OxalisCommunity / oxalis

Oxalis - PEPPOL Access Point open source implementation - Core component
Other
129 stars 90 forks source link

Query on handling the Inbound Documents via Peppol #268

Closed VijayaKumar2 closed 8 years ago

VijayaKumar2 commented 8 years ago

Hi All,

We are using the following version of Oxalis, : https://peppolap.everbinding.nl/as2

version.oxalis: 3.0.2-SNAPSHOT version.java: 1.7.0_51 oxalis.operation.mode: PRODUCTION oxalis.pki.version: V2 oxalis.sml.hostname: edelivery.tech.ec.europa.eu certificate.subject: O=eConnect International B.V.,CN=APP_1000000187,C=NL certificate.issuer: CN=PEPPOL ACCESS POINT CA,O=NATIONAL IT AND TELECOM AGENCY,C=DK certificate.expired: false build.id: ${git.commit.id} build.tstamp: ${git.commit.time}

and Inbound and Outbound is working fine for us.

**Now the questions is,

  1. One of the SI members was able to send a document via PEPPOL to us only using a self signed certificate. Is it a security vulnerability? If yes Where can we handle this in Oxalis level ?**

Thanks in Advance, VijayaKumar

steinarcook commented 8 years ago

Your Oxalis installation is outdated. You should at least use a final build, i.e. not a "SNAPSHOT" version.

I urge you to update to the latest version as several security holes have been fixed.

VijayaKumar2 commented 8 years ago

Hi,

Which version should we need to update, since we are in production environment now, Is there any impact for these upgrade ?

Thanks, Vijay

On Mon, Oct 3, 2016 at 2:07 PM, Steinar Overbeck Cook < notifications@github.com> wrote:

Closed #268 https://github.com/difi/oxalis/issues/268.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/difi/oxalis/issues/268#event-809964249, or mute the thread https://github.com/notifications/unsubscribe-auth/AInYTXfNqDyaNOgStNnbBJqNVuWbuNG5ks5qwL7HgaJpZM4KMSn_ .