Uploaded image for project: 'Rampart'
  1. Rampart
  2. RAMPART-108

Policy Validator doesn't check the transport when Transport binding is used with HttpsToken

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.4
    • None
    • None

    Description

      When a transport security binding is used wih HttpsToken, PolicyBasedValidator doesn't check whether the incoming transport was HTTPS. This allows a service to be accessed via HTTP ( violating the policy), if a HTTP endpoint is available.

      Attachments

        Activity

          People

            nandana.cse Nandana Mihindukulasooriya
            nandana.cse Nandana Mihindukulasooriya
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: