Re: [Openvpn-devel] [PATCH] Document tls-crypt security considerations in man page

2017-05-07 Thread Steffan Karger
Hi, On 07-05-17 11:39, Magnus Kroken wrote: > Non-crypto geek here, comments inline. > > On 05.05.2017 22:30, Steffan Karger wrote: >> +control channel messages. A typical initial negotiation is about 10 packets >> +in each direction. Assuming both initial negotation and renogatiations are >> +

Re: [Openvpn-devel] [PATCH] Document tls-crypt security considerations in man page

2017-05-07 Thread Magnus Kroken
Hi Steffan Non-crypto geek here, comments inline. On 05.05.2017 22:30, Steffan Karger wrote: > +control channel messages. A typical initial negotiation is about 10 packets > +in each direction. Assuming both initial negotation and renogatiations are > +at most 2^16 (65536) packets, and (re)nego

[Openvpn-devel] [PATCH] Document tls-crypt security considerations in man page

2017-05-05 Thread Steffan Karger
The tls-crypt commit message contained an elaborate discussion on the function's security properties. This commit adds the gist of that discussion, "rotate keys periodically" to the man page. (The 'real' solution will follow later: add support for per-client tls-crypt keys. That will make tls-cr