Netscape, RC4, key exchange?

Kipp E.B. Hickman kipp at warp.mcom.com
Fri Jan 20 12:25:09 PST 1995



In article <19875.9501201052 at exe.dcs.exeter.ac.uk>, you write:
> -----BEGIN PGP SIGNED MESSAGE-----
> 
> grendel at netaxs.com wrote:
> > aba at atlas.ex.ac.uk wrote:
> > > I have code to generate the RSA key pairs and modulus, what I am
> > > looking for is code to factorise a number using one of the better
> > > algorithms (quadratic sieve, etc.).
> >
> >	It's been established that the encryption in Netscape is 40 bit 
> >RC4, not 40 bit RSA, [...]
> 
> Ok, so Netscape (the exported version only?) uses 40bit RC4 for
> encryption, but what about key exchange?  RC4 is a stream cypher so
> both the receiver and sender need to know the key.  Does anybody know
> what method Netscape uses to exchange keys DH, RSA, other? and what
> key sizes?

If you read the spec (http://www.mcom.com/info/SSL.html), you will see
that SSL uses RSA public key encryption for key exchange. However, the
protocol is slightly more general than that, so if there is a
different public key algorithm it is possible for SSL to support it.

---------------------------------------------------------------------
Kipp E.B. Hickman          Netscape Communications Corp.
kipp at netscape.com          http://home.mcom.com/people/kipp/index.html








More information about the cypherpunks-legacy mailing list