Spring 2014

Preparation for Recitation 23

Read the TLS in book section 11.10.

Please answer the following question:

1. In the TLS handshake protocol, why is it necessary for master_secret to be generated using the client's and server's random values?

2. What procedure does a client use to verify a Web site's certificate? What parties does the client need to trust?

