CWE
Home > CWE List > CWE- Individual Dictionary Definition (1.4)  

CWE-295: Certificate Issues

Individual Definition in a New Window
Certificate Issues
Status: Incomplete
Category ID: 295 (Category)
+ Description
Summary

Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.

+ Applicable Platforms
Languages
All
+ Background Details

A certificate is a token that associates an identity (principle) to a cryptographic key. Certificates can be used to check if a public key belongs to the assumed owner.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfCategoryCategory254Security Features
Development Concepts (primary)699
ChildOfCategoryCategory731OWASP Top Ten 2004 Category A10 - Insecure Configuration Management
Weaknesses in OWASP Top Ten (2004) (primary)711
ParentOfWeakness BaseWeakness BaseWeakness Base296Improper Following of Chain of Trust for Certificate Validation
Development Concepts (primary)699
ParentOfWeakness BaseWeakness BaseWeakness Base297Improper Validation of Host-specific Certificate Data
Development Concepts (primary)699
ParentOfWeakness BaseWeakness BaseWeakness Base298Improper Validation of Certificate Expiration
Development Concepts (primary)699
ParentOfWeakness BaseWeakness BaseWeakness Base299Improper Check for Certificate Revocation
Development Concepts (primary)699
+ Taxonomy Mappings
Mapped Taxonomy NameNode IDFitMapped Node Name
OWASP Top Ten 2004A10CWE More SpecificInsecure Configuration Management
+ References
M. Bishop. "Computer Security: Art and Science". Addison-Wesley. 2003.
+ Content History
Modifications
Veracode. 2008-08-15. (External)
Suggested OWASP Top Ten 2004 mapping
CWE Content Team. MITRE. 2008-09-08. (Internal)
updated Relationships, Taxonomy_Mappings
CWE Content Team. MITRE. 2008-10-14. (Internal)
updated Background_Details, Description
Page Last Updated: May 26, 2009