View Issue Details

IDProjectCategoryView StatusLast Update
001064310000-004: ServicesSpecpublic2025-11-30 23:38
ReporterRandy Armstrong Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityalways
Status assignedResolutionopen 
Product Version1.05.07 RC1 
Target Version1.05.07 RC1 
Summary0010643: ClientSignature, ServerSignature and UserTokenSignatures are vulnerable to hijacking
Description

The current signature algorithm uses data provided by an untrusted party to generate signatures.
This increases the attack surface and makes servers more vulnerable when an application certificate is stolen.

Need to define a signature algorithm that ties the signatures to data supplied by both sides and, when possible, the secure channel active when the signature is created.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-11-30 23:37 Randy Armstrong New Issue
2025-11-30 23:37 Randy Armstrong Status new => assigned
2025-11-30 23:37 Randy Armstrong Assigned To => Randy Armstrong