Re: Article on removing codebase property

Dan Creswell <[email protected]>
Newsgroups gmane.comp.java.sun.jini
Message-ID <[email protected]>
And one more thought:

Dunno what the security implications of this kind of approach are.  I
would generally favour having some kind of authentication mechanism that
allowed for validation of the codebase server which the client would
apply before configuring itself with that codebase.

Could be done a myriad of ways one of which would be to actually have
the codebase server be a Jini service and publish a secure proxy etc.
That will likely mean the codebase service will likely need to be
statically configured with it's own codebase and associated http server
but that's easily handled through the starter config file so it wouldn't
be too painful.

[ It's worth realizing that for many circumstances this security concern
is irrelevant.  From a design perspective security has to be considered
from the start of a project because retro-fitting is painful.  Trouble
is this makes development difficult because it front-loads the design
effort signficantly. ]

Getting on for more like 4 cents of feedback now,

Dan.

Calum Shaw-Mackay wrote:
> Any thoughts?
>
> http://www.theserverside.com/news/thread.tss?thread_id=44288
>
> Cheers
>
> --Calum
>
> --------------------------------------------------------------------------
> Getting Started:     http://www.jini.org/wiki/Category:Getting_Started
> Community Web Site:  http://jini.org
> jini-users Archive:  http://archives.java.sun.com/archives/jini-users.html
> Unsubscribing:       email "signoff JINI-USERS"  to [email protected]
>

--------------------------------------------------------------------------
Getting Started:     http://www.jini.org/wiki/Category:Getting_Started
Community Web Site:  http://jini.org
jini-users Archive:  http://archives.java.sun.com/archives/jini-users.html
Unsubscribing:       email "signoff JINI-USERS"  to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.