View Issue Details

IDProjectCategoryView StatusLast Update
000947410000-012: DiscoverySpecpublic2024-06-11 18:52
ReporterMatthias Damm Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Product Version1.05.02 
Target Version1.05.04 RC1Fixed in Version1.05.04 RC1 
Summary0009474: Enhancements for G.1 Application Setup with Pull Management
Description

G.1 Application Setup with Pull Management

Current definition:
After establishing a secure channel with the CertificateManager, the Application shall provide user credentials which allow it to register new applications and request new Certificates. The credentials may be provided by prompting a user or they may be one time use credentials delivered via some out of band mechanism such as a web site during the installation process.

Issue:
The whole StartSigningRequest/FinishRequest is build to allow the confirmation of the request in the GDS. It is even stated in FinishRequest "It is expected that a Client will periodically call this Method until an entity with access to the RegistrationAuthorityAdmin Role has approved the request"
Therefore we must allow Anonymous if the approval is done on the GDS side.

Proposed change
Add the following text:
The Application shall also allow the option for Anonymous user for the case where the CertificateManager supports approval of the registration and Certificate request by an administrator of the CertificateManager.


Current definition:
Once an Application has received its first Certificate then the Certificate can be used in lieu of user credentials when the Application needs to renew its Certificate or update its Trust List.

Issue:
We must make sure the client does not assume the user credential stays valid, can be persisted and used for following updates. Therefore we should clearly state that the credentials are NOT stored after the initial setup is completed.

Proposed addition to the above definition:
Change "then the Certificate can be used" to "then the Certificate with Anonymous user shall be used"
Add the following text:
The user credentials shall not be persisted in the Application after the initial setup with the GDS is completed.

TagsNo tags attached.
Commit Version1.05.04 RC
Fix Due Date

Relationships

related to 0009195 closedRandy Armstrong Define more details about recommended behaviour for "setup state" and TOFU 

Activities

Matthias Damm

2024-03-17 16:27

developer   ~0020914

Must be moved to Part 12 - not sure why it was created for Part 14

Randy Armstrong

2024-06-11 18:52

administrator   ~0021302

Updated text during in F2F review.

Jim Luth

2024-06-11 18:52

administrator   ~0021303

Agreed to changes in Virtual F2F.

Issue History

Date Modified Username Field Change
2024-03-17 15:46 Matthias Damm New Issue
2024-03-17 15:46 Matthias Damm Status new => assigned
2024-03-17 15:46 Matthias Damm Assigned To => Randy Armstrong
2024-03-17 15:47 Matthias Damm Relationship added related to 0009195
2024-03-17 15:49 Matthias Damm Description Updated
2024-03-17 16:27 Matthias Damm Note Added: 0020914
2024-03-19 16:53 Jim Luth Project 10000-014: PubSub => 10000-012: Discovery
2024-06-11 18:52 Randy Armstrong Status assigned => resolved
2024-06-11 18:52 Randy Armstrong Resolution open => fixed
2024-06-11 18:52 Randy Armstrong Note Added: 0021302
2024-06-11 18:52 Jim Luth Status resolved => closed
2024-06-11 18:52 Jim Luth Fixed in Version => 1.05.04 RC1
2024-06-11 18:52 Jim Luth Commit Version => 1.05.04 RC
2024-06-11 18:52 Jim Luth Note Added: 0021303