[jboss-dev-forums] [Design of Security on JBoss] - Re: SRP and SASL

anil.saldhana@jboss.com do-not-reply at jboss.com
Fri Oct 19 10:43:18 EDT 2007


Additionally, with SRP (like SSL), the only thing common between the client and the server is the session key.  So if there is any need to do password verification semantics, you have to do it on the session key.

View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4097012#4097012

Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4097012



More information about the jboss-dev-forums mailing list