Skip to content
This repository has been archived by the owner on Oct 25, 2024. It is now read-only.

Validate date header to protect against replay attacks #2

Open
cveilleux opened this issue Apr 19, 2018 · 0 comments
Open

Validate date header to protect against replay attacks #2

cveilleux opened this issue Apr 19, 2018 · 0 comments

Comments

@cveilleux
Copy link

The http-signature security audit recommends that server implementations validate the required Date header to be within a 5 minutes skew interval.

https://web-payments.org/specs/source/http-signatures-audit/#replay-http

Excerp:

As the default scheme is to include the Date header in the signature, service providers SHOULD protect against logged replay attacks by enforcing a clock skew. The server SHOULD be synchronized with NTP, and the recommendation is to allow 300 seconds of clock skew (in either direction).

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant