View Issue Details

IDProjectCategoryView StatusLast Update
0007778Part 83: UAFX Offline EngineeringSpecpublic2022-04-08 14:03
ReporterTodd Snide Assigned To 
PrioritynormalSeveritymajorReproducibilityhave not tried
Status acknowledgedResolutionsuspended 
Summary0007778: Chapter 5.2: lack of information on how to verify the content of a URI
Description

In Chapter 5.2 There is no information of how the consumer of a package can verify the content of the linked reference. A reference should also include some kind of hash or thumbprint. There is nothing in the 'Relationsships' to support this.

On behalf of Thomas Enzinger

TagsSecurity

Activities

Todd Snide

2022-03-04 15:26

developer   ~0016192

Open packaging Convention does provide this feature. It may be defined in Part 83 by some definitions. This needs to be investigated further.

Emanuel Kolb

2022-03-15 09:48

manager   ~0016372

This is maybe possible to integrate into a digital signature, by storing the external reference in a 2nd Object tag.
But it requires some investigation work, so it is out of scope for RC2.
It is planned to do this in a future version of part 83.

Emanuel Kolb

2022-03-15 09:49

manager   ~0016373

moved to future version

Emanuel Kolb

2022-04-08 14:03

manager   ~0016553

Future topic

Issue History

Date Modified Username Field Change
2022-02-24 18:37 Todd Snide New Issue
2022-03-04 09:06 Emanuel Kolb Tag Attached: Security
2022-03-04 15:24 Todd Snide Assigned To => Todd Snide
2022-03-04 15:24 Todd Snide Status new => assigned
2022-03-04 15:24 Todd Snide Assigned To Todd Snide => Emanuel Kolb
2022-03-04 15:26 Todd Snide Note Added: 0016192
2022-03-15 09:48 Emanuel Kolb Note Added: 0016372
2022-03-15 09:49 Emanuel Kolb Status assigned => resolved
2022-03-15 09:49 Emanuel Kolb Resolution open => suspended
2022-03-15 09:49 Emanuel Kolb Note Added: 0016373
2022-04-08 14:03 Emanuel Kolb Assigned To Emanuel Kolb =>
2022-04-08 14:03 Emanuel Kolb Status resolved => acknowledged
2022-04-08 14:03 Emanuel Kolb Note Added: 0016553
2022-04-08 14:03 Emanuel Kolb Product Version 1.00.00 RC2 =>
2022-04-08 14:03 Emanuel Kolb Target Version 1.00.00 RC2 =>