OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Updated: (SECURITY-17) PE: Need discussion of various TLS vulnerabilities in Security Considerations


     [ http://tools.oasis-open.org/issues/browse/SECURITY-17?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Scott Cantor updated SECURITY-17:
---------------------------------

      Component/s: Security Considerations
    Fix Version/s:     (was: Version 2.0 + Approved Errata 05)

> PE: Need discussion of various TLS vulnerabilities in Security Considerations
> -----------------------------------------------------------------------------
>
>                 Key: SECURITY-17
>                 URL: http://tools.oasis-open.org/issues/browse/SECURITY-17
>             Project: OASIS Security Services (SAML) TC
>          Issue Type: Improvement
>          Components: Security Considerations
>    Affects Versions: Version 2.0
>            Reporter: Scott Cantor
>
> We discuss some SSL/TLS issues in the Security Considerations doc, but we probably need to refresh that material in light of all the attacks that have emerged. The renegotiation bug comes to mind, as well as the Beast attacks.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]