I miss understanding something using HMAC authentication for my RESTFull service . HMAC sing nature is concluded on request header , and this is clue . But what about the body of the request , it's not hashed , how we should secure them . Does this mean I have to use ssl to hash the body also . As you know HMAC is a one way hashing algorithm .
Thanks in advance ...