View Issue Details

IDProjectCategoryView StatusLast Update
000649410000-003: Address SpaceSpecpublic2022-08-05 06:24
ReporterRandy Armstrong Assigned ToJeff Harding  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Summary0006494: 4.8.1 Endpoint identity mappings are based on the URL are a security risk.
Description

The paragraph:

Endpoint identity mappings are based on the URL used to connect to the Server. Endpoint identity can be used to restrict access to Clients running on particular networks.

Needs this text:

Endpoint identity mappings should not be used as the only criteria unless access to the endpoint is restricted by the network infrastructure. For example an endpoint on a loopback address is only accessible from the same machine.

TagsBSI
Commit Version
Fix Due Date

Activities

Jim Luth

2021-04-06 16:15

administrator   ~0014169

Post RC 1.05.0
Request from BSI review.

Jeff Harding

2021-05-03 18:35

developer   ~0014295

Added recommended text to 4.8.1.

Jim Luth

2021-05-04 15:05

administrator   ~0014300

Agreed to changes in telecon.

Issue History

Date Modified Username Field Change
2021-02-17 16:29 Randy Armstrong New Issue
2021-02-17 16:29 Randy Armstrong File Added: image.png
2021-04-06 16:11 Jim Luth File Deleted: image.png
2021-04-06 16:15 Jim Luth Note Added: 0014169
2021-04-06 16:15 Jim Luth Assigned To => Jeff Harding
2021-04-06 16:15 Jim Luth Status new => assigned
2021-05-03 18:35 Jeff Harding Status assigned => resolved
2021-05-03 18:35 Jeff Harding Resolution open => fixed
2021-05-03 18:35 Jeff Harding Fixed in Version => 1.05
2021-05-03 18:35 Jeff Harding Note Added: 0014295
2021-05-04 15:04 Jim Luth Tag Attached: BSI
2021-05-04 15:05 Jim Luth Status resolved => closed
2021-05-04 15:05 Jim Luth Note Added: 0014300
2022-08-05 06:17 Paul Hunkar Relationship added related to 0003632
2022-08-05 06:24 Paul Hunkar Relationship deleted related to 0003632