Google Answers Logo
View Question
 
Q: How often should an encrypted session be rekeyed? ( Answered 1 out of 5 stars,   0 Comments )
Question  
Subject: How often should an encrypted session be rekeyed?
Category: Computers > Security
Asked by: daksong-ga
List Price: $2.00
Posted: 22 Apr 2003 19:58 PDT
Expires: 22 May 2003 19:58 PDT
Question ID: 194117
Using OpenSSL, is there a preferred/recommended rate of rekeying an
encrypted stream of data?  Does OpenSSL handle this for developers
behind the scenes?  Does it even need to be rekeyed?
Answer  
Subject: Re: How often should an encrypted session be rekeyed?
Answered By: errol-ga on 19 May 2003 20:39 PDT
Rated:1 out of 5 stars
 
Hi there, Daksong!


There is precious little documentation available for OpenSSL.
Even the manual [ http://www.openssl.org/docs/ ] is incomplete.

I only found one single article on the web, archived from Usenet.
The message contains the quote:

"     -k key_gen_time
             Specifies how often the ephemeral protocol version 1
server key
             is regenerated (default 3600 seconds, or one hour).  The
motiva-
             tion for regenerating the key fairly often is that the
key is not
             stored anywhere, and after about an hour, it becomes
impossible
             to recover the key for decrypting intercepted
communications even
             if the machine is cracked into or physically seized.  A
value of
             zero indicates that the key will never be regenerated."

As you can see, it performs the operation by itself every hour.
Another section contains:

"Yes, you do want renegotiations, for two reasons. One is that if you
use
the same key over a long period of time, you offer too much same-keyed
cryptographic material to an attacker, and increase his chances of a
successful attack. The second is that you limit the amount of data
that
can be compromised should someone get hold of your current key."

So basically, it isn't a bad idea to rekey every so often and would
strengthen security considerably.

To view the entire thread, view the following (very long) URL:
http://groups.google.co.uk/groups?hl=en&lr=&ie=UTF-8&safe=off&threadm=20030411025825.GK79923%40perrin.int.nxad.com&rnum=1&prev=/groups%3Fq%3Drekey%2Bopenssl%2Boften%26hl%3Den%26lr%3D%26ie%3DUTF-8%26safe%3Doff%26selm%3D20030411025825.GK79923%2540perrin.int.nxad.com%26rnum%3D1

I hope that this makes it a little more clear for you.


Kind regards,
errol-ga.


Related Google searches:

"openssl rekey"
://www.google.co.uk/search?q=openssl+rekey

"openssl session timeout"
://www.google.co.uk/search?q=openssl+session+timeout
daksong-ga rated this answer:1 out of 5 stars
sorry too late

Comments  
There are no comments at this time.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy