View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008532 | 10000-012: Discovery | Spec | public | 2022-12-14 11:55 | 2023-05-30 18:29 |
Reporter | Zbynek Zahradnik | Assigned To | Randy Armstrong | ||
Priority | normal | Severity | minor | Reproducibility | always |
Status | assigned | Resolution | open | ||
Product Version | 1.05.02 | ||||
Target Version | ?.?? | ||||
Summary | 0008532: Interoperability problems when GDS returns private key in PFX format | ||||
Description | I have observed interoperability problems when the client calls the StartNewKeyPairRequest and requests the privateKeyFormat format as PFX (and retrieves it using FinishRequest). PFX is a container, and can contain just the private key. And that is indeed what OpenSSL-based implementations of GDS will do/are doing currently. They return the PFX which contains only the private key (which is correct per the UA spec). There are, however, following problems with such PFX: What works for (1) and (2) above is when the PFX also contains the certificate itself. I suggest that the spec is changed to require the PFX to contain both the private and the certificate. | ||||
Tags | No tags attached. | ||||
Commit Version | |||||
Fix Due Date | |||||
Date Modified | Username | Field | Change |
---|---|---|---|
2022-12-14 11:55 | Zbynek Zahradnik | New Issue | |
2023-03-23 21:54 | Jim Luth | Note Added: 0019032 | |
2023-03-23 21:54 | Jim Luth | Assigned To | => Randy Armstrong |
2023-03-23 21:54 | Jim Luth | Status | new => assigned |
2023-05-30 18:29 | Jim Luth | Target Version | 1.05.03 => ?.?? |