Active
Project:
Belgium eID Login
Version:
6.x-1.1
Component:
Miscellaneous
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
25 Feb 2010 at 12:02 UTC
Updated:
4 Sep 2010 at 13:58 UTC
Jump to comment: Most recent
Comments
Comment #1
amedee-1 commentedAs you can see in eid.install, firstname lastname and rrk are stored:
Now I am a bit worried about the rrk field with a length of 11, becasue the national number is also 11 long. Coincidence?
In another piece of code I saw that a serial number is read. I'm not sure if it's the certificate serial number, or the national number.
In the eID docs issued by Fedict, they also speak of SSL_CLIENT_S_DN_serialNumber to get or set the national number.
Somebody is even more convinced that there is a problem, but I'm not sure, I'm not a top Drupal coder and I have not yet read all of the code.
http://www.zionsecurity.com/blog/2010/2/26/unsecure-implementation-of-ei...
Comment #2
Anonymous (not verified) commentedsubscribe
Comment #3
coworksbe commentedAt this point, there are some security concerns regarding this module. We are investigating those issues to perform the nescessary steps. More news coming soon.
Comment #4
amedee-1 commentedfeature request changed to bug report, and subscribing.
Comment #5
Pheatus commentedsubscribe
Comment #6
domidc commentedsubscribe
Comment #7
sonjan commentedsubscribe