同时拥有 SAML 断言和相互 SSL 有意义吗
我被要求这样做,我认为他们都在努力完成同样的事情。两者都需要有意义吗?
I'm being asked to do this and I think they're both trying to accomplish the same thing. Would it make sense to require both?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
您使用哪种绑定?
我根据您问题的性质假设 SOAP 绑定。如果您签署断言,并且相互身份验证 SSL 使用相同的私钥/证书,则它不会为您购买任何东西。当然,SSL 对于加密/隐私很有好处 - 但这可能是您的标准服务器 SSL/TLS - 不需要客户端 SSL。
Which binding are you using?
I'm assuming SOAP binding based on the nature of your question. If you are signing the Assertion, and mutual auth SSL is using the same private key/certificate, it's not buying you anything. Certainly SSL is good for encryption/privacy - but that could be your standard server SSL/TLS - no need for client SSL.