.? I know that on connection,
NN> the server sends the client a key, identifying itself to the
NN> client. But what prevents, a rogue client from grabbing the
NN> identification #, and masking the servers IP, and setting up their
NN> own rogue server, with a the same server id?

The rogue server does not possess the corresponding private hostkey.

--
Richard Silverman
res@qoxp.net

  Réponse avec citation
Vieux 26/08/2007, 16h52   #3
Richard E. Silverman
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Authentication

>>>>> "NN" == Nate, Nano <nanonut@gmail.com> writes:

NN> So I understand the DSA/RSA authentication procedure and how it
NN> provides authenication of a client from a servers perspective, but
NN> what is there implemented in SSH to provide authentication of the
NN> server from the clients perspective.? I know that on connection,
NN> the server sends the client a key, identifying itself to the
NN> client. But what prevents, a rogue client from grabbing the
NN> identification #, and masking the servers IP, and setting up their
NN> own rogue server, with a the same server id?

The rogue server does not possess the corresponding private hostkey.

--
Richard Silverman
res@qoxp.net

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 20h51.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,08013 seconds with 11 queries