[OAI-implementers] oai security

Michael L. Nelson mln@ils.unc.edu
Mon, 14 Jan 2002 20:36:22 -0500 (EST)


On Mon, 14 Jan 2002, Josie Imlay wrote:

> I am working on an oai server right now and the people that own the
> information don't want it getting in to just anyone and everyone's
> hands. I satisfied this using some simple http protocol level
> authentication. What I am woundering is if people writing harvesters
> out there are implementing username/password support at all.

Josie,

there are probably many data providers that require username/passwd for
harvesting.  I'm aware of several data providers that allow harvesting
only from certain hosts.

writing a harvester to handle usernames and passwords is no problem.  for
a Perl example, look at the User Agent object in LWP:

http://www.perldoc.com/perl5.6.1/lib/LWP/UserAgent.html

this will allow you to protect your OAI interface using standard http
authentication.

regards,

Michael

> 
> Thanks,
> 
> Josie Imlay
> 
> 
> _______________________________________________
> OAI-implementers mailing list
> OAI-implementers@oaisrv.nsdl.cornell.edu
> http://oaisrv.nsdl.cornell.edu/mailman/listinfo/oai-implementers
> 

---
Michael L. Nelson
NASA Langley Research Center		m.l.nelson@larc.nasa.gov
MS 158, Hampton, VA 23681		http://www.ils.unc.edu/~mln/
+1 757 864 8511				+1 757 864 8342 (f)