This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP WebSpa Project"
From OWASP
m (→Quick Download) |
(Updated project roadmap for WebSpa v0.8 - v0.9) |
||
Line 293: | Line 293: | ||
= Roadmap = | = Roadmap = | ||
− | == Release 0.9 (Q3/ | + | == Release 0.9 (Q3/2015) == |
− | WebSpa_v0.9 will | + | WebSpa_v0.9 will be major release and include a comprehensive redesign of the WebKnock format in order to improve overall security and robustness of the request. The tickets for this release are: |
− | + | 44 New WebKnock request format should be defined | |
+ | 42 Do not limit the web knock to 100 characters, instead use SHA-512 lengths | ||
+ | 35 A threat model for WebSpa should be created and reviewed | ||
+ | 33 Apache should be replaced by nginx | ||
− | WebSpa_v0. | + | == Release 0.85 (Q1/2015) == |
+ | WebSpa_v0.85 will offer improved usability features, which will simplify installing, configuring and running WebSpa. The tickets for this release are: | ||
− | + | 40 Log to /var/log instead of a log.txt file | |
+ | 15 Add easy way to run the server as a background daemon | ||
+ | |||
+ | == Release 0.8 (Q4/2014) == | ||
+ | |||
+ | WebSpa_v0.8 will be sort of a proof-of-concept of WebSpa. A stable version to demonstrate the concept of WebKnocking, however, with some limitations with regards to usability/configuration and modularity (e.g. changing the hashing algorithm). The tickets for this release are: | ||
+ | |||
+ | 43 Change SSL configuration to allow wget | ||
41 WebSpa administrator to WebSpa user output | 41 WebSpa administrator to WebSpa user output | ||
− | |||
38 umask 077 should be added to webspa.sh | 38 umask 077 should be added to webspa.sh | ||
− | |||
− | |||
32 A known_hosts file should be used to maintain the list of successfully verified keys | 32 A known_hosts file should be used to maintain the list of successfully verified keys | ||
31 Verification of server's public key fingerprint should be possible | 31 Verification of server's public key fingerprint should be possible | ||
30 Help Files Update (0.8) | 30 Help Files Update (0.8) | ||
27 Arrays.equals is not a constant time function | 27 Arrays.equals is not a constant time function | ||
− | |||
2 Create maven build task for release | 2 Create maven build task for release | ||
Revision as of 18:53, 26 August 2014