View Issue Details

IDProjectCategoryView StatusLast Update
000755710000-018: Role-Based SecuritySpecpublic2022-02-22 16:34
ReporterMatthias Damm Assigned ToMatthias Damm  
PrioritynormalSeveritymajorReproducibilityhave not tried
Status closedResolutionfixed 
Product Version1.05.00 
Target Version1.05.01 RC1 
Summary0007557: Handling of ApplicationsExclude for Security NONE
Description

What happes if the Application Instance Certificate is not known or cannot be verified in case of Security NONE

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Matthias Damm

2022-02-15 21:16

developer   ~0016021

Added to Applications Property description:
If the array is not empty, the Role shall only be granted if the Session uses at least a signed communication channel.

It makes no sense to allow application authentication if the applicaiton authentication was not verified in the case of a NONE channel.

Randy Armstrong

2022-02-22 16:34

administrator   ~0016067

Reviewed in WG.

Issue History

Date Modified Username Field Change
2022-01-16 19:00 Matthias Damm New Issue
2022-02-08 17:43 Jim Luth Assigned To => Matthias Damm
2022-02-08 17:43 Jim Luth Status new => assigned
2022-02-15 21:16 Matthias Damm Status assigned => resolved
2022-02-15 21:16 Matthias Damm Resolution open => fixed
2022-02-15 21:16 Matthias Damm Note Added: 0016021
2022-02-22 16:34 Randy Armstrong Status resolved => closed
2022-02-22 16:34 Randy Armstrong Note Added: 0016067