Project

General

Profile

Actions

Feature #795

closed

Verbindung - Anmeldung zu "Mein Elster" mit eperso über z.B. Ubuntu usw.

Added by Marko Preuss over 4 years ago. Updated about 4 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Start date:
01/21/2020
Due date:
% Done:

0%

Estimated time:
Reviewer:
Build Version:

Description

Hallo
Der Kontakt mit Elster teilt mit:

"
leider ist die Open Ecard App in Verbindung mit dem Personalausweis und dem ELSTER eID Server nicht funktionsfähig. Das betrifft die Open Ecard App generell, nicht nur die Linux Anwendung. Ursache ist die Umsetzung verschiedener Spezifikationsstände im eID Server und der Open Ecard App.

Linux Nutzer können den als Open Source bereitgestellten Quellcode der AusweisApp2 (https://github.com/Governikus/AusweisApp2) herunterladen und kompilieren. Vorteil dieser Lösung ist auch die mögliche Nutzung des Handys (Android/iOS) als Kartenleser.
"

Sie sagen es funktioniert wohl nicht mit OpeneCard, kann das sein?

Gruß


Files

Actions #1

Updated by Tobias Wich over 4 years ago

  • Status changed from New to Rejected

This is a duplicate of #640.

Unfortunately this is the case. As it can be seen in the referenced issue, this is a problem for a long time. In a nutshell, the eID Server is set up in a way that a same origin check (SOP) fails and the app terminates. They claim that for attached eID Servers using SAML this check must not be performed, but after reading the relevant parts of TR 03124 and TR 03130, we came to the conclusion that a SOP check is required. The issue contains excerpts of these sections.
It basically boils down to the fact that an attached eID Server is a construct where the eID Server and the eService are reachable under the same domain. Their interpretation is that only the SAML SP must be reachable under the same domain. This however breaks the strong channel binding between eService and eID-Server, which is established through the eService URL in the Authorisation Certificate (Berechtigungszertifikat).

Now considering that the Open eCard App was certified, there were tests executed during this process, proving that the termination criteria are correctly implemented. Obviously this is also the case for the AusweisApp2, which leads me to the conclusion that there is probably some deficiency in the testing process. The right way to deal with this situation is to let the officials from the BSI clarify what the intended behaviour of the system should be. We'll gladly adapt the code then, in the case we are doing it wrong. It turned out to be quite difficult to get a disputing statement. The provider/ eID Server manufacturer of course have the same point of view. Their software is checked and so there will be no change without an official instruction to change the behaviour.

Actions #2

Updated by Ralf Dingeldey about 4 years ago

Das Problem besteht immer noch. Wann gibt es eine Lösung?

Actions

Also available in: Atom PDF