View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008373 | Compliance Test Tool (CTT) Unified Architecture | 1 - Script Issue | public | 2022-09-29 16:04 | 2022-11-17 21:27 |
Reporter | V. Monfort | Assigned To | Paul Hunkar | ||
Priority | normal | Severity | minor | Reproducibility | always |
Status | closed | Resolution | no change required | ||
Summary | 0008373: Security User Name Password 015.js (PolicyId unique) seems excessive | ||||
Description | The test checks that each PolicyId is completely unique for each endpoint description without considering that it might be the same UserTokenPolicy used for several combinations.
It seems a bit excessive to request the server to produce new PolicyId for a UserTokenPolicy with the exact same parameters reused in several contexts.
Moreover this is a rule for all UserTokenTypes. | ||||
Tags | No tags attached. | ||||
Files Affected | |||||
|
Can you provide the actual error being reported by the CTT (the error output)? |
|
The PolicyId: username, is used for multiple UserIdentityTokens. The PolicyId has to be unique within the server. |
|
After a second verification it seems it occurs only when the UserTokenPolicy SecurityPolicyUri is the default one (empty) and not if we use explicitly the same UserTokenPolicy SecurityPolicyUri as I stated in the example description. Sorry about that. In the particular case of the error log provided the UserTokenPolicy parameters are indeed exactly the same but the SecurityPolicyUri to use is deduced from the SecureChannel SecurityPolicyUri. As a consequence I guess it might be acceptable to consider those UserTokenPolicy differents since the SecurityPolicyUri becomes implicitly different depending on the SecureChannel configuration it is used on. |
|
As discussed in email chain - nothing to fix |
Date Modified | Username | Field | Change |
---|---|---|---|
2022-09-29 16:04 | V. Monfort | New Issue | |
2022-11-03 15:47 | Paul Hunkar | Status | new => feedback |
2022-11-03 15:47 | Paul Hunkar | Note Added: 0018097 | |
2022-11-03 16:06 | V. Monfort | Note Added: 0018098 | |
2022-11-03 16:06 | V. Monfort | Status | feedback => new |
2022-11-03 17:23 | V. Monfort | Note Added: 0018100 | |
2022-11-17 21:27 | Paul Hunkar | Assigned To | => Paul Hunkar |
2022-11-17 21:27 | Paul Hunkar | Status | new => closed |
2022-11-17 21:27 | Paul Hunkar | Resolution | open => no change required |
2022-11-17 21:27 | Paul Hunkar | Note Added: 0018163 |