4 ms·
It happens during the Finished messages. The OP covers the handshake about halfway down, and 72deluxe's Wikipedia link covers it nicely, too: https://en.wikipe
by mnordhoff 13y ago
It happens during the Finished messages. The OP covers the handshake about halfway down, and 72deluxe's Wikipedia link covers it nicely, too:
https://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_handshake https://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_h...
In TLS 1.0 and 1.1, the Finished message is protected by HMAC-MD5 and HMAC-SHA1. (RFC 2246, sections 5 and 7.4.9.) (By the way, while there are attacks against MD5 and SHA-1, there are no known attacks against HMAC-MD5 or HMAC-SHA1. Don't freak out.)
TLS 1.1 is the same as TLS 1.0. (RFC 4346, sections 5 and 7.4.9.)
For TLS 1.2, I am uncertain which algorithm is used. See RFC 5246, sections 5 and 7.4.9. It's either HMAC-SHA256 or the MAC defined by the chosen cipher suite, which would currently be one of HMAC-MD5, HMAC-SHA1, HMAC-SHA256 or HMAC-SHA384. (As long as your weakest cipher suite's MAC can't be broken in half a second, this doesn't help an attacker.)
Edit: Staring at RFC 5246 a bit longer, I am almost certain that TLS 1.2 will always use HMAC-SHA256. Future cipher suites may define a different algorithm, but no such cipher suites yet exist.
(Edits: This post was basically written one sentence at a time in a dozen different edits.)
- Nursie 13y ago>> In TLS 1.0 and 1.1, the Finished message is protected by HMAC-MD5 and HMAC-SHA1. (RFC 2246, sections 5 and 7.4.9.) (By the way, while there are attacks against MD5 and SHA-1, there are no known attacks against HMAC-MD5 or HMAC-SHA1. Don't freak out.) Yeah, been reading up on HMAC lately. I had to implement a MAC algorithm due to a weird failing by an embedded platform vendor. HMAC(sha256) was it, until at the last minute we switched out for iso9797 algorithm 3, pad 3* because a second vendor we have to work with couldn't support 32 byte keys. It's always a bit sad to write beautiful code and then discard it again within days... (*why yes, it is a retail application)