View Issue Details

IDProjectCategoryView StatusLast Update
000379110000-007: ProfilesSpecpublic2017-06-06 15:17
ReporterKarl Deiretsbacher Assigned ToKarl Deiretsbacher  
PrioritynormalSeveritymajorReproducibilityhave not tried
Status closedResolutionfixed 
Summary0003791: Replace Security Policies that use Sha1
Description

Now that SHA1 is officially broken we need to specify new profiles.
Profiles with Sha1 have to be deprecated.

TagsNo tags attached.
Commit Version
Fix Due Date

Relationships

related to 0003769 closedKarl Deiretsbacher Core Client & security 

Activities

Karl Deiretsbacher

2017-04-25 11:30

developer   ~0008006

One of these policies "Base128Rsa15" is a required policy in several Profiles. This requires creating new versions of these Profiles.

To avoid this in future we could replace specific policies with a CU:
"Support at least one Security Policy that is not obsolete.
Obsolete Security Policies shall not be enabled / usable without user / operator intervention.
Support of multiple Security Policies - even obsolete ones - is recommended. This will provide best interoperability and allows the end user to choose the required level of security."

Karl Deiretsbacher

2017-06-06 15:17

developer   ~0008213

Added new policies to Part 7 in v1.04.17.

Jim Luth

2017-06-06 15:17

administrator   ~0008214

Agreed to changes in telecon.

Issue History

Date Modified Username Field Change
2017-04-03 11:59 Karl Deiretsbacher New Issue
2017-04-23 10:21 Karl Deiretsbacher Assigned To => Karl Deiretsbacher
2017-04-23 10:21 Karl Deiretsbacher Status new => assigned
2017-04-25 11:30 Karl Deiretsbacher Note Added: 0008006
2017-04-25 11:49 Karl Deiretsbacher Relationship added related to 0003769
2017-06-06 15:17 Karl Deiretsbacher Note Added: 0008213
2017-06-06 15:17 Karl Deiretsbacher Status assigned => resolved
2017-06-06 15:17 Karl Deiretsbacher Fixed in Version => 1.04
2017-06-06 15:17 Karl Deiretsbacher Resolution open => fixed
2017-06-06 15:17 Jim Luth Note Added: 0008214
2017-06-06 15:17 Jim Luth Status resolved => closed