cxf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Tomasz Oponowicz (JIRA)" <j...@apache.org>
Subject [jira] Issue Comment Edited: (CXF-2873) Add authentication support (temporary implementation using HTTP basic authentication)
Date Mon, 05 Jul 2010 09:03:56 GMT

    [ https://issues.apache.org/jira/browse/CXF-2873?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12885149#action_12885149
] 

Tomasz Oponowicz edited comment on CXF-2873 at 7/5/10 5:03 AM:
---------------------------------------------------------------

First of all it's obvious (for me) that endpoints should be well secured because of sensitive
information.

Unfortunately I've made mistake in the title of this task. 
I think about "Add authentication support (*temporary implementation using* -via- HTTP basic
authentication)".
First I will create basic solution to have grounds for enhanced it (ex. with "digest access
authentication" or "WSSE UsernameToken" or HTTPS). 

I also agree that "HTTP basic" isn't secure method.

Sergey mentioned about very important thing:
bq. If we use the basic auth then HTTPS will have to be set up which may be a bit of a headache
if people just would like to view logs

Easy configuration is crucial. We should keep this in mind.

At the moment I don't know what is the best solution for us. I must think about this for a
while.

Thanks for your help.

      was (Author: tomekopo):
    First of all it's obvious (for me) that endpoints should be well secured because of sensitive
information.

Unfortunately I've made mistake in the title of this task. 
I think about "Add authentication support (*temporary implementation using* -via- HTTP basic
authentication)".
First I will create basic solution to have grounds for enhanced it (ex. with "digest access
authentication" or "WSSE UsernameToken" or HTTPS). 

I also agree that "HTTP basic" isn't secure method.

Sergey mentioned about very important thing:
bq. If we use the basic auth then HTTPS will have to be set up which may be a bit of a headache
if people just would like to view logs

Easy configuration is crucial. We should keep this in mind.

At the moment I don't know what is the best solution for us. I must about think this for a
while.

Thanks for your help.
  
> Add authentication support (temporary implementation using HTTP basic authentication)
> -------------------------------------------------------------------------------------
>
>                 Key: CXF-2873
>                 URL: https://issues.apache.org/jira/browse/CXF-2873
>             Project: CXF
>          Issue Type: Sub-task
>            Reporter: Tomasz Oponowicz
>


-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


Mime
View raw message