Using AWS API Gateway as a licensing server2019 Community Moderator ElectionHow to pass a querystring or route parameter to AWS Lambda from Amazon API GatewayAWS API-Gateway client authentication and NGINXAWS: Amazon API Gateway Unknown Endpoint Error upon Testing Deployed APILimiting public api gateway to specific IPAPI Gateway intermittently returns “No 'Access-Control-Allow-Origin' header is present…” when the CORS OPTIONS request completes successfullyHTTP Certificate Pinning (HPKP) with AWS LambdaAWS API Gateway to .NET Core Web Api running in ECSSIM 800 GPRS modem for HTTP GET and POST to AWS IoT and AWS API gatewayRestrict API access to specific app clientsInvalidate credentials on Logout with IAM secured AWS API Gateway

Rejected in 4th interview round citing insufficient years of experience

Make a transparent 448*448 image

What to do when during a meeting client people start to fight (even physically) with each others?

Aliens englobed the Solar System: will we notice?

Could a cubesat be propelled to the moon?

A three room house but a three headED dog

Am I not good enough for you?

Can you reject a postdoc offer after the PI has paid a large sum for flights/accommodation for your visit?

Offered promotion but I'm leaving. Should I tell?

Do I really need to have a scientific explanation for my premise?

Built-In Shelves/Bookcases - IKEA vs Built

Force user to remove USB token

What Happens when Passenger Refuses to Fly Boeing 737 Max?

Why is this plane circling around the Lucknow airport every day?

Could a cubesat propel itself to Mars?

Replacing Windows 7 security updates with anti-virus?

What is the likely impact of grounding an entire aircraft series?

BitNot does not flip bits in the way I expected

Grey hair or white hair

Is it true that real estate prices mainly go up?

String reversal in Python

PTIJ: Why can't I eat anything?

They call me Inspector Morse

Good for you! in Russian



Using AWS API Gateway as a licensing server



2019 Community Moderator ElectionHow to pass a querystring or route parameter to AWS Lambda from Amazon API GatewayAWS API-Gateway client authentication and NGINXAWS: Amazon API Gateway Unknown Endpoint Error upon Testing Deployed APILimiting public api gateway to specific IPAPI Gateway intermittently returns “No 'Access-Control-Allow-Origin' header is present…” when the CORS OPTIONS request completes successfullyHTTP Certificate Pinning (HPKP) with AWS LambdaAWS API Gateway to .NET Core Web Api running in ECSSIM 800 GPRS modem for HTTP GET and POST to AWS IoT and AWS API gatewayRestrict API access to specific app clientsInvalidate credentials on Logout with IAM secured AWS API Gateway










0















Is using AWS API Gateway as a license check server a good approach to limit access to a desktop application? Assuming I hand out API keys to users and query my license server on each startup. I know that no method is 100% bulletproof and my application C code can be reverse-engineered, but I'm happy with weeding out 99.9%.



Correct me if I'm wrong, but the flow should be:



  1. Application queries the API Gateway

  2. Application performs certificate validation (to prevent host redirection)

  3. Application then sends the key to the API

  4. API answers with go/no-go

Can this be done in API Gateway or am I using the wrong tool?










share|improve this question






















  • The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

    – stdunbar
    Mar 7 at 20:43















0















Is using AWS API Gateway as a license check server a good approach to limit access to a desktop application? Assuming I hand out API keys to users and query my license server on each startup. I know that no method is 100% bulletproof and my application C code can be reverse-engineered, but I'm happy with weeding out 99.9%.



Correct me if I'm wrong, but the flow should be:



  1. Application queries the API Gateway

  2. Application performs certificate validation (to prevent host redirection)

  3. Application then sends the key to the API

  4. API answers with go/no-go

Can this be done in API Gateway or am I using the wrong tool?










share|improve this question






















  • The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

    – stdunbar
    Mar 7 at 20:43













0












0








0








Is using AWS API Gateway as a license check server a good approach to limit access to a desktop application? Assuming I hand out API keys to users and query my license server on each startup. I know that no method is 100% bulletproof and my application C code can be reverse-engineered, but I'm happy with weeding out 99.9%.



Correct me if I'm wrong, but the flow should be:



  1. Application queries the API Gateway

  2. Application performs certificate validation (to prevent host redirection)

  3. Application then sends the key to the API

  4. API answers with go/no-go

Can this be done in API Gateway or am I using the wrong tool?










share|improve this question














Is using AWS API Gateway as a license check server a good approach to limit access to a desktop application? Assuming I hand out API keys to users and query my license server on each startup. I know that no method is 100% bulletproof and my application C code can be reverse-engineered, but I'm happy with weeding out 99.9%.



Correct me if I'm wrong, but the flow should be:



  1. Application queries the API Gateway

  2. Application performs certificate validation (to prevent host redirection)

  3. Application then sends the key to the API

  4. API answers with go/no-go

Can this be done in API Gateway or am I using the wrong tool?







amazon-web-services aws-api-gateway






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 7 at 7:53









susdususdu

434312




434312












  • The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

    – stdunbar
    Mar 7 at 20:43

















  • The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

    – stdunbar
    Mar 7 at 20:43
















The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

– stdunbar
Mar 7 at 20:43





The "go/no-go" requires some code that API gateway realistically won't be able to provide (unless you have only a few licenses). More likely you'll put a Lambda behind API gateway to, for example, read from a DynamoDB table to check if the provided license is still valid.

– stdunbar
Mar 7 at 20:43












0






active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55038651%2fusing-aws-api-gateway-as-a-licensing-server%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55038651%2fusing-aws-api-gateway-as-a-licensing-server%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Can't initialize raids on a new ASUS Prime B360M-A motherboard2019 Community Moderator ElectionSimilar to RAID config yet more like mirroring solution?Can't get motherboard serial numberWhy does the BIOS entry point start with a WBINVD instruction?UEFI performance Asus Maximus V Extreme

Identity Server 4 is not redirecting to Angular app after login2019 Community Moderator ElectionIdentity Server 4 and dockerIdentityserver implicit flow unauthorized_clientIdentityServer Hybrid Flow - Access Token is null after user successful loginIdentity Server to MVC client : Page Redirect After loginLogin with Steam OpenId(oidc-client-js)Identity Server 4+.NET Core 2.0 + IdentityIdentityServer4 post-login redirect not working in Edge browserCall to IdentityServer4 generates System.NullReferenceException: Object reference not set to an instance of an objectIdentityServer4 without HTTPS not workingHow to get Authorization code from identity server without login form

2005 Ahvaz unrest Contents Background Causes Casualties Aftermath See also References Navigation menue"At Least 10 Are Killed by Bombs in Iran""Iran"Archived"Arab-Iranians in Iran to make April 15 'Day of Fury'"State of Mind, State of Order: Reactions to Ethnic Unrest in the Islamic Republic of Iran.10.1111/j.1754-9469.2008.00028.x"Iran hangs Arab separatists"Iran Overview from ArchivedConstitution of the Islamic Republic of Iran"Tehran puzzled by forged 'riots' letter""Iran and its minorities: Down in the second class""Iran: Handling Of Ahvaz Unrest Could End With Televised Confessions""Bombings Rock Iran Ahead of Election""Five die in Iran ethnic clashes""Iran: Need for restraint as anniversary of unrest in Khuzestan approaches"Archived"Iranian Sunni protesters killed in clashes with security forces"Archived