[Maybe this message will go through. Suddenly come to think about using the same mail address for postings as I used for subscription...]
I understand the use of different keys for MAC and encryption, because using the same key for different purposes is to my understanding considered bad. But I wonder if there are any security reasons for using different client and server session write keys in the SSL specification. Thanks for all answers. Regards, -- Jostein Tveit ([EMAIL PROTECTED]) ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]