[PATCH] First part of TCP-MD5 inbound verification
Barney Wolff
barney at databus.com
Thu Apr 22 09:11:46 PDT 2004
Just a note that, as discussion on nanog shows, it's very important to
only do the md5 check if the incoming packet is going to be accepted
and processed, rather than the intuitive order of checking the sig
first. That's because checking first allows an easy DoS, since checking
is cpu-intensive.
Barney
--
Barney Wolff http://www.databus.com/bwresume.pdf
I'm available by contract or FT, in the NYC metro area or via the 'Net.
More information about the freebsd-net
mailing list