View Issue Details

IDProjectCategoryView StatusLast Update
0010403CTT UA Test Case4 - Test Case Definitionpublic2025-07-08 06:42
ReporterSebastian Allmendinger Assigned ToSebastian Allmendinger  
PrioritynormalSeverityminorReproducibilityhave not tried
Status resolvedResolutionduplicate 
Summary0010403: Security User Name Password / 006: Expected result needs to be updated
Description

The test case expects a server to reject a Username-UserToken if no nonce is appended. The expected error codes are: Bad_UserAccessDenied and Bad_IdentityTokenRejected.
According to the specification, the returned error should be Bad_IdentityTokenInvalid. This behavior has been added with Mantis 4155 and was also pushed back to 1.03.

Additional Information

https://reference.opcfoundation.org/Core/Part4/v105/docs/7.41.2.1

To prevent the leakage of information useful to attackers, Servers shall ensure that the process of validating UserIdentityTokens completes in a fixed interval independent of whether an error occurs or not. The process of validation includes decrypting, check for padding and checking for a valid nonce. If any errors occur the return code is Bad_IdentityTokenInvalid.

TagsNo tags attached.
Files Affected

Relationships

duplicate of 0010414 assignedAlexander Allmendinger Username Password / 006 needs to expect BadUserIdentityTokenInvalid 

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-07-01 10:13 Sebastian Allmendinger New Issue
2025-07-02 11:43 Paul Hunkar Assigned To => Sebastian Allmendinger
2025-07-02 11:43 Paul Hunkar Status new => assigned
2025-07-08 06:42 Sebastian Allmendinger Relationship added duplicate of 0010414
2025-07-08 06:42 Sebastian Allmendinger Status assigned => resolved
2025-07-08 06:42 Sebastian Allmendinger Resolution open => duplicate