aspose file tools
The moose likes Security and the fly likes j2ee authentication methods (web) Big Moose Saloon
  Search | Java FAQ | Recent Topics
Register / Login
JavaRanch » Java Forums » Engineering » Security
Reply Bookmark "j2ee authentication methods (web)" Watch "j2ee authentication methods (web)" New topic
Author

j2ee authentication methods (web)

Sol Mayer-Orn
Ranch Hand

Joined: Nov 13, 2002
Posts: 310
Hi,
I'm a little confused about the available methods for clients to authenticate themselves to a web application.
In particular, all tutorials mention "basic HTTP authentication" , "form-based", and "digest". Which is clear enough.
However, some of them mention "client certificate" while others refer to "https (or SSL) client authentication". Are those 2 terms identical ?

Also, am I correct in understanding that "basic http" and "form based" are the most commonly used, yet they allow the password to travel as *plain text* ? This really sounds bad... which authentication method would you recommend ?

Thank you very much
 
 
subject: j2ee authentication methods (web)
 
Threads others viewed
Basic-Auth plus Form-Login based authentication in Spring 3
HTTPS Client Authentication
http authentication methods
a vague question
clarification on mock exam question
IntelliJ Java IDE

cast iron skillet 49er

more from paul wheaton's glorious empire of web junk: cast iron skillet diatomaceous earth rocket mass heater sepp holzer raised garden beds raising chickens lawn care CFL flea control missoula heat permaculture