Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs


Chronological Thread 
  • From: "Cantor, Scott E." <>
  • To: "" <>
  • Subject: RE: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs
  • Date: Wed, 9 Feb 2011 16:52:32 +0000
  • Accept-language: en-US

> Don't focus on sessionid, in SSL3 and later. Work with the channel binding
> that cues off the finished messages (not the endpoint certs).

Even if we understood how that would work, Java doesn't expose that message.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page