java - Is it necessary to add signature verification based on HTTPS two-way authentication?
三叔
三叔 2017-06-23 09:13:02
0
2
1043

The enterprise system directly communicates on the basis of HTTPS two-way authentication. Is it necessary to add additional signature verification to the key fields? It involves accounting and security, please give me some advice from someone with relevant experience!

三叔
三叔

reply all(2)
伊谢尔伦

HTTPS itself uses encrypted transmission.
Look at what kind of encryption your HTTPS certificate uses. SHA256 is originally a very high-level encryption method.
How many years is it expected that the current SSL encryption technology will be easily cracked?

And security is not only the security of the transmission process, but also involves other aspects. If you still can’t trust these encryption methods, then add another layer!

曾经蜡笔没有小新

https can only ensure communication security
Digital signature can prevent repudiation

Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template