potiuk commented on PR #2575: URL: https://github.com/apache/plc4x/pull/2575#issuecomment-4627148711
Thanks @chrisdutz — approval much appreciated, and all 11 notes are folded in. Highlights: - **OPC UA defaults → secure-by-default:** §14 Q14/Q15/Q16 now record that the insecure defaults aren't the supported posture. In particular the permissive certificate verifier is marked a **gap to fix (`VALID`)**, not `OUT-OF-MODEL`, per your "should be changed and reported" — the §9 false-friend entry and §13 disposition table are updated to match. - **SPI3 forward-references** captured as *(maintainer)* notes: `tls`/`tls-psk` transport (Q8), ETS/XML parser hardening (Q18), per-connection fixed-length ring-buffer bounding allocation (Q11/Q19), the optional debug filesystem audit-log, and the spi-module restructuring. - **Clarifications** folded into §9: nonces are protocol-provided only (none beyond spec); PLC4X proxies the target PLC's permission checks and provides none of its own. On the OPC UA cert default — happy to help file a tracking issue in the PLC4X tracker if useful, but I'll leave that to the PMC. I've replied on and resolved the threads; the model is the PMC's to merge whenever. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
