View Issue Details

IDProjectCategoryView StatusLast Update
001064410000-004: ServicesSpecpublic2025-12-01 00:42
ReporterRandy Armstrong Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionfixed 
Product Version1.05.07 RC1 
Target Version1.05.07 RC1Fixed in Version1.05.07 RC1 
Summary0010644: ActivateSession must require the SessionTransferToken when using a new SecureChannel and Sign only mode.
Description

SessionTransferToken is defined in Part 6. It provides additional security needed to protect Sessions after a Client certificate is stolen.

ActivateSession also should show not allow the SecurityPolicy or SecurityMode to change.

TagsNo tags attached.
Commit Version1.05.07 RC1
Fix Due Date

Activities

Randy Armstrong

2025-12-01 00:39

administrator   ~0023607

Added required to handle the SessionTransferToken with reference to Part 6 for the details.

Fixed the SecurityPolicy/SecurityMode oversight.

Issue History

Date Modified Username Field Change
2025-12-01 00:12 Randy Armstrong New Issue
2025-12-01 00:12 Randy Armstrong Status new => assigned
2025-12-01 00:12 Randy Armstrong Assigned To => Randy Armstrong
2025-12-01 00:39 Randy Armstrong Status assigned => resolved
2025-12-01 00:39 Randy Armstrong Resolution open => fixed
2025-12-01 00:39 Randy Armstrong Note Added: 0023607
2025-12-01 00:40 Randy Armstrong Fixed in Version => 1.05.07 RC1
2025-12-01 00:42 Randy Armstrong Commit Version => 1.05.07 RC1