Luis, the way you see it is completelly wrong. If you are looking only
for a way to encrypt data sent to the server, stop wasting time
researching 3rd party libraries, instead visit
www.verisign.com, buy a
certificate and use SSL! There just is NO OTHER WAY to provide better
encryption for the data sent over the net, that could be implemented
on a javascript client. Reason is simple, if you would be able to
implement AES or some other symmetric cipher on the javascript client,
you simply would not be able to exchange the key for the cipher, just
because a secure, man in the middle proof asymmetric cipher CAN NOT be
implemented in pure javascript.
With all that said, you do not need SECURITY, you just need
ENCRYPTION. After you get it (SSL I mean) and get comfortable and
happy about encrypted data being sent to the server, you may run into
a situation, when a non authorized person, called a hacker or an
attacker, starts to execute services on you server via RPC, that he is
not supposed to have access to. Then you will realize, that despite
all the fancy encryption, you gotta start looking for a way to prevent
this. And maybe you will also realize, that security is not just
encryption.
Btw. if you still want to argue about whether acris-security is about
security or not, I suggest, you visit spring security forums and try
it there. Good luck trying to explain to them that Spring Security
actually isn't about security, it's just an "authentication
interface".
P.S.: Acris-Security is mainly about authorization, not
authentication...just to get the facts straight.
On 14. Aug, 17:22 h., Luis Daniel Mesa Velasquez
> ...
>
> ďalšie informácie >>