Web Services authentication - best practices?

前端 未结 3 1757
时光取名叫无心
时光取名叫无心 2020-12-24 14:01

We have SOAP web services in production that are relying on SOAP Headers (containing plain client credentials) for the authentication. The WS are used in heterogeneous envir

3条回答
  •  刺人心
    刺人心 (楼主)
    2020-12-24 14:28

    If you have to roll it all yourself and can't use HTTPS, I'd suggest the hash-based UsernameToken portion of WS-Security. It's pretty secure and fairly easy to implement as long as your libraries have the hashing functions.

    If you're doing web services, I wouldn't rely on HTTP for authentication.

    WS-Security as a whole is way too big.

提交回复
热议问题