View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0006507 | 10000-004: Services | Spec | public | 2021-02-17 17:24 | 2021-03-05 14:19 |
| Reporter | Randy Armstrong | Assigned To | Matthias Damm | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Summary | 0006507: Need to explain what should happen if Certificates expire when a Session is active. | ||||
| Description | Probably needs to be in the CreateSession discussion. | ||||
| Tags | No tags attached. | ||||
| Commit Version | |||||
| Fix Due Date | |||||
|
|
The expectation is that the certificates are checked latest when the SecureChannel is renewed. Applications may do the checks earlier. This should be described already today. |
|
|
Added new chapter: 6.1.7 Continuous security checks A complete ApplicationInstanceCertificates verification shall be executed every time the SecurityToken is renewed for a SecureChannel. OPC UA Application may do additional verifications between SecurityToken renews e.g. if the trust list is updated from a GDS. If the SecureChannel does not use ApplicationInstanceCertificates, the OPC UA Application shall executed frequent ApplicationInstanceCertificate checks for the Session. The recovery mechanisms for ApplicationInstanceCertificate replacement scenarios are described in 6.7. OPC UA Application shall have internal notification mechanisms to get informed about removal of user identities or should frequently check if the UserIdentityTokens is still valid or if the authorization for a UserIdentityTokens was changed. Added in |
|
|
Agreed to changes edited in Virtual F2F. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2021-02-17 17:24 | Randy Armstrong | New Issue | |
| 2021-03-01 18:26 | Matthias Damm | Assigned To | => Matthias Damm |
| 2021-03-01 18:26 | Matthias Damm | Status | new => assigned |
| 2021-03-01 18:29 | Matthias Damm | Note Added: 0013855 | |
| 2021-03-02 13:56 | Matthias Damm | Status | assigned => resolved |
| 2021-03-02 13:56 | Matthias Damm | Resolution | open => fixed |
| 2021-03-02 13:56 | Matthias Damm | Note Added: 0013878 | |
| 2021-03-05 14:19 | Jim Luth | Status | resolved => closed |
| 2021-03-05 14:19 | Jim Luth | Fixed in Version | => 1.05 |
| 2021-03-05 14:19 | Jim Luth | Note Added: 0013992 |