Re: Cross site authentication
| From: | Bill Lubanovic | Date: | Wed, 19 Sep 2001 14:59:43 +0000 |
| Subject: | Re: Cross site authentication | ||
| References: | 1 | Groups: | php.db php.general |
| Request: | Send a blank email to php-db+get-12590@lists.php.net to get a copy of this message | ||
> "Hoover, Josh" wrote:
>
> What about if your XML-RPC calls are run over SSL? That would make
> them secure I believe. Now the question becomes whether any of the
> PHP XML-RPC classes support SSL. Anyone know if any/all of the
> classes support SSL?
>
> Josh Hoover
> KnowledgeStorm, Inc.
> jhoover@knowledgestorm.com
>
> Searching for a new IT solution for your company? Need to improve your
> product marketing?
> Visit KnowledgeStorm at www.knowledgestorm.com to learn how we can
> simplify the process for you.
> KnowledgeStorm - Your IT Search Starts Here
>
> > XML-RPC or SOAP structure the data better than GET or POST, but they
>
> > don't address the security issues. We can't send names, passwords,
> or
> > ids, no matter how we wrap them. How can platform A tell platform
> B
> > that it's authenticated someone? How can B trust A?
SSL avoids the problem of someone sniffing the plain text data. We
still have the problem: what data do we send? Anyone can forge
credentials and send them over SSL. How does B know it came from A? I'm
thinking of some key exchange method, but portability between the
Microsoft and UNIX worlds makes this even trickier.
--
Bill Lubanovic
Mad Scheme Limited