SSO & HTTPS on pear.php.net
| From: | Tobias Schlitt | Date: | Fri, 07 May 2004 11:54:29 +0000 |
| Subject: | SSO & HTTPS on pear.php.net | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-28951@lists.php.net to get a copy of this message | ||
Hi!
Resulting from the discussions on the Wiki Auth and the non-secure
connection one can have all over the world (as we had in A'dam), I would
suggest the following things for PEARWeb (if possible):
a) Enable HTTPS for PEARWeb. There are so many places (espacially when using
wifi) where you have non-secure network connections. I hope that works on
the server?
b) Invent a real authentication method for the RPC connections of PEARWeb. I
guess that's a very usefull service, for services related with PEAR. In this
case the wiki, but may be we get sometimes a messageboard and even an
integration into PEARBot would be cool (so that you authenticate in #pear
and are not bind to the hostmask).
For more security i would suggest to remove the password (even if it's
hashed) from the PEARWeb cookie and invent something like a ticket system
for that (ticket is generated while logon and renewed everytime you get
back). This would also be feasible for the RPC stuff.
Ideas on that? (Flames please directly to /dev/null !)
Regards,
Toby
--
Tobias Schlitt
a passion for php http://www.schlitt.info