View Issue Details

IDProjectCategoryView StatusLast Update
0008974CTT UA Scripts3 - Feature Requestpublic2023-05-19 15:33
ReporterPaul Hunkar Assigned ToAlexander Allmendinger  
PrioritynormalSeverityminorReproducibilityhave not tried
Status assignedResolutionopen 
Summary0008974: Add test case with a certificate chain loop
Description

see https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-5q2v-6j86-5h9v

for the disclosed sample code see https://github.com/OPCFoundation/UA-.NETStandard/blob/6711523ffe60d6e4cda6ee190f08d53b29ca7610/Tests/Opc.Ua.Core.Tests/Security/Certificates/CertificateValidatorAlternate.cs#L296

how to build a certificate chain with a loop.

Servers may not detect the loop and hang infinitely, or refuse new secure connections, or consume more and more memory over time.

TagsNo tags attached.
Files Affected

Relationships

related to 0008548 closedAlexander Allmendinger CTT UA Test Case Add test case with a certificate chain loop 

Activities

Paul Hunkar

2023-05-19 15:22

administrator   ~0019407

Ok to use a fixed set of certificates for this issue (100 year expiration)

Alexander Allmendinger

2023-05-19 15:22

developer   ~0019408

Added Test Case 059 in Certificate Validation CU

Paul Hunkar

2023-05-19 15:33

administrator   ~0019413

Add scripts for this new test case

Issue History

Date Modified Username Field Change
2023-05-19 15:22 Paul Hunkar New Issue
2023-05-19 15:22 Paul Hunkar Status new => assigned
2023-05-19 15:22 Paul Hunkar Assigned To => Alexander Allmendinger
2023-05-19 15:22 Paul Hunkar Issue generated from: 0008548
2023-05-19 15:22 Paul Hunkar Note Added: 0019407
2023-05-19 15:22 Paul Hunkar Note Added: 0019408
2023-05-19 15:22 Paul Hunkar Relationship added related to 0008548
2023-05-19 15:22 Paul Hunkar Project CTT UA Test Case => CTT UA Scripts
2023-05-19 15:33 Paul Hunkar Note Added: 0019413