- **Type**: defect --> enhancement
- **Comment**:

I find this ticket hard to understand.
The current level of support for authentication and authorization is at
the level of the posic group. 

Why would anyone go to the trouble of faking a handle if they have
access to the group, i.e. 100% access to the system as a whole anyway?
Much simpler is to just open a fresh handle.

Changing this from defect to enhancement for now.
But the ticket also needs clarification on what problem is to be solved.



---

** [tickets:#1163] IMM: no verification of handle and msg source correlation**

**Status:** unassigned
**Milestone:** 4.5.1
**Created:** Wed Oct 08, 2014 04:03 PM UTC by Hans Feldt
**Last Updated:** Thu Oct 09, 2014 07:00 AM UTC
**Owner:** nobody

This is a continuation of https://sourceforge.net/p/opensaf/tickets/938/
Each message received that contains a handle must be verified to be from the 
correct mds source to prevent package spoofing.


---

Sent from sourceforge.net because [email protected] is 
subscribed to https://sourceforge.net/p/opensaf/tickets/

To unsubscribe from further messages, a project admin can change settings at 
https://sourceforge.net/p/opensaf/admin/tickets/options.  Or, if this is a 
mailing list, you can unsubscribe from the mailing list.
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk
_______________________________________________
Opensaf-tickets mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensaf-tickets

Reply via email to