Perry E. Metzger (perry@piermont.com)
Mon, 26 Oct 1998 11:22:47 -0500
"David R. Conrad" writes:
> Primarily, what I'm concerned about is the security of the protocol that's
> used between the applet and the server. (Secondarily, I'm concerned about
> exporting it and/or having an unexportable java applet embedded in a web
> page that's accessible outside the U.S. and Canada.)
My suggestion: why re-implement what is already available in the
program? The java applet is allowed to open an https: URL on the
server if it wishes. Have it do so, and download your session keys
that way.
I've built several systems already that use this trick. 'taint pu'rty,
but it does the job.
Perry
The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:15:22