OpenSSH SRP 3.8.1p1 patch

Tom Wu tom at arcot.com
Tue Aug 3 10:13:28 EST 2004


Andreas wrote:
> On Mon, Aug 02, 2004 at 02:49:28PM -0700, Tom Wu wrote:
> 
>>>Isn't this patented by Phoenix Technologies Ltd?
>>>http://www.ietf.org/ietf/IPR/PHOENIX-SRP-RFC2945.txt
>>
>>No, that is only an offer to license under RAND terms IF some technology 
>>is covered under the SPEKE patent.  There has not been any claim or 
>>substantiation that SPEKE technology covers the math used in SRP.
> 
> 
> Here is an email that talks about these issues from the point of view of
> an implementation in Kerberos:
> 
> http://mailman.mit.edu/pipermail/krbdev/2004-January/002251.html
> 
> I guess they don't want to be the first to implement it and see if it will
> attract heat from lawyers.

I'll talk to Jeffrey about his comments, as I believe the issue is 
closed in the "other direction", i.e. other projects, both OSS and 
commercial, have already used SRP without paying a dime in licensing fees.

> _______________________________________________
> openssh-unix-dev mailing list
> openssh-unix-dev at mindrot.org
> http://www.mindrot.org/mailman/listinfo/openssh-unix-dev

Tom
-- 
Tom Wu
Chief Security Architect
Arcot Systems
(408) 969-6124




More information about the openssh-unix-dev mailing list