My favorites | Sign in
Logo
                
New issue | Search
for
| Advanced search | Search tips
Issue 176: Protect Provider accounts from replay attacks at other 1.0 RPs
  Back to list
Status:  Fixed
Owner:  andrewarnott
Closed:  Mar 2009
Type-Enhancement
Priority-Medium
Release-3.0


Sign in to add a comment
 
Reported by andrewarnott, Dec 26, 2008
Add feature in OP-side of the OpenID library to never use shared
associations with RP 1.0 clients when sending assertions, thereby forcing
them to send a check_auth mesage, allowing the OP to check for replay attacks.

Comment 1 by andrewarnott, Mar 05, 2009
Added OpenID Provider downlevel protection for 1.x Relying Parties and turning it on 
by default.

master c282f35b8cca
Status: Fixed
Sign in to add a comment

Hosted by Google Code