Re: At what layer to hash a password
Chris Travers <[email protected]>
| Newsgroups | gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Jun 28, 2010 at 1:37 PM, Niels Teusink <[email protected]> wrote: > No perfect solution I guess :) (especially if you have the multiple interfaces thing to take into account) The perfect solution would be to use mod_auth_krb5 with Apache and pass the ticket off to the application, database, etc. Only works well on intranets though..... Best Wishes, Chris Travers This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------