← Prev in month ← Prev in thread
Next in thread → Next in month →

Issue 109: Potential attack when using RST parameters from a targetsite - WS-SecurityPolicy part

From
Marc Goodner <>
Date
2006-08-25T17:11:58+00:00
ID
Thread
Issue 109: Potential attack when using RST parameters from a targetsite - WS-SecurityPolicy part
Issue 109

 

From: Jan Alexander 

Sent: Friday, August 25, 2006 9:20 AM

To: 

Cc: Marc Goodner

Subject: New Issue: Potential attack when using RST parameters from a
target site - WS-SecurityPolicy part

 

PLEASE
DO NOT REPLY TO THIS EMAIL OR START A DISCUSSISON THREAD UNTIL THE ISSUE IS
ASSIGNED A NUMBER.  

 

The
issues coordinators will notify the list when that has occurred.

 

Protocol: 
ws-securitypolicy

 

http://www.oasis-open.org/apps/org/workgroup/ws-sx/download.php/18837/ws-securitypolicy-1.2-spec-ed-01-r07.pdf

 

Artifact:  spec

 

Type: design

 

Title:
Potential
attack when using RST parameters from a target site - WS-SecurityPolicy part

 

Description:

The
RequestSecurityTokenTemplate parameter of the IssuedToken assertion is critical
to allow generalized token issuance policy, but allows possible RST parameter
attacks because the requestor's parameters cannot be separated from those
specified for the target site. See the description of the attack in the related
WS-Trust issue description.

 

Related
issues:

The
same issue, WS-Trust part

 

Proposed
Resolution:

Change
the description of RequestSecurityTokenTemplate element on lines 910 - 914 to
say that the contents is inserted into the wst:SecondaryParameters element of
the RST instead of being placed directly as children of the
wst:RequestSecurityToken element.
← Prev in month ← Prev in thread
Next in thread → Next in month →