[BXXPwg] BEEP Server Names

Darren New dnew@san.rr.com
Wed, 08 Nov 2000 11:33:58 -0800


Marshall T. Rose wrote:
> err, user identity doesn't get reset after a TLS negotation.

It does in our code. ;-)

>  what spec are
> you reading?

BEEP framework 07, page 51 (section 9), bullet 2.3

A man-in-the-middle may modify any protocol exchanges prior
to a successful negotiation. Upon completing the
negotiation, a BEEP peer must discard previously cached
information about the BEEP session.

Now that I found the actual wording, I see that it would imply
that the serverName would get discarded.

-- 
Darren New / Senior MTS & Free Radical / Invisible Worlds Inc.
San Diego, CA, USA (PST).  Cryptokeys on demand.