I think the ticket probably is attempting to talk about session security, if 
not physical security. But then, if a CLI session (ssh, telnet) is compromised 
there could be any kind of attack and not just identity theft.

Session security, physical security, and the likes are probably not problems 
that OpenSAF has to solve!
I have had my own doubts and difficulty in understanding this ticket. Packet 
integrity check(or security) should probably be dealt with by the 
entity/application that is doing the actual talk/transmission over the north 
bound mechanism(snmp, cli, rest, rpc, etc).


---

** [tickets:#1163] IMM: no verification of handle and msg source correlation**

**Status:** unassigned
**Milestone:** future
**Created:** Wed Oct 08, 2014 04:03 PM UTC by Hans Feldt
**Last Updated:** Wed Nov 26, 2014 08:59 AM UTC
**Owner:** nobody

This is a continuation of https://sourceforge.net/p/opensaf/tickets/938/
Each message received that contains a handle must be verified to be from the 
correct mds source to prevent package spoofing.


---

Sent from sourceforge.net because [email protected] is 
subscribed to https://sourceforge.net/p/opensaf/tickets/

To unsubscribe from further messages, a project admin can change settings at 
https://sourceforge.net/p/opensaf/admin/tickets/options.  Or, if this is a 
mailing list, you can unsubscribe from the mailing list.
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk
_______________________________________________
Opensaf-tickets mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensaf-tickets

Reply via email to