Re: SSO & HTTPS on pear.php.net
| From: | Paul M Jones | Date: | Fri, 07 May 2004 12:34:30 +0000 |
| Subject: | Re: SSO & HTTPS on pear.php.net | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28954@lists.php.net to get a copy of this message | ||
On May 7, 2004, at 6:54 AM, Tobias Schlitt wrote:
First off: crypto is good, more is better.
a) Enable HTTPS for PEARWeb. There are so many places (espacially when using wifi) where you have non-secure network connections. I hope that works on the server?Or at least HTTPS for the authentication portion.
For more security i would suggest to remove the password (even if it's hashed) from the PEARWeb cookie and invent something like a ticket system for that (ticket is generated while logon and renewed everytime you get back). This would also be feasible for the RPC stuff.Would it work with existing versions of PEAR Auth? Implementation will be important. -- Paul M. Jones Savant: the simple alternative to Smarty for PHP. http://phpsavant.com/ DB_Table: build RDBMS tables and XHTML forms in one PHP class. http://wiki.ciaweb.net/yawiki/index.php?area=DB_Table Yawiki: your collaborative online documentation system. http://wiki.ciaweb.net/yawiki/index.php?area=Yawiki