[FreeNX-kNX] nxsetup --setup-nomachine-key (Was: Alioth projekt for FreeNX debian packages)
Gian Filippo Pinzari
pinzari at nomachine.com
Wed Jun 15 13:05:03 UTC 2005
Felix Schumacher wrote:
> if "nxsetup --setup-nomachine-key" installs a pre-computed ssh private
> key
> for use with the secure channel. I believe anyone could intercept this
> secure
> Channel with a "man in the middle" attack. And get the clear-text
> passwords
> for the user, which are sent over the (than not so) secure channel.
No, because the key we are talking about is not used to encrypt the
traffic but only for authenticating the nx user to the SSHD server.
SSHD will then yield the control to nxserver, being nxserver the nx
user's login shell. Both host authentication and all the other TLS
features of SSH are entirely preserved.
/Gian Filippo.
More information about the FreeNX-kNX
mailing list