View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0010643 | 10000-004: Services | Spec | public | 2025-11-30 23:37 | 2025-11-30 23:38 |
| Reporter | Randy Armstrong | Assigned To | Randy Armstrong | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | assigned | Resolution | open | ||
| Product Version | 1.05.07 RC1 | ||||
| Target Version | 1.05.07 RC1 | ||||
| Summary | 0010643: ClientSignature, ServerSignature and UserTokenSignatures are vulnerable to hijacking | ||||
| Description | The current signature algorithm uses data provided by an untrusted party to generate signatures. Need to define a signature algorithm that ties the signatures to data supplied by both sides and, when possible, the secure channel active when the signature is created. | ||||
| Tags | No tags attached. | ||||
| Commit Version | |||||
| Fix Due Date | |||||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-11-30 23:37 | Randy Armstrong | New Issue | |
| 2025-11-30 23:37 | Randy Armstrong | Status | new => assigned |
| 2025-11-30 23:37 | Randy Armstrong | Assigned To | => Randy Armstrong |