home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:1758 alt.security:4818 comp.unix.admin:6197
- Newsgroups: comp.security.misc,alt.security,comp.unix.admin
- Path: sparky!uunet!gatech!usenet.ins.cwru.edu!agate!spool.mu.edu!sdd.hp.com!news.cs.indiana.edu!noose.ecn.purdue.edu!mentor.cc.purdue.edu!purdue!spaf
- From: spaf@cs.purdue.EDU (Gene Spafford)
- Subject: Re: Tripwire release
- In-Reply-To: mccurley@cs.sandia.gov's message of 13 Nov 92 00:47:08 GMT
- Message-ID: <SPAF.92Nov15135616@uther.cs.purdue.EDU>
- Sender: news@mentor.cc.purdue.edu (USENET News)
- Organization: Department of Computer Sciences, Purdue University
- References: <1992Nov6.161125.10283@ghost.dsi.unimi.it>
- <1992Nov06.173036.28994@watson.ibm.com>
- <BxMEuE.CwC@mentor.cc.purdue.edu>
- <1992Nov13.004708.26881@cs.sandia.gov>
- Date: Sun, 15 Nov 1992 18:56:16 GMT
- Lines: 27
-
- In article <1992Nov13.004708.26881@cs.sandia.gov> mccurley@cs.sandia.gov (Kevin McCurley) writes:
-
- From: mccurley@cs.sandia.gov (Kevin McCurley)
- Newsgroups: comp.security.misc,alt.security,comp.unix.admin
- Date: 13 Nov 92 00:47:08 GMT
-
- I stated earlier that NONE of these, including MD5, Snefru, and MD4,
- are signatures in the cryptographic sense. A true signature would
- require something like RSA or DSA layered on a one-way hash function
- like MD5 or SHA.
-
- We have seen the word "signature" used in different ways in the
- literature and the general user community. Our use of the word in the
- Tripwire documentation was in the sense of other uses we had seen.
- Perhaps we should put little quote marks around the word, or put a
- footnote that some people have a more restrictive definition of
- signature than what we used....
-
- The basic point made by GeneK was that the program has a
- simple-extension feature to include whatever other algorithm you wish.
- For instance, if you wish to apply DES in CBC mode, and save the last
- 64 or 128 bits as a signature, you can (and it doesn't need to be
- layered on top of anything else to work). Or encode using your
- favorite RSA key before running the CRC...whatever method you choose.
-
- Is anyone using Tripwire, or is the only traffic about the terminology
- used in the README file? :-)
-