如何使用PASSPORT SDK建立强健的网站应用,有人成功实施过吗?(300分)

房客

Unregistered / Unconfirmed
GUEST, unregistred user!
SDK下载地址:微软一搜就有了
 
http://www.borland.com/events/javaone_02/passport.html
Borland Passport
Make the Borland booth your first stop in the JavaOne Pavilion and pick up your Borland Passport. Get your passport stamped at Borland partner booths and bring it back to receive a special gift and a chance to win great prizes.
Borland partners participating in this year's Passport program
Apple Computer, Inc.
Embarcadero Technologies
HNC Software
Instantiations, Inc.
Intel
Mercury Interactive
Nokia
Rational Software
Serena Software
Siemens AG
Sonic Software
Sprint PCS
Sun Java Technology and XML
Thought, Inc.
Zero G Software, Inc.
 
Let's talk about the Security of Web Services
 
http://msdn.microsoft.com/downloads/sample.asp?url=/MSDN-FILES/027/001/644/msdncompositedoc.xml
 
关心这个话题的人真是太少了。
前两天在推广会后特意问了李维这个问题,他的解决方法是用http的Security。
那不成了SOAP只能用HTTP来封装,如果我想用SMTP怎么办?
 
LeeChange:
我记得有个小伙子提问,难道就道LeeChange大虾?
1。IPWSSL组件(第3方),支持FTP,POP,SMTP,HTTP。。。
2。INDY9(SSL),DELPHI6增强方案,支持SSLv3
3。SOAP-DISG,MAC和数字签名(我理解为SOAP的MSG签名)
哪位朋友对“不可抵赖性”做过测试,结果如何?是否有方案?
 
SOAP Security
This page demonstrates some of the technologies for secure SOAP transactions. It shows that how SOAP transactions/messages can be strongly protected through digital signature and encryption.
Authen
tication: Users of SOAP services can be authen
ticated in many different ways including token-based authen
tication and digest authen
tication. Token based authen
tication requires users to supply credentials through a secure channel. SOAP servers respond with an auth token which can be used for all subsequent requests.
Digital Signature: Signature is a way of ensuring integrity of ado
cument. SOAP messages, wholly or in part, are first digested. The digest is a hash value equivalent to a human fingerprint. The digest, along with other sensitive data, is then
digitally signed using the senders certificate and then
encrypted using the receiver's public key. Because the signature is encrypted using the receiver's public key, only the receiver can decrypt it and verify the signature and message digest. Any tampering during the transmission will lead to a signature/hash verification failure. XML Signiture (XML-DSIG) is a W3C recommendation that defines the rules for digital signature processing and the structure of the XMLdo
cument.
Data Encryption: Sensitive data can also be encrypted using either session keys or public/private key. Even the message is sent in the clear, the part that is encrypted will be opaque and difficult to crack. The W3C draft, XML Encryption, defines the process and format of the encrypted XML data.
The form below demonstrates how SQLData SOAP server and client support XML Signature (XML-DSIG), SOAP Security Extensions (SOAP-DSIG) and XML Encryption. Both request and response of the following method are signed and verified by the SOAP client and server. In addition, the first parameter (bstrParam1) value is encrypted before sending to server;
and the returned value from the server is also encrypted.

 
www.msnfans.com
 
版主你好,能不能透露点COM+技术,如饥似渴。
我的MAIL是:hzjone@hotmail.com.请多指教。
 

Similar threads

D
回复
0
查看
1K
DelphiTeacher的专栏
D
S
回复
0
查看
3K
SUNSTONE的Delphi笔记
S
S
回复
0
查看
2K
SUNSTONE的Delphi笔记
S
D
回复
0
查看
2K
DelphiTeacher的专栏
D
D
回复
0
查看
2K
DelphiTeacher的专栏
D
顶部