Re: Article on removing codebase property
Dan Creswell <[email protected]>
| Newsgroups | gmane.comp.java.sun.jini |
|---|---|
| Message-ID | <[email protected]> |
And one more thought: Dunno what the security implications of this kind of approach are. I would generally favour having some kind of authentication mechanism that allowed for validation of the codebase server which the client would apply before configuring itself with that codebase. Could be done a myriad of ways one of which would be to actually have the codebase server be a Jini service and publish a secure proxy etc. That will likely mean the codebase service will likely need to be statically configured with it's own codebase and associated http server but that's easily handled through the starter config file so it wouldn't be too painful. [ It's worth realizing that for many circumstances this security concern is irrelevant. From a design perspective security has to be considered from the start of a project because retro-fitting is painful. Trouble is this makes development difficult because it front-loads the design effort signficantly. ] Getting on for more like 4 cents of feedback now, Dan. Calum Shaw-Mackay wrote: > Any thoughts? > > http://www.theserverside.com/news/thread.tss?thread_id=44288 > > Cheers > > --Calum > > -------------------------------------------------------------------------- > Getting Started: http://www.jini.org/wiki/Category:Getting_Started > Community Web Site: http://jini.org > jini-users Archive: http://archives.java.sun.com/archives/jini-users.html > Unsubscribing: email "signoff JINI-USERS" to [email protected] > -------------------------------------------------------------------------- Getting Started: http://www.jini.org/wiki/Category:Getting_Started Community Web Site: http://jini.org jini-users Archive: http://archives.java.sun.com/archives/jini-users.html Unsubscribing: email "signoff JINI-USERS" to [email protected]