SOAP Client: Client TLS credential selection

Cantor, Scott cantor.2 at osu.edu
Wed May 13 19:46:46 EDT 2015


On 5/13/15, 11:43 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:


>
>If we need to support that level of per-RP configurability, then the
>whole SOAP client might have to be the unit of configuration.

That kind of persuades me that it's a good idea, because recent years have 
demonstrated that per-connection control over TLS versions and ciphers is 
increasingly needed to deal with security issues much like it is with 
SHA-1 now.

People will definitely want to be able to turn on broken features for 
specific partners and not globally.

-- Scott



More information about the dev mailing list