cLive ;-) has asked for the wisdom of the Perl Monks concerning the following question:
So basically, only requests from the correct IP addresses with the correct authentication over HTTPS get through. But I'm wondering if that's enough :)
The system needs to be flexible enough that it can easily be expanded, but security is definitely a priority over flexibility.
The other method I thought of (dropping the Basic Authentication) was:
Or am I approaching this the wrong way? Searching on this I haven't found any advice over use HTTPS and basic auth...
cLive ;-)
Update: to avoid confusion here, all clients are servers we have control over. I'm leaning towards creating a local Certification Authority and SSL certificate authentication - This article looks promising. Thanks for thoughts so far :)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: SOAP::Lite - securest authentication route...
by Fletch (Bishop) on Apr 20, 2004 at 01:48 UTC | |
by cLive ;-) (Prior) on Apr 20, 2004 at 01:52 UTC | |
|
Re: SOAP::Lite - securest authentication route...
by exussum0 (Vicar) on Apr 20, 2004 at 02:15 UTC | |
|
Re: SOAP::Lite - securest authentication route...
by sgifford (Prior) on Apr 20, 2004 at 01:55 UTC | |
by matija (Priest) on Apr 20, 2004 at 07:03 UTC | |
by sgifford (Prior) on Apr 20, 2004 at 15:18 UTC | |
|
Re: SOAP::Lite - securest authentication route...
by gnork (Scribe) on Apr 20, 2004 at 09:18 UTC | |
by cLive ;-) (Prior) on Apr 20, 2004 at 14:10 UTC | |
by gnork (Scribe) on Apr 21, 2004 at 09:18 UTC |