View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0008532 | 10000-012: Discovery | Spec | public | 2022-12-14 11:55 | 2025-06-10 15:35 |
| Reporter | Zbynek Zahradnik | Assigned To | Randy Armstrong | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Product Version | 1.05.02 | ||||
| Target Version | ?.?? | Fixed in Version | 1.05.05 RC1 | ||
| Summary | 0008532: Interoperability problems when GDS returns private key in PFX format | ||||
| Description | I have observed interoperability problems when the client calls the StartNewKeyPairRequest and requests the privateKeyFormat format as PFX (and retrieves it using FinishRequest). PFX is a container, and can contain just the private key. And that is indeed what OpenSSL-based implementations of GDS will do/are doing currently. They return the PFX which contains only the private key (which is correct per the UA spec). There are, however, following problems with such PFX: What works for (1) and (2) above is when the PFX also contains the certificate itself. I suggest that the spec is changed to require the PFX to contain both the private and the certificate. | ||||
| Tags | Errata Needed to Close | ||||
| Commit Version | 1.05.05 RC1 | ||||
| Fix Due Date | |||||
|
|
Clarify the PFX must contain the public cert and the private key. |
|
|
Now require the Certificate in PFX private key packages in 7.9.4 |
|
|
Agreed to text in 1.05. Needs 1.04 Errata to Close. |
|
|
Added errata. |
|
|
Agreed to 1.04.13 Errata. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2022-12-14 11:55 | Zbynek Zahradnik | New Issue | |
| 2023-03-23 21:54 | Jim Luth | Note Added: 0019032 | |
| 2023-03-23 21:54 | Jim Luth | Assigned To | => Randy Armstrong |
| 2023-03-23 21:54 | Jim Luth | Status | new => assigned |
| 2023-05-30 18:29 | Jim Luth | Target Version | 1.05.03 => ?.?? |
| 2024-12-06 02:57 | Randy Armstrong | Status | assigned => resolved |
| 2024-12-06 02:57 | Randy Armstrong | Resolution | open => fixed |
| 2024-12-06 02:57 | Randy Armstrong | Fixed in Version | => 1.05.05 RC1 |
| 2024-12-06 02:57 | Randy Armstrong | Commit Version | => 1.05.05 RC1 |
| 2024-12-06 02:57 | Randy Armstrong | Note Added: 0022182 | |
| 2024-12-12 19:18 | Jim Luth | Note Added: 0022207 | |
| 2024-12-12 19:19 | Jim Luth | Tag Attached: Errata Needed to Close | |
| 2025-06-10 06:30 | Randy Armstrong | Note Added: 0022996 | |
| 2025-06-10 15:35 | Jim Luth | Status | resolved => closed |
| 2025-06-10 15:35 | Jim Luth | Note Added: 0023001 |