[Fiware-lab-help] OAuth2 authentication issue and httpfs

Kimmo Surakka Kimmo.Surakka at fourdeg.com
Thu Feb 18 09:57:32 CET 2016


Hello,

I'm working in a INCENSe project where the aim is to run Big Data analysis on a set of customer data. The data should be handled in a protected manner. As far as I've understood, the httpfs server on cosmos.lab.fiware.org:14000 supports OAuth2 authentication, so so far things look good. However, there's an issue with the SSL certificate for the Cosmos Tokens Generator on cosmos.lab.fiware.org:13000. The server uses a self-signed certificate, making it impossible to verify the server's identity. Is this really true? If there's no way to verify the OAuth2 server's identity, the authentication is open to man-in-the-middle-attack, and thus not suitable for secure data.

Second question: does the https server on cosmos.lab.fiware.org:14000 support https transport?

Regards,
Kimmo Surakka
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.fiware.org/private/fiware-lab-help/attachments/20160218/430d49e9/attachment.html>


More information about the Fiware-lab-help mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy