Vince Hon<br /> <br />SCJP 1.4 | SCWCD | SCBCD <br /><a href="http://vincehon.homeip.net:8000/VJW" target="_blank" rel="nofollow">http://vincehon.homeip.net:8000/VJW</a>
Vince Hon<br /> <br />SCJP 1.4 | SCWCD | SCBCD <br /><a href="http://vincehon.homeip.net:8000/VJW" target="_blank" rel="nofollow">http://vincehon.homeip.net:8000/VJW</a>
From HFB p.647, it said FORM-Based Authentication needs to use SSL or session tracking.
Narendra Dhande
SCJP 1.4,SCWCD 1.4, SCBCD 5.0, SCDJWS 5.0, SCEA 5.0
I think any of the auth mechanism can use the SSL or session tracking
I read somewhere that the session tracking with url rewirting is problematic ( what is problem is not mentioned , I remember), so the session tracking using cookie or session tracking bultin into SSL should be used.
Sawan<br />SCJP,SCWCD,SCBCD<br /> <br />Every exit is an entry somewhere.
Sorry but I don't think this is correct. The SSL gives more security because the encryption is good. For example BASIC won't use SSL. Secure socket layer has a built in mechanism which the container can use to track session.
Narendra Dhande
SCJP 1.4,SCWCD 1.4, SCBCD 5.0, SCDJWS 5.0, SCEA 5.0
I think typically for INTEGRAL or CONFIDENTIAL transport SSL is used
Sawan<br />SCJP,SCWCD,SCBCD<br /> <br />Every exit is an entry somewhere.
Vince Hon<br /> <br />SCJP 1.4 | SCWCD | SCBCD <br /><a href="http://vincehon.homeip.net:8000/VJW" target="_blank" rel="nofollow">http://vincehon.homeip.net:8000/VJW</a>
can be used BUT the website just continuously show up the login page (for FORM method) or popup window to request login (for BASIC and DIGEST) even the username and password are correct, right ?
Narendra Dhande
SCJP 1.4,SCWCD 1.4, SCBCD 5.0, SCDJWS 5.0, SCEA 5.0
Sawan metioned that the basic and form auth. use uu-encoding. But I don't think the FORM auth use uu-encoding. It is just the plain text.
Sawan<br />SCJP,SCWCD,SCBCD<br /> <br />Every exit is an entry somewhere.
With a little knowledge, a cast iron skillet is non-stick and lasts a lifetime. |