View Issue Details

IDProjectCategoryView StatusLast Update
000987510000-007: ProfilesSpecpublic2024-10-16 15:35
ReporterRandy Armstrong Assigned ToRandy Armstrong  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionno change required 
Summary0009875: Update Profile to require that SignOnly mode be disabled by default.
Description

ARP Poisoning and STP attack are well known vulnerabilities that affect all IP networks. Modern commercial routers have protections built in but they must be configured.

To protect against misconfiguration or routers that lack the protections, applications should encrypt all messages.

Making SignOnly disabled by default will reduce the likelyhood of SignOnly being used on bad networks.

TagsNo tags attached.
Commit Version
Fix Due Date

Relationships

related to 0009874 new 10000-002: Security Need to Address ARP Poisoning and Spanning Tree Protocol (STP) attacks 

Activities

Randy Armstrong

2024-10-16 15:35

administrator   ~0021899

WG decided this is not necessary for OT because the network is well understood.

Issue History

Date Modified Username Field Change
2024-10-09 15:22 Randy Armstrong New Issue
2024-10-09 15:22 Randy Armstrong Issue generated from: 0009874
2024-10-09 15:22 Randy Armstrong Project 10000-002: Security => 10000-007: Profiles
2024-10-09 15:23 Randy Armstrong Relationship added related to 0009874
2024-10-16 15:35 Randy Armstrong Assigned To => Randy Armstrong
2024-10-16 15:35 Randy Armstrong Status new => closed
2024-10-16 15:35 Randy Armstrong Resolution open => no change required
2024-10-16 15:35 Randy Armstrong Note Added: 0021899