View Issue Details

IDProjectCategoryView StatusLast Update
000910810000-004: ServicesSpecpublic2025-03-10 20:47
ReporterMatthias Isele Assigned ToMatthias Damm  
Status resolvedResolutionfixed 
Target Version1.05.03 RC1Fixed in Version1.05.06 RC1 
Summary0009108: Clarification for comparing UserTokens

The specification states (ActivateSession - Description):
"In addition, the Server shall verify that the Client supplied a UserIdentityToken that is identical to the token currently associated with the Session."

It's not clear which parameters of the UserTokens need to be evaluated for the different TokenTypes.
E.g. The UserNameIdentityToken has 4 parameter (policyId, userName, password, encryptionAlgorithm). In this case it's obvious that the password shall not be evaluated for comparing the user token. However it's not explicitly stated.

TagsNo tags attached.
Commit Version
Fix Due Date


Jim Luth

2023-09-26 15:48

administrator   ~0020058

Determine if we can eliminate this check entirely. Validating the Client Application Cert is the same should be sufficient.

Matthias Isele

2025-03-04 12:30

developer   ~0022454

The section I refered to is about a subsequent call to ActivateSession with a new SecureChannel. In that case the requirement that the UserIdentityToken is that same makes sense.
I suggest to check for the same ClientUserId. How ClientUserId are built is described in other places of the specification.

Matthias Damm

2025-03-10 20:47

developer   ~0022502

Added clarification that the UserIdentityToken compare is done based on the ClientUserId

Issue History

Date Modified Username Field Change
2023-08-17 13:21 Matthias Isele New Issue
2023-08-17 13:23 Matthias Isele Summary Clarification => Clarification for comparing UserTokens
2023-09-26 15:48 Jim Luth Note Added: 0020058
2023-09-26 15:54 Jim Luth Assigned To => Matthias Damm
2023-09-26 15:54 Jim Luth Status new => assigned
2025-03-04 12:30 Matthias Isele Note Added: 0022454
2025-03-10 20:47 Matthias Damm Status assigned => resolved
2025-03-10 20:47 Matthias Damm Resolution open => fixed
2025-03-10 20:47 Matthias Damm Fixed in Version => 1.05.06 RC1
2025-03-10 20:47 Matthias Damm Note Added: 0022502