Comment 2 for bug 1522297

Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Hello Robert!

We highly discourage using PLAINTEXT sigantures, SSO supports them only for backward compatibility with old clients. You should sign your requests with HMAC signatures.

Not sending the nonce and the timestamp makes the signed request less secure: if your SSL connection gets compromised somehow, your request is vulnerable to replay attacks. Are you using a third party library to sign your requests?

Thanks.