Well, since you use HTTPS , you donβt have to worry about sending passwords in text form. Therefore, as long as your authentication works correctly (you say that the repo has been checked for security), it is pretty safe.
In addition, you have an encrypted payload with PGP that is truly secure - at least as long as all parties process their keys with the necessary care.
-> What you describe sounds pretty solid to me, especially with PGP asynchronous encryption, which is mostly not attacked (unless you are considering social engineering).
Maybe the last thought (but I think you do not need this advice):
I donβt know about Websphere, but other application servers or ESBs (like JBoss) have some default administrative tools that are usually freely available over the Internet (just google for / jmx-console ...). Be sure to provide security with a password or disable them if necessary.
source share