in reply to Re: Re: SOAP::Lite - securest authentication route...
in thread SOAP::Lite - securest authentication route...

I agree that the script should never assume the client is secure, as an essential component of a security-in-depth strategy.

However, a secure client really is necessary for making sure only authorized users use the script. A compromised computer may be under an unauthorized user's control, but have a permitted IP address and access to the password or the SSL certificate.

  • Comment on Re: Re: Re: SOAP::Lite - securest authentication route...