From: rcoder Date: 2006-02-10T03:08:22+09:00 Subject: Re: Writing Secure Web Services Scotte wrote: > We'd like to eliminate the overhead of a challenge/response type of system. No offense, but "eliminating the overhead" by introducing a full round-trip through GPG each time is kind of rediculous. Why not simply generate SSL client certs and distribute them to your clients? It's no less secure (or more work for you) than importing GPG/PGP keys, and re-uses the existing HTTPS security model. -Lennon