[JIRA] Updated: (OSJ-4) Client cert auth eval should be conditional

Scott Cantor (JIRA) noreply at shibboleth.net
Thu Oct 18 00:23:21 EDT 2012


     [ https://issues.shibboleth.net/jira/browse/OSJ-4?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Scott Cantor updated OSJ-4:
---------------------------

      Component/s: Security
    Fix Version/s: 3.0.0

> Client cert auth eval should be conditional
> -------------------------------------------
>
>                 Key: OSJ-4
>                 URL: https://issues.shibboleth.net/jira/browse/OSJ-4
>             Project: OpenSAML - Java
>          Issue Type: Improvement
>          Components: Security
>            Reporter: Brent Putman
>            Assignee: Brent Putman
>             Fix For: 3.0.0
>
>
> Logic in client cert auth rule should be conditional based on binding and/or profile specific inputs.
> Known problem with current approach is that if there is (legitimately or otherwise) a client TLS cert present in the request, which does not belong to a system entity (for example, a SAML IdP authenticating users with client TLS), then the rule fails. The rule as it currently stands is primarily for evaluating peer system entity creds, not end-user TLS creds. 

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list