View Issue Details

IDProjectCategoryView StatusLast Update
001064310000-004: ServicesSpecpublic2025-12-01 00:41
ReporterRandy Armstrong Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionfixed 
Product Version1.05.07 RC1 
Target Version1.05.07 RC1Fixed in Version1.05.07 RC1 
Summary0010643: ClientSignature, ServerSignature and UserTokenSignatures are vulnerable to hijacking
Description

The current signature algorithm uses data provided by an untrusted party to generate signatures.
This increases the attack surface and makes servers more vulnerable when an application certificate is stolen.

Need to define a signature algorithm that ties the signatures to data supplied by both sides and, when possible, the secure channel active when the signature is created.

TagsNo tags attached.
Commit Version1.05.07 RC1
Fix Due Date

Activities

Randy Armstrong

2025-12-01 00:41

administrator   ~0023609

Add ChannelBound signatures including rules to ensure backward compatibility.

Issue History

Date Modified Username Field Change
2025-11-30 23:37 Randy Armstrong New Issue
2025-11-30 23:37 Randy Armstrong Status new => assigned
2025-11-30 23:37 Randy Armstrong Assigned To => Randy Armstrong
2025-12-01 00:41 Randy Armstrong Status assigned => resolved
2025-12-01 00:41 Randy Armstrong Resolution open => fixed
2025-12-01 00:41 Randy Armstrong Fixed in Version => 1.05.07 RC1
2025-12-01 00:41 Randy Armstrong Commit Version => 1.05.07 RC1
2025-12-01 00:41 Randy Armstrong Note Added: 0023609