GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
1–6 of 6 posts
Re: GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
#2This seems to be in the GnuTLS implementation and not the specification itself as the title led me to believe.
Re: GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
#3This seems to be in the GnuTLS implementation and not the specification itself as the title led me to believe.
Agreed, would be better if the title would be changed to "MITM flaw in Gnutls implementation of TLS 1.2 & 1.3"
Re: GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
#4This seems to be in the GnuTLS implementation and not the specification itself as the title led me to believe.
Fixed now. Submitted title was "TLS 1.3 session resumption works without master key, allowing MITM"
Re: GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
#5Any ideas which software uses gnutls by default? I couldn't figure it out.
Re: GnuTLS TLS 1.3 session resumption works without master key, allowing MITM
#6Any ideas which software uses gnutls by default? I couldn't figure it out.
https://en.wikipedia.org/wiki/GnuTLS#Deployment
>Software packages using GnuTLS include(d):
GNOME
CenterIM
Exim
Weechat
Mutt
Wireshark
slrn
Lynx
CUPS
gnoMint
GNU Emacs
Synology DiskStation Manager
OpenConnect