Re: SSO & HTTPS on pear.php.net
| From: | Martin Jansen | Date: | Fri, 07 May 2004 13:19:15 +0000 |
| Subject: | Re: SSO & HTTPS on pear.php.net | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28957@lists.php.net to get a copy of this message | ||
On Fri May 07, 2004 at 01:5429PM +0200, Tobias Schlitt wrote:
> a) Enable HTTPS for PEARWeb. There are so many places (espacially when using
> wifi) where you have non-secure network connections. I hope that works on
> the server?
Most of the things for SSL support is already in place. Basically I
only need to get around to rebuild Apache+mod_ssl on the box.
> b) Invent a real authentication method for the RPC connections of
> PEARWeb.
Please define "real". I thought about this a bit and I came up with the
idea of having something like
boolean user.isValid(string username, string password_hash)
which returns true if username/password_hash are valid and false if
not. This still makes it possible to guess the password by flooding the
RPC server with requests, but it at least makes things a bit more
complicated.
Additionally one might restrict access to user.isValid to certain IP
addresses.
>I
> guess that's a very usefull service, for services related with PEAR. In this
> case the wiki, but may be we get sometimes a messageboard and even an
> integration into PEARBot would be cool (so that you authenticate in #pear
> and are not bind to the hostmask).
Guys, I'm not sure if I like the idea of using the login database for
this sort of stuff.
And pear-dev is really not the place for such a discussion.
--
- Martin Martin Jansen
http://martinjansen.com/