Bug 411184 - QCA: Channel binding support
Summary: QCA: Channel binding support
Status: REPORTED
Alias: None
Product: qca
Classification: Frameworks and Libraries
Component: general (show other bugs)
Version: Git
Platform: Other All
: NOR wishlist
Target Milestone: ---
Assignee: Ivan Romanov
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-08-22 17:59 UTC by Neustradamus
Modified: 2024-01-21 18:15 UTC (History)
4 users (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Neustradamus 2019-08-22 17:59:46 UTC
Change requests for 2 plugins: qca-ossl and qca-cyrus-sasl:
- First plugin should have some API to return data from SSL_get_finished()
- Second one should have some API to accept this data and also to push it down to cyrus-sasl

https://paquier.xyz/postgresql-2/channel-binding-openssl/
Comment 1 Neustradamus 2019-09-09 21:20:19 UTC
Linked to RFC5929: Channel Bindings for TLS
- https://tools.ietf.org/html/rfc5929
- https://www.iana.org/assignments/channel-binding-types/channel-binding-types.xhtml
Comment 2 Neustradamus 2023-11-05 00:40:46 UTC
I have done a ticket for RFC 9266: Channel Bindings for TLS 1.3:
- https://bugs.kde.org/show_bug.cgi?id=476562

I think that you have seen the jabber.ru MITM:
- https://notes.valdikss.org.ru/jabber.ru-mitm/
- https://snikket.org/blog/on-the-jabber-ru-mitm/
- https://www.devever.net/~hl/xmpp-incident
- https://blog.jmp.chat/b/certwatch
Comment 3 Neustradamus 2024-01-15 18:04:02 UTC
Dear QCA team members,

I wish you a Happy New Year 2024!

After some comments, an email sent to security@qt.io, there is an important comment about my original ticket about Channel Binding and Qt, I think that you can do an answer here? You are impacted...
- https://bugreports.qt.io/browse/QTBUG-77783?focusedId=768178&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-768178

Thanks in advance.
Comment 4 Albert Astals Cid 2024-01-21 18:15:59 UTC
Why do you keep spamming bugs? There's 0 need to write the same comment here and in https://bugs.kde.org/show_bug.cgi?id=476562

The only thing you achieve by that is your reports being more ignored because of your behaviour