[Previous] [Next] [Index] [Thread]

Re: OBCSCR



Phill says:
> Because HTTP is simple it is easy to encapsulate other protocols. 

Actually, we've found it incredibly easy to encapsulate HTTP in DCE
RPC. That way we get ACL-based authorization, Kerberos-based
authentication, cell-based security registration and authorities,
location-independant name, and transport independance, all today (OK,
we haven't written the ACL Mgr quite yet...). We're an Out-Of-Band
solution, though not Challenge/Response based.

Does anyone have technical arguments around the difference between getting encapsulated or being encapsulated? 
 
	Mez