Archive of UserLand's first discussion group, started October 5, 1998.

Re: Tough problem to solve...

Author:David Brown
Posted:5/10/2000; 12:14:13 PM
Topic:Piking behind firewalls
Msg #:17170 (In response to 17168)
Prev/Next:17169 / 17171

But the entire manila.rpc interface is built on sending usernames and passwords, so if you want more security, it's not possible without putting a security layer inbetween.

I felt uneasy when I originally saw that bit of the manila.rpc spec.

The security issues are orthogonal to that.

Glad to see that I came to the same conclusion. Best to use something like SSL and secure the entire channel. I think the next version of Python will include an SSL implementation, meaning that it should be simple to just drop it into the existing xml-rpc implementation.

Is the security issue one that will be addressed at some point?

We're undergoing a security audit at work, so these issues are on my mind right now.

dave




This page was archived on 6/13/2001; 4:55:09 PM.

© Copyright 1998-2001 UserLand Software, Inc.