Uploaded image for project: 'SoftHSM'
  1. SoftHSM
  2. SOFTHSM-58

Not checking user authorization

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 2.0.0
    • Fix Version/s: 2.0.0
    • Component/s: PKCS#11 Interface
    • Labels:
      None

      Description

      Many functions are missing to check if the user is allowed to use the object in the crypto operation (missing a call to haveRead()).

      C_Sign, C_Verify, C_Encrypt, C_Decrypt, ...

      We must go through the different PKCS#11-functions and check this. Also to update the test cases to include unauthorized usage of key objects.

        Attachments

          Activity

            People

            Assignee:
            rickard Rickard Bellgrim
            Reporter:
            rickard Rickard Bellgrim
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: