SSO & HTTPS on pear.php.net

From: Date: Fri, 07 May 2004 11:54:29 +0000
Subject: SSO & HTTPS on pear.php.net
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-28951@lists.php.net to get a copy of this message
Hi! Resulting from the discussions on the Wiki Auth and the non-secure connection one can have all over the world (as we had in A'dam), I would suggest the following things for PEARWeb (if possible): a) Enable HTTPS for PEARWeb. There are so many places (espacially when using wifi) where you have non-secure network connections. I hope that works on the server? b) Invent a real authentication method for the RPC connections of PEARWeb. I guess that's a very usefull service, for services related with PEAR. In this case the wiki, but may be we get sometimes a messageboard and even an integration into PEARBot would be cool (so that you authenticate in #pear and are not bind to the hostmask). For more security i would suggest to remove the password (even if it's hashed) from the PEARWeb cookie and invent something like a ticket system for that (ticket is generated while logon and renewed everytime you get back). This would also be feasible for the RPC stuff. Ideas on that? (Flames please directly to /dev/null !) Regards, Toby -- Tobias Schlitt a passion for php http://www.schlitt.info

« previous php.pear.dev (#28951) next »