[PATCH] First part of TCP-MD5 inbound verification

Barney Wolff barney at databus.com
Thu Apr 22 09:11:46 PDT 2004


Just a note that, as discussion on nanog shows, it's very important to
only do the md5 check if the incoming packet is going to be accepted
and processed, rather than the intuitive order of checking the sig
first.  That's because checking first allows an easy DoS, since checking
is cpu-intensive.
Barney

-- 
Barney Wolff         http://www.databus.com/bwresume.pdf
I'm available by contract or FT, in the NYC metro area or via the 'Net.


More information about the freebsd-net mailing list