I myself have no opinion about Digest authentication, but if you want to contribute code, then axis-dev is the better place to post it than axis-user. Perhaps if you post something, someone who knows more about security (dims?) will find the time to look at your contribution.

Russell Butek
[EMAIL PROTECTED]

Please respond to [EMAIL PROTECTED]

To: <[EMAIL PROTECTED]>
cc:
Subject: code contribution



Hi,

    This is not a question about Axis.
    I wrote several mails to the user list, but no reaction.
So I thought I'll give it a shot on this list also.
My mail is mainly about Digest authentication in

HTTPSender class. I was playing around with this issue,
because my project need both Basic and Digest authentication.
So I "upgraded" HTTSender to support both authentication
methods. It seems to work, but for now it only support MD5,
and has a few more restrictions.

I also played with SSL and client certificates. What I
did is to enable the code to let the user choose the certificate
to be sent based on alias. I don't know if this is useful
or not, it is a stupid thing to have several certificates, but
this was also a requirement from me. So I hacked this one too.

Anyway I thought I'll ask you if Axis developer group is
interested about these issues. I'd be most happy to contribute
to Axis. In this case I'll try to make HTTPSender ever more
clever and maybe support other (digest) algorithms too.

So, what do you think ? Is Digest authentication planned into
Axis ?
            Regards, Geza

________________________________________________________________
Szôcs Géza
    Software Engineer - Nokia Hungary / NMP
    Tel: +36-20-9849623, Email: [EMAIL PROTECTED]

Reply via email to