I'll have to confirm what you can and cannot see by watching traffic 
when connected via SSL, i know the actual data is encrypted, which is 
all in the soap body, so I would assume the actuall method call is 
encrypted as well.  I'll confirm...

You definately see all off the soap message if not using SSL.

However, and i do realize this is not an all encompassing security 
solution, but it's at least closing the front door to the house.  Why 
expose more than you have to.

Not sure what other http network tools anyone uses, but i'll be 
testing this with Fiddler, a MS http debugging tool.

--Scott


--- In [EMAIL PROTECTED], Tom Chiverton <[EMAIL PROTECTED]> 
wrote:
>
> On Thursday 12 Apr 2007, scott_flex wrote:
> > and part of the security, as I have done in the past, is deny any 
GETs
> > on the WSDL file so someone can't easily determine all the methods
> > exposed.  I will be calling these services via SSL as well.
> 
> They can determine that by watching the network traffic, can't 
they ?
> 
> -- 
> Tom Chiverton
> Helping to preemptively syndicate customized information
> on: http://thefalken.livejournal.com
> 
> ****************************************************
> 
> This email is sent for and on behalf of Halliwells LLP.
> 
> Halliwells LLP is a limited liability partnership registered in 
England and Wales under registered number OC307980 whose registered 
office address is at St James's Court Brown Street Manchester M2 
2JF.  A list of members is available for inspection at the registered 
office. Any reference to a partner in relation to Halliwells LLP 
means a member of Halliwells LLP. Regulated by the Law Society.
> 
> CONFIDENTIALITY
> 
> This email is intended only for the use of the addressee named 
above and may be confidential or legally privileged.  If you are not 
the addressee you must not read it and must not use any information 
contained in nor copy it nor inform any person other than Halliwells 
LLP or the addressee of its existence or contents.  If you have 
received this email in error please delete it and notify Halliwells 
LLP IT Department on 0870 365 8008.
> 
> For more information about Halliwells LLP visit www.halliwells.com.
>


Reply via email to