Skip to main content
Bob Hatcher (Ticketmaster) a posé une question dans #Security
I am looking into the Apex Crypto class and forgive me but I am a novice to encryption and its methods, including web protocols such as HTTPS. Salesforce seems to position Crypto as a solution to encryption for both in-transit and at rest data. This implies that Apex Crypto has a role in encryption from the browser to the Salesforce server.

 

I'm hung up on how Apex, as a server-side solution, can be a factor in encrypting information before it hits Salesforce.

 

Is it assumed that standard Web protocols such as https are sufficient to ensure end to end encryption while in transit to Salesforce's servers? 

 

And data is decrypted at Salesforce and delivered over https to the browser, resulting in encryption on the round trip?
3 réponses
  1. 21 sept. 2018, 05:25
    You are absolutely correct. I think the question stems from your understanding of "in transit" as "in transit between the client and server on Salesforce" - where my understanding of it would be "in transit between the Salesforce server and a third party server".
0/9000