Re: Securing PHP code

From: Date: Thu, 26 Jun 2003 22:26:33 +0000
Subject: Re: Securing PHP code
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-153034@lists.php.net to get a copy of this message
Hello, On 06/26/2003 02:10 AM, Joseph Szobody wrote:
A safer architechture would be to use two machines. One to act as the Web server and the other to process transactions. The Web server would take the orders and request the transaction server to process them. The transcation server can only be accessed from the Web server. Nobody should be able to reach the transaction server from the Internet. The transaction server machine should have the database server too. The database server should not accept network connections.
Having never setup a multi-server web environment before, I'm a bit curious. How would the public server communicate with the private server, passing in database queries and getting results, if it can't connect directly to the database? Are we talking about building a SOAP interface between the two?
Yes, it could be SOAP although a less bloated protocol over HTTP would do. -- Regards, Manuel Lemos Free ready to use OOP components written in PHP http://www.phpclasses.org/

« previous php.general (#153034) next »