View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008357 | 10000-006: Mappings | Spec | public | 2022-09-27 12:26 | 2023-01-24 17:26 |
Reporter | Alexander Allmendinger | Assigned To | Randy Armstrong | ||
Priority | normal | Severity | minor | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Product Version | 1.05.01 | ||||
Fixed in Version | 1.05.03 RC1 | ||||
Summary | 0008357: Requirement on CA Flag for self-signed certificates is a potential security risk | ||||
Description | We see products which are not accepting self-signed certificates which have the CA Flag set to TRUE due to security concerns. The specification in 1.05 states: The security concern is about the requirement to accept self-signed certificates where the CA Flag is set to TRUE for backward interoperability. Is this a hard requirement or should such certificates rather be rejected by default with a configuration option to accept them (individually). In any case the requirement changes need to be pushed back to 1.04 as well. | ||||
Tags | No tags attached. | ||||
Commit Version | |||||
Fix Due Date | |||||
related to | 0006809 | closed | Randy Armstrong | Clarify content of self-signed end-entity certificates |
related to | 0008370 | closed | Randy Armstrong | Requirement on CA Flag for self-signed certificates is a potential security risk |
|
I don't see what security concern that may be, since a self-signed certificate alone is not enough |
|
Agreed to update text in 1.05 and produce errata for 1.04. |
|
Updated 6.2.2 to require that cA flag = FALSE for ApplicationInstance Certificates. Created 1.04 errata. |
|
Agreed to changes in web meeting. |
Date Modified | Username | Field | Change |
---|---|---|---|
2022-09-27 12:26 | Alexander Allmendinger | New Issue | |
2022-09-27 12:26 | Alexander Allmendinger | Relationship added | related to 0006809 |
2022-09-27 12:28 | Alexander Allmendinger | Description Updated | |
2022-09-28 04:38 | Bernd Edlinger | Note Added: 0017866 | |
2022-09-28 12:04 | Paul Hunkar | Assigned To | => Randy Armstrong |
2022-09-28 12:04 | Paul Hunkar | Status | new => assigned |
2022-09-28 12:04 | Paul Hunkar | Summary | Requirement on cA Flag for self-signed certificates is a potential security risk => Requirement on CA Flag for self-signed certificates is a potential security risk |
2022-09-28 12:04 | Paul Hunkar | Description Updated | |
2022-09-29 14:18 | Randy Armstrong | Note Added: 0017890 | |
2022-09-29 14:19 | Randy Armstrong | Issue cloned: 0008370 | |
2022-09-29 14:19 | Randy Armstrong | Relationship added | related to 0008370 |
2022-12-28 10:22 | Randy Armstrong | Status | assigned => resolved |
2022-12-28 10:22 | Randy Armstrong | Resolution | open => fixed |
2022-12-28 10:22 | Randy Armstrong | Fixed in Version | => 1.05.03 RC1 |
2022-12-28 10:22 | Randy Armstrong | Note Added: 0018363 | |
2023-01-24 17:26 | Jim Luth | Status | resolved => closed |
2023-01-24 17:26 | Jim Luth | Note Added: 0018574 |