[LIP] Doubt regarding a authorization module design

Vardhman Jain <[email protected]>
Newsgroups gmane.user-groups.linux.india.programmers
Message-ID <[email protected]>
Hi,
  I am planning to desing a system which will be based on J2EE, The
access to information will be provided by the server after
authentication. If I keep the concept simple to make it work only via
JSP/servlets there is no issue, but I could imagine providing an
access to the information from JAVA Clients, so the problem arise
here. What kind of authentication system should I use.

Should the password be sent by the JAVA-Client via XML (with only
passwd encrypted using say MD5), or the whole connection should use
some SSL sort of thing. I would consider it ideal if the design of the
authorization system is not much different in Web-based system as well
as for Java Clients. What kind of design should be suggestible. Also
what kind of code-resuse is possible in desing of such Authentication
tools.


-- 

*************************************
Vardhman Jain, Btech 3rd [email protected] Hyderabad
website: http://students.iiit.net/~vardhman


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.