Re: [viewvc-users] how would I configure Apache to force cookies to be secure?

Notice Sender <[email protected]>
Newsgroups gmane.comp.version-control.cvs.viewcvs.user
Message-ID <AANLkTi=4Ejtu3h894JKg5LZHNB0O0Yuonmcc81MRu-iW__4708.10089395872$1283912489$gmane$org@mail.gmail.com>
> ViewVC doesn't use session cookies (or any cookies, for that matter).  If
> you configure ViewVC to use weak authentication (Basic auth over unencrypted
> HTTP), then sure, someone could sniff the Basic auth credentials and use
> them.  If that's a concern, then don't do that.  Use SSL or somesuch.

That's great news -- thanks for the quick response! I am already using
SSL to protect the transmission of the source code, and just wanted to
make sure that the system is not vulnerable to people sniffing session
cookies.

Thanks for a great product,
Jerry

------------------------------------------------------
http://viewvc.tigris.org/ds/viewMessage.do?dsForumId=4255&dsMessageId=2656622

To unsubscribe from this discussion, e-mail: [[email protected]].
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.