Home  >  Q&A  >  body text

java - Is it necessary to add signature verification based on HTTPS two-way authentication?

The enterprise system directly communicates on the basis of HTTPS two-way authentication. Is it necessary to add additional signature verification to the key fields? It involves accounting and security, please give me some advice from someone with relevant experience!

三叔三叔2662 days ago994

reply all(2)I'll reply

  • 伊谢尔伦

    伊谢尔伦2017-06-23 09:15:02

    HTTPS itself uses encrypted transmission.
    Look at what kind of encryption your HTTPS certificate uses. SHA256 is originally a very high-level encryption method.
    How many years is it expected that the current SSL encryption technology will be easily cracked?

    And security is not only the security of the transmission process, but also involves other aspects. If you still can’t trust these encryption methods, then add another layer!

    reply
    0
  • 曾经蜡笔没有小新

    曾经蜡笔没有小新2017-06-23 09:15:02

    https can only ensure communication security
    Digital signature can prevent repudiation

    reply
    0
  • Cancelreply