[Security-devroom] Talk submission : SSH Libraries
Hello, I'm sorry I did not follow the procedure for the submission of talks. I already put a brief description of the talk on the wiki [1] but give the official submission now. Affiliation: libssh project, BELNET Bio: I'm lead of the libssh project [2], started in 2003. I work at BELNET (Belgian Research and Education Network) as technical advisor. Talk duration: 30 minutes (20 + 5 + 5). Can do less if that's absolutely needed. Talk: SSH libraries - what they can do for you. Since 2003, a few libraries that implement the SSH protocol are around. However, SSL and TLS are very popular protocols. Why would one use SSH for secure connection ? We will present the differences between SSH and TLS, as well as an overview of the different SSH libraries. We will then focus on libssh and give the status of the project, the achievements, and its future. [1] http://www.opensc-project.org/opensc/wiki/FOSDEM2011 [2] http://www.libssh.org -- Aris Adamantiadis
Hi, Here is another submission that I though might be interesting. If accepted I hope to get the creator, Samuel, of this interesting tool to come, instead of me. Affiliation: Fribid.se [1] Bio: I am a PKI nerd since middle of the 90's. Samuel is a Computer Science student at KTH, Stockholm. Talk duration: 30 minutes max Talk: The development of Fribid, what can be do for browser clients? Since many years ago Swedish digital id's issued by the banks (equivalent to other countries digital national id's) are using proprietary client software in order to log in, sign transactions and enroll for id's. The software works as browser plug-ins since on-line services are always web based. Prorietary software rarely works well with Linux, although there are now have a 32 bit version out. Samuel created an open source version of the browser plug-in, Fribid [1] to get something that works better. By investigating communication he soon had a linux client that worked well. It even works with smart cards using OpenSC [2]. This talk will describe a bit of the development behind fribid, and extend to some questions that are much broader in scope than the swedish digital id's, that fribid was created for. Some of the natural questions to ask are: - Why are there no open standards for the authentication and digital signature operations needed for web based applications? - What can the open source world to to make this important technology (in a much wider concept than swedish digital id's) open and user friendly? [1] http://fribid.se/ (swedish unfortunately) [2] http://wiki.fribid.se/sidor/SmartCards Cheers, Tomas
Hello, On Dec 17, 2010, at 8:16 PM, Tomas Gustavsson wrote:
Here is another submission that I though might be interesting. If accepted I hope to get the creator, Samuel, of this interesting tool to come, instead of me.
Affiliation: Fribid.se [1]
Bio: I am a PKI nerd since middle of the 90's. Samuel is a Computer Science student at KTH, Stockholm.
Talk duration: 30 minutes max
Talk: The development of Fribid, what can be do for browser clients?
Since many years ago Swedish digital id's issued by the banks (equivalent to other countries digital national id's) are using proprietary client software in order to log in, sign transactions and enroll for id's. The software works as browser plug-ins since on-line services are always web based. Prorietary software rarely works well with Linux, although there are now have a 32 bit version out. Samuel created an open source version of the browser plug-in, Fribid [1] to get something that works better. By investigating communication he soon had a linux client that worked well. It even works with smart cards using OpenSC [2].
This talk will describe a bit of the development behind fribid, and extend to some questions that are much broader in scope than the swedish digital id's, that fribid was created for.
Some of the natural questions to ask are: - Why are there no open standards for the authentication and digital signature operations needed for web based applications? - What can the open source world to to make this important technology (in a much wider concept than swedish digital id's) open and user friendly?
Indeed, very interesting. Online signature schemes and mechanics have IMHO been a moving target for a while and re-developed over and over again (applets, plugin, helpers, etc-etc) that it surely is an interesting, as well as parctical topic. For example, I don't know anyone who would know anyone who would use the .sign() function in firefox, but I've created or help to create ~3 different plugins or applets for the same purpose... While TLS/SSL and related PKI is natural in the "web 2.5" world, anything that's not connection oriented (and is not S/MIME) is somewhat left aside. Even OAuth 2.0 decided that "signatures are difficult, lets just do SSL which everyone knows how to do" +1 from me. -- @MartinPaljak.net +3725156495
Hello, On Dec 17, 2010, at 6:39 PM, Aris Adamantiadis wrote:
Hello,
I'm sorry I did not follow the procedure for the submission of talks. I already put a brief description of the talk on the wiki [1] but give the official submission now. Actually either is OK, just the wiki will be the "master copy" of the documentation. I've added all submissions to the wiki already.
Affiliation:
libssh project, BELNET
Bio: I'm lead of the libssh project [2], started in 2003. I work at BELNET (Belgian Research and Education Network) as technical advisor.
Talk duration: 30 minutes (20 + 5 + 5). Can do less if that's absolutely needed. 30 minutes is OK unless you know for sure that it will be too much. If current submission rate continues there will be no room for 60 minutes slots, because there are so many interesting topics, that already claim to fit into 30m slots :) Currently the proposed talks either almost fill the available time or leave room for just two more, granted that the "bootstrap hour" will be scheduled.
Talk: SSH libraries - what they can do for you.
Since 2003, a few libraries that implement the SSH protocol are around. However, SSL and TLS are very popular protocols. Why would one use SSH for secure connection ? Indeed, a good question. I personally like my ~/.ssh/authorized_keys/known hosts file more than I like the X509 CA list in any of the browsers...
We will present the differences between SSH and TLS, as well as an overview of the different SSH libraries. We will then focus on libssh and give the status of the project, the achievements, and its future. Be sure to touch on PKCS#11 support.
Thanks, Martin -- @MartinPaljak.net +3725156495
participants (3)
-
Aris Adamantiadis -
Martin Paljak -
Tomas Gustavsson