10.12.2012 Views

The Java EE 5 Tutorial (PDF) - Oracle Software Downloads

The Java EE 5 Tutorial (PDF) - Oracle Software Downloads

The Java EE 5 Tutorial (PDF) - Oracle Software Downloads

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<br />

<br />

hello1_formauth<br />

<br />

index<br />

index<br />

/index.jsp<br />

<br />

<br />

SecurityConstraint<br />

<br />

WRCollection<br />

/*<br />

<br />

<br />

loginUser<br />

<br />

<br />

NONE<br />

<br />

<br />

<br />

FORM<br />

<br />

/logon.jsp<br />

/logonError.jsp<br />

<br />

<br />

<br />

loginUser<br />

<br />

<br />

More description of the elements that declare security in a deployment descriptor can be found<br />

in “Specifying Security Constraints” on page 850.<br />

Protecting Passwords with SSL<br />

Examples: SecuringWeb Applications<br />

Passwords are not protected for confidentiality with HTTP basic or form-based authentication,<br />

meaning that passwords sent between a client and a server on an unprotected session can be<br />

viewed and intercepted by third parties. To overcome this limitation, you can run these<br />

authentication protocols over an SSL-protected session and ensure that all message content is<br />

protected for confidentiality.<br />

Chapter 30 • SecuringWeb Applications 867

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!