View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008370 | 10000-006: Mappings | Spec | public | 2022-09-29 14:19 | 2023-03-23 21:24 |
Reporter | Randy Armstrong | Assigned To | Randy Armstrong | ||
Priority | normal | Severity | minor | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Product Version | 1.04 | ||||
Fixed in Version | 1.04 | ||||
Summary | 0008370: Requirement on CA Flag for self-signed certificates is a potential security risk | ||||
Description | We see products which are not accepting self-signed certificates which have the CA Flag set to TRUE due to security concerns. The specification in 1.05 states: The security concern is about the requirement to accept self-signed certificates where the CA Flag is set to TRUE for backward interoperability. Is this a hard requirement or should such certificates rather be rejected by default with a configuration option to accept them (individually). In any case the requirement changes need to be pushed back to 1.04 as well. | ||||
Additional Information | Cloned for errate. | ||||
Tags | No tags attached. | ||||
Commit Version | |||||
Fix Due Date | |||||
related to | 0008357 | closed | Randy Armstrong | Requirement on CA Flag for self-signed certificates is a potential security risk |
related to | 0008670 | closed | Randy Armstrong | Update from OpenSSL V1.x.x (EOL(end of live) soon) to V3.x.x |
Date Modified | Username | Field | Change |
---|---|---|---|
2022-09-29 14:19 | Randy Armstrong | New Issue | |
2022-09-29 14:19 | Randy Armstrong | Status | new => assigned |
2022-09-29 14:19 | Randy Armstrong | Assigned To | => Randy Armstrong |
2022-09-29 14:19 | Randy Armstrong | Issue generated from: 0008357 | |
2022-09-29 14:19 | Randy Armstrong | Relationship added | related to 0008357 |
2022-09-29 14:29 | Randy Armstrong | Status | assigned => resolved |
2022-09-29 14:29 | Randy Armstrong | Resolution | open => fixed |
2022-09-29 14:29 | Randy Armstrong | Fixed in Version | => 1.04 |
2022-09-29 14:29 | Randy Armstrong | Note Added: 0017891 | |
2023-01-24 17:05 | Jim Luth | Status | resolved => closed |
2023-01-24 17:05 | Jim Luth | Note Added: 0018569 | |
2023-03-23 21:24 | Jim Luth | Relationship added | related to 0008670 |