Re: [oauth] OAuth design for API without users permission

2010-08-06 Thread Lukas Rosenstock
Hi Eric! If there's no user authentication, you can use two-legged OAuth. That means there's only consumer credentials but no token credentials. If the application is not hosted somewhere but deployed and installed at their user's, there's as far as I know no way to securely integrate consumer cr

Re: [oauth] SSL Gateway Service provider

2010-08-06 Thread Lukas Rosenstock
Interesting idea, don't know if that exists. But my question would be in which scenarios an encrypted tunnel should be easier to configure compared to installing an SSL certificate on the webserver itself?! 2010/7/30 Jake > Hello, > > Does anyone know of a service provider that offers SSL termin