View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008129 | 10000-004: Services | Spec | public | 2022-07-25 13:10 | 2022-12-07 14:35 |
Reporter | Matthias Damm | Assigned To | Matthias Damm | ||
Priority | normal | Severity | major | Reproducibility | have not tried |
Status | closed | Resolution | fixed | ||
Product Version | 1.04 | ||||
Target Version | 1.05.03 RC1 | Fixed in Version | 1.05.03 RC1 | ||
Summary | 0008129: Remove requirement to allow Administrators to disable the DiscoveryEndpoint | ||||
Description | The spec states at the moment: This makes no sense since since in the automatic certificate update szenario with GDS, the client MUST call GetEndpoints to get the new certificate from the server. There is a special status code that indicates that the client is using the wrong certificate and GetEndpoints is the only way to get the new certificate. This new certificate will be used by the client if it is trusted (which will be the case for a GDS managed trust list). We clarified this in erratas to 1.04 a while ago. If Clients are configured to use a certain endpoint setting, they should not change the used parameters by calling GetEndpoints but a updated certificate must be fetched with GetEndpoints. If a Client has a "use best security" option, the client MUST verify the GetEndpoints results with the endpoints returned from CreateSession. It is much more important that clients do this check ALWAYS when the automatically select the endpoint. | ||||
Additional Information | See also 0007916 | ||||
Tags | No tags attached. | ||||
Commit Version | |||||
Fix Due Date | |||||
related to | 0007916 | assigned | Karl Deiretsbacher | 10000-007: Profiles | Description of CU "Discovery Client Configure Endpoint" misleading |
|
Discussed in UA meeting. We disagree with the proposed request to disallow the disabling of the DiscoveryEndpoint. Instead, the spec needs to discuss the ramifications of disabling DiscoveryEndpoints when used with Certificate Managers. |
|
5.4 Discovery Service Set Added following clarification: |
|
Agreed to changes edited in Virtual F2F. |
Date Modified | Username | Field | Change |
---|---|---|---|
2022-07-25 13:10 | Matthias Damm | New Issue | |
2022-07-25 13:10 | Matthias Damm | Relationship added | related to 0007916 |
2022-08-02 17:00 | Jim Luth | Note Added: 0017214 | |
2022-08-02 17:00 | Jim Luth | Assigned To | => Matthias Damm |
2022-08-02 17:00 | Jim Luth | Status | new => assigned |
2022-12-06 20:38 | Matthias Damm | Status | assigned => resolved |
2022-12-06 20:38 | Matthias Damm | Resolution | open => fixed |
2022-12-06 20:38 | Matthias Damm | Fixed in Version | => 1.05.03 RC1 |
2022-12-06 20:38 | Matthias Damm | Note Added: 0018256 | |
2022-12-07 14:35 | Jim Luth | Status | resolved => closed |
2022-12-07 14:35 | Jim Luth | Note Added: 0018260 |