Beefy Boxes and Bandwidth Generously Provided by pair Networks
Welcome to the Monastery
 
PerlMonks  

Re: Re: Re: Securing your SOAP Application

by simon.proctor (Vicar)
on Jul 30, 2003 at 20:19 UTC ( [id://279359]=note: print w/replies, xml ) Need Help??


in reply to Re: Re: Securing your SOAP Application
in thread Securing your SOAP Application

I see what you mean now about HTTP (sorry about that :P ).

Frankly I have avoided the whole authentication issue by only exposing publicly available (in the company) data and making it query only. I couldn't use SSL in my projects (for various political reasons) and my scheme was the path of least resistance.

Until there is a standard I guess it boils down to your own environment. In my case, packing it inside the envelope will have to be the way to go. Plus our security policy (at work) is to encrypt everything, SSL or otherwise.

I do wonder, however, whether you have considered using some form of digest mechanism in your method? Do you think this is worthwhile?

Thanks for your feedback :)
  • Comment on Re: Re: Re: Securing your SOAP Application

Replies are listed 'Best First'.
Re: Re: Re: Re: Securing your SOAP Application
by hardburn (Abbot) on Jul 30, 2003 at 20:25 UTC

    I do wonder, however, whether you have considered using some form of digest mechanism in your method? Do you think this is worthwhile?

    Perhaps. The Apache::Htpasswd module already stores the passwords in encryped form. Apache's .htpasswd file format supports using hashes instead of encrypted data, but the module doesn't appear to support this feature. For just transfering the password, it couldn't hurt to use a digester.

    ----
    I wanted to explore how Perl's closures can be manipulated, and ended up creating an object system by accident.
    -- Schemer

    Note: All code is untested, unless otherwise stated

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://279359]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others surveying the Monastery: (2)
As of 2024-04-25 21:52 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found