View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0008370 | 10000-006: Mappings | Spec | public | 2022-09-29 14:19 | 2023-03-23 21:24 |
| Reporter | Randy Armstrong | Assigned To | Randy Armstrong | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Product Version | 1.04 | ||||
| Fixed in Version | 1.04 | ||||
| Summary | 0008370: Requirement on CA Flag for self-signed certificates is a potential security risk | ||||
| Description | We see products which are not accepting self-signed certificates which have the CA Flag set to TRUE due to security concerns. The specification in 1.05 states: The security concern is about the requirement to accept self-signed certificates where the CA Flag is set to TRUE for backward interoperability. Is this a hard requirement or should such certificates rather be rejected by default with a configuration option to accept them (individually). In any case the requirement changes need to be pushed back to 1.04 as well. | ||||
| Additional Information | Cloned for errate. | ||||
| Tags | No tags attached. | ||||
| Commit Version | |||||
| Fix Due Date | |||||
| related to | 0008357 | closed | Randy Armstrong | Requirement on CA Flag for self-signed certificates is a potential security risk |
| related to | 0008670 | closed | Randy Armstrong | Update from OpenSSL V1.x.x (EOL(end of live) soon) to V3.x.x |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2022-09-29 14:19 | Randy Armstrong | New Issue | |
| 2022-09-29 14:19 | Randy Armstrong | Status | new => assigned |
| 2022-09-29 14:19 | Randy Armstrong | Assigned To | => Randy Armstrong |
| 2022-09-29 14:19 | Randy Armstrong | Issue generated from: 0008357 | |
| 2022-09-29 14:19 | Randy Armstrong | Relationship added | related to 0008357 |
| 2022-09-29 14:29 | Randy Armstrong | Status | assigned => resolved |
| 2022-09-29 14:29 | Randy Armstrong | Resolution | open => fixed |
| 2022-09-29 14:29 | Randy Armstrong | Fixed in Version | => 1.04 |
| 2022-09-29 14:29 | Randy Armstrong | Note Added: 0017891 | |
| 2023-01-24 17:05 | Jim Luth | Status | resolved => closed |
| 2023-01-24 17:05 | Jim Luth | Note Added: 0018569 | |
| 2023-03-23 21:24 | Jim Luth | Relationship added | related to 0008670 |