dexter submitted this change.

View Change



1 is the latest approved patch-set.
No files were changed between the latest approved patch-set and the submitted one.

Approvals: jolly: Looks good to me, approved Jenkins Builder: Verified
proc_prfle_dwnld: Add TODO about missing profileMetadata check

Related: SYS#8100
Change-Id: I99aae5efa7f3ec16315d53dd3aaa67692d918672
---
M src/ipa/libipa/proc_prfle_dwnld.c
1 file changed, 9 insertions(+), 0 deletions(-)

diff --git a/src/ipa/libipa/proc_prfle_dwnld.c b/src/ipa/libipa/proc_prfle_dwnld.c
index e753408..c30442c 100644
--- a/src/ipa/libipa/proc_prfle_dwnld.c
+++ b/src/ipa/libipa/proc_prfle_dwnld.c
@@ -62,6 +62,15 @@
else if (!get_bnd_prfle_pkg_res->get_bnd_prfle_pkg_ok)
goto error;

+ /* TODO: SGP.32, section 3.2.3.2, step 19 requires us to compare the SGP32_StoreMetadataRequest from
+ pars->auth_clnt_ok_dpe->profileMetaData (optional field) against the SGP32_StoreMetadataRequest from
+ the ES8+ StoreMetadata (see SGP.22, section 5.5.3) function call in the BoundProfilePackage we have
+ just received.
+
+ The ES8+ StoreMetadata function call is not encrypted, so we can decode it and extract the
+ SGP32_StoreMetadataRequest contents from it. Then we can do the comparison. In case a mismatch is
+ detected, the session should be cancelled (metadataMismatch) */
+
/* In case of error it is the responsibility of the caller to call the Common Cancel Session procedure.
* In case of success, the caller should ask the user for consent before continuing with the profile
* installation. */

To view, visit change 43427. To unsubscribe, or for help writing mail filters, visit settings.

Gerrit-MessageType: merged
Gerrit-Project: onomondo-ipa
Gerrit-Branch: master
Gerrit-Change-Id: I99aae5efa7f3ec16315d53dd3aaa67692d918672
Gerrit-Change-Number: 43427
Gerrit-PatchSet: 2
Gerrit-Owner: dexter <pmaier@sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier@sysmocom.de>
Gerrit-Reviewer: jolly <andreas@eversberg.eu>