View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0010266 | 10000-004: Services | Spec | public | 2025-04-03 08:38 | 2025-11-12 16:57 |
| Reporter | Bernd Edlinger | Assigned To | Randy Armstrong | ||
| Priority | normal | Severity | major | Reproducibility | have not tried |
| Status | assigned | Resolution | open | ||
| Product Version | 1.05.04 | ||||
| Summary | 0010266: CreateSessionResponse shold not always drop the Certificates | ||||
| Description | From the recent ECC IOP workshop I have learned that some But there is a problem with the specification of the CreateSessionResponse, The client is supposed to check that the prior unencrypted GetEndpointsResponse But that assumed that the server does only have one certificate. The spec should be amended, that only those serverCertificates can be omitted that That should hopefully be an upward compatible change, that prevents this | ||||
| Tags | sg.Security | ||||
| Commit Version | |||||
| Fix Due Date | |||||
|
|
Discussed in meeting. There is a potential downgrade attack possible because of the missing certificate. |
|
|
Option require certificate when ECC and not used for current SecureChannel. |
|
|
Can we please make this mandatory for the new Security-Enhanced profiles? |
|
|
Risk: a downgrade attack can be triggered by putting bad certificates in the endpointdescriptions for high security policies. Clients would only discover the bad certificate after choosing an endpointdescription. We need to dcoument what a client should do in this case: 1) Warn user that it is using a lower security because of a bad certificates (confirm/continue prompt?) Note: this only applies to client that actually attempt a fallback after certificate validation failure. Clients that always abort if the first choice has an invalid certificate would not have this risk. |
|
|
Add a flow chart that shows the connection process with three paths: |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-04-03 08:38 | Bernd Edlinger | New Issue | |
| 2025-04-09 15:19 | Randy Armstrong | Note Added: 0022624 | |
| 2025-04-09 15:20 | Randy Armstrong | Note Added: 0022625 | |
| 2025-07-22 16:55 | Jim Luth | Tag Attached: sg.Security | |
| 2025-07-22 16:57 | Jim Luth | Assigned To | => Randy Armstrong |
| 2025-07-22 16:57 | Jim Luth | Status | new => assigned |
| 2025-10-22 05:20 | Bernd Edlinger | Note Added: 0023480 | |
| 2025-11-12 16:34 | Randy Armstrong | Note Added: 0023530 | |
| 2025-11-12 16:48 | Randy Armstrong | Note Added: 0023531 | |
| 2025-11-12 16:57 | Randy Armstrong | Note Edited: 0023530 |