facet-acq / post-award

Application Service Supporting Entitlement and Administration of Government Procurement Actions
BSD 3-Clause "New" or "Revised" License
5 stars 3 forks source link

Client Authentication #21

Open djfurman opened 6 years ago

djfurman commented 6 years ago

Note that this epic relates only to practices identifying that the end client (user/system) is whom it claims to be, not whether it may or may not take an action. This is the difference between authentication (the former) and authorization (the latter).

As a business critical function, the system must be able to reliably determine that a calling client is whom they claim to be. The authentication method must