Re: Re: Any ideas if a form needs a signature?
| From: | Sean C. McCarthy | Date: | Fri, 10 Aug 2001 14:20:07 +0000 |
| Subject: | Re: Re: Any ideas if a form needs a signature? | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-62178@lists.php.net to get a copy of this message | ||
Hi,
If you want to distribute your app and need to be signed the almost only
thing you can use without getting into too much trouble is Java. The
applets can be sent to the client and used in a simple browser. At the
server side you can still use PHP, since the applet can make HTTP
requests (POST and GET) and process the data with PHP. The applet signed
has strong critpography (both simetric and public), and the execution
only occurs if the signed code belongs to the issuer of the certificate
you give execution permission. Click on the security tab of any browser
and have a look at it.
I don't know if you mean that kind of signing. If you mean the
information transfer must be signed then you only need signing tools.
Have a look at openssl (www.openssl.org), it has many methods for
signing, hash codes and security related stuff. It is also under a GPL
license and developed outside US, so you will have no problem about
restrictions.
Sean C. McCarthy
SCI, S.L. (www.sci-spain.com)
Manuel Lemos wrote:
>
> Hello,
>
> Chris wrote:
> >
> > I am digitalizing a companies Application in an online system. The problem is that
> > companies they deal with require the app to be signed. Obviously an online application cannot be
> > signed conventionally. Does anyone know of a way or a work-around to accomplish this?
>
> In Europe, many banks only let you do Internet banking if you use a
> digital certificate that you enable after you receive a code by postal
> (snail) mail. The certificate is created online, but you need to enter a
> password defined by yourself everytime you want to use it. This is to
> reduce the chance that somebody does anything if they steal the
> certificate files from your disk.
>
> It is annoying because the certificate maybe lost in a hard disk crash,
> very frequent with Windows users that keep trying all the crap that they
> get from the Internet and they don't have a clue that they should take
> backup copies of the certifcate files. Some banks only let you create 3
> copies of your certificate.
>
> I don't know if this solves your problem, but at least could be a means
> of demonstrating that who is accessing your site pages is somebody well
> known to your institution and the possibilities of fraud are low.
>
> Regards,
> Manuel Lemos
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net