Re: Cross site authentication
| From: | Bill Lubanovic | Date: | Wed, 19 Sep 2001 14:36:21 +0000 |
| Subject: | Re: Cross site authentication | ||
| References: | 1 | Groups: | php.db php.general |
| Request: | Send a blank email to php-general+get-67856@lists.php.net to get a copy of this message | ||
Rick Gardner wrote:
>
> Would a solution like xml-rpc work?
>
> On Wednesday, September 19, 2001, at 09:43 AM, Bill Lubanovic wrote:
>
> >
> > Customers are authenticating through an IIS server against a database on
> > Win2K. How do I securely pass this information to a separate
> > PHP/apache/UNIX system? Since any parameters could be forged, it seems
> > I'd need a cryptographic approach. Does anyone have experience with a
> > cross-platform solution (ASP/IIS/Win2K and PHP/apache/Linux)?
> >...
XML-RPC or SOAP structure the data better than GET or POST, but they
don't address the security issues. We can't send names, passwords, or
ids, no matter how we wrap them. How can platform A tell platform B
that it's authenticated someone? How can B trust A?
--
Bill Lubanovic
Mad Scheme Limited