Re: [xml-dev] What Does SOAP/WS Do that A REST System Can't?
by Joe Gregorio other posts by this author
Mar 30 2005 7:42PM messages near this date
Re: [xml-dev] What Does SOAP/WS Do that A REST System Can't?
|
Re: [xml-dev] What Does SOAP/WS Do that A REST System Can't?
& XSLT On Wed, 30 Mar 2005 21:33:59 -0500 (EST), Rich Salz
<rsalz@[...].com> wrote:
> But what if the Credit Card company is building its back office around
> HTTP and REST? They *can't* resubmit and let someone else work it out. :)
> Note that I'm not talking about transactions, rollback, etc., I just
> want to know if the damn message got there and what the answer was.
> I'd also like to avoid message replay.
I believe POE fulfills that requirement:
http://www.mnot.net/blog/2005/03/21/poe
> HTTP has no way to provide end-to-end security of the Request URI.
> That means you can't do a GET and have any cryptographically based
> way to be sure that (a) the URI wasn't modified in-flight; and (b)
> that nobody else will see it (i.e., signing and encryption). SSL/TLS
> is only hop-by-hop. If there are any proxies or loadbalancers in the
> path, at least some of them will get the plaintext.
As far as (a) is concerned, doesn't Digest include the URI in the hash?
As far as (b) is concerned, isn't the SLL certificate tied to the IP address
of the server being accessed?
-joe
--
Joe Gregorio http://bitworking.org
-----------------------------------------------------------------
The xml-dev list is sponsored by XML.org <http://www.xml.org> , an
initiative of OASIS <http://www.oasis-open.org>
The list archives are at http://lists.xml.org/archives/xml-dev/
To subscribe or unsubscribe from this list use the subscription
manager: <http://www.oasis-open.org/mlmanage/index.php>
Thread:
Claude L Bullard
Marc de Graauw
Joe Gregorio
Bill de hÓra
Michael Champion
Uche Ogbuji
Jan Algermissen
Uche Ogbuji
Rich Salz
Jan Algermissen
Rich Salz
Michael Champion
Bill de hÓra
Michael Champion
Uche Ogbuji
Bill de hÓra
Robert Koberg
Peter Hunsberger
Michael Champion
Leigh Dodds
Jan Algermissen
Leigh Dodds
Bill de hÓra
Michael Champion
Leigh Dodds
Michael Champion
Rick Marshall
Bill de hÓra
Robert Koberg
Rich Salz
Leigh Dodds
Rich Salz
Leigh Dodds
Rich Salz
Leigh Dodds
Andrzej Jan Taramina
Rich Salz
Bob Foster
Jan Algermissen
Mark Baker
Michael Champion
Michael Champion
Mark Baker
Mark Baker
Michael Champion
Bill de hÓra
Rich Salz
David Lyon
Rich Salz
Joe Gregorio
Rich Salz
Joe Gregorio
Saptagirisa N
Arvind Singh
Rich Salz
Joe Gregorio
Rich Salz
Joe Gregorio
Rich Salz
Dave Pawson
Mark Baker
Joe Gregorio
Mark Baker
Rich Salz
Michael Champion
Elliotte Rusty Harold
Joe Gregorio
Michael Champion
Jan Algermissen
Bill de hÓra
Joe Gregorio
Charles Woerner
Rich Salz
|