OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Created: (SECURITY-17) PE: Need discussion of various TLS vulnerabilities in Security Considerations


PE: Need discussion of various TLS vulnerabilities in Security Considerations
-----------------------------------------------------------------------------

                 Key: SECURITY-17
                 URL: http://tools.oasis-open.org/issues/browse/SECURITY-17
             Project: OASIS Security Services (SAML) TC
          Issue Type: Improvement
    Affects Versions: Version 2.0
            Reporter: Scott Cantor
             Fix For: 2.0 incorporating Approved Errata


We discuss some SSL/TLS issues in the Security Considerations doc, but we probably need to refresh that material in light of all the attacks that have emerged. The renegotiation bug comes to mind, as well as the Beast attacks.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]