OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ebxml-msg message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] (EBXMLMSG-53) Preventing replay attack for PullRequest


Sander Fieten created EBXMLMSG-53:
-------------------------------------

             Summary: Preventing replay attack for PullRequest
                 Key: EBXMLMSG-53
                 URL: https://issues.oasis-open.org/browse/EBXMLMSG-53
             Project: OASIS ebXML Messaging Services TC
          Issue Type: Improvement
          Components: AS4 Profile
            Reporter: Sander Fieten
            Priority: Minor


Section 7.11.3 of the ebMS Core Spec includes a recommendation how to prevent replay attacks on pull requests. This is based on At-Most-Once reliability and use of WSS.

Shouldn't AS4 also include such a recommendation based on the options specified for authentication and authorization of the PullRequest?



--
This message was sent by Atlassian JIRA
(v6.2.2#6258)


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]