View Issue Details

IDProjectCategoryView StatusLast Update
001061110000-004: ServicesSpecpublic2025-11-13 11:32
ReporterRandy Armstrong Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status newResolutionopen 
Product Version1.05.06 
Target Version1.05.07 RC1 
Summary0010611: 7.41.5 X509IdentityTokens - Need to Clarify what Happens with ECC and RSA support.
Description

ECC introduces a need to support UserTokenSignatures that have public key algorithms that are not supported for the SecureChannel.

Text needs to be added to call this out use case to ensure implementers do not miss it.

Additional Information

This token shall always be accompanied by a Signature in the userTokenSignature parameter of ActivateSession if required by the SecurityPolicy. The Server shall specify a SecurityPolicy for the UserTokenPolicy if the SecureChannel has a SecurityPolicy with a different CertificateKeyAlgorithm and/or AsymmetricSignatureAlgorithm. Servers that support multiple CertificateKeyAlgorithms for a UserCertificate shall provide a distinct UserTokenPolicy for each CertificateKeyAlgorithm supported.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-11-13 11:17 Randy Armstrong New Issue
2025-11-13 11:31 Randy Armstrong Description Updated
2025-11-13 11:32 Randy Armstrong Description Updated
2025-11-13 11:32 Randy Armstrong Description Updated