> If  [heh]  you  have a particular axe to grind, you can probably come 
> up
> with some little semantic corner where this is not end-to-end  in  
> every
> respect, but it will be just that -- a semantic little corner.  SSL 
> over
> TCP performs end-to-end flow  control,  end-to-end  congestion  
> control,
> weak end-to-end integrity checking at the transport layer, and 
> extremely
> robust end-to-end integrity checking (possibly as  well  as  
> authentica-
> tion)  at the application layer.  Note that, in this example, each 
> layer
> of the stack provides the largest reasonable set of  guarantees  it  
> can
> provide,  and  the  ultimate  "end-to-end"  integrity and 
> authentication
> checks are performed at the _true_ ends of the connection -- the  
> appli-
> cation.

Would that semantic corner include SSL offload NICs like Britestream, 
and/or SSL offload boxes/blades we see advertised from time to time?-)

rick jones
