← Prev in month
← Prev in thread
Next in thread →
Next in month →
Issue 109: Potential attack when using RST parameters from a targetsite - WS-SecurityPolicy part
Issue 109 From: Jan Alexander Sent: Friday, August 25, 2006 9:20 AM To: Cc: Marc Goodner Subject: New Issue: Potential attack when using RST parameters from a target site - WS-SecurityPolicy part PLEASE DO NOT REPLY TO THIS EMAIL OR START A DISCUSSISON THREAD UNTIL THE ISSUE IS ASSIGNED A NUMBER. The issues coordinators will notify the list when that has occurred. Protocol: ws-securitypolicy http://www.oasis-open.org/apps/org/workgroup/ws-sx/download.php/18837/ws-securitypolicy-1.2-spec-ed-01-r07.pdf Artifact: spec Type: design Title: Potential attack when using RST parameters from a target site - WS-SecurityPolicy part Description: The RequestSecurityTokenTemplate parameter of the IssuedToken assertion is critical to allow generalized token issuance policy, but allows possible RST parameter attacks because the requestor's parameters cannot be separated from those specified for the target site. See the description of the attack in the related WS-Trust issue description. Related issues: The same issue, WS-Trust part Proposed Resolution: Change the description of RequestSecurityTokenTemplate element on lines 910 - 914 to say that the contents is inserted into the wst:SecondaryParameters element of the RST instead of being placed directly as children of the wst:RequestSecurityToken element.
← Prev in month
← Prev in thread
Next in thread →
Next in month →