View Issue Details

IDProjectCategoryView StatusLast Update
000274810000-002: SecuritySpecpublic2015-07-28 16:52
ReporterPaul Hunkar Assigned ToPaul Hunkar  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Target Version1.03Fixed in Version1.03 
Summary0002748: Discovery - Security Discussion
Description

Clients should be aware of rogue DiscoveryServers that might direct them to rogue Servers. Clients can use the SSL/TLS server certificate (if available) to verify that the DiscoveryServer is a server that they trust and/or ensure that they trust any Server provided by the DiscoveryServer. See Part 2 for a detailed discussion of these issues.
In any case, Clients shall always verify that it trusts the Server Certificate and that the EndpointUrl matches the HostNames specified in the Certificate before it creates a Session with a Server. After it creates a Session it shall look at the EndpointDescriptions returned by the Server and verify that it used the best security possible and that the Server’s Certificate matches the one that the Client used to connect. The decision on whether the Client is using the best security possible is made by looking for the largest SecurityLevel among the EndpointDescriptions returned in the CreateSession Response.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Paul Hunkar

2015-06-23 03:01

developer   ~0006156

Fxied to include text as described in mantis issue

Jim Luth

2015-07-28 16:52

administrator   ~0006288

Agreed to changes edited in telecon.

Issue History

Date Modified Username Field Change
2014-02-21 20:00 Paul Hunkar New Issue
2014-02-21 20:01 Paul Hunkar Status new => assigned
2014-02-21 20:01 Paul Hunkar Assigned To => Paul Hunkar
2014-08-19 17:23 Jim Luth Category (No Category) => Spec
2014-08-19 17:23 Jim Luth Target Version => 1.03
2015-06-23 03:01 Paul Hunkar Note Added: 0006156
2015-06-23 03:01 Paul Hunkar Status assigned => resolved
2015-06-23 03:01 Paul Hunkar Fixed in Version => 1.03
2015-06-23 03:01 Paul Hunkar Resolution open => fixed
2015-07-28 16:52 Jim Luth Note Added: 0006288
2015-07-28 16:52 Jim Luth Status resolved => closed