Re: [viewvc-users] how would I configure Apache to force cookies to be secure?
Notice Sender <[email protected]>
| Newsgroups | gmane.comp.version-control.cvs.viewcvs.user |
|---|---|
| Message-ID | <AANLkTi=4Ejtu3h894JKg5LZHNB0O0Yuonmcc81MRu-iW__4708.10089395872$1283912489$gmane$org@mail.gmail.com> |
> ViewVC doesn't use session cookies (or any cookies, for that matter). If > you configure ViewVC to use weak authentication (Basic auth over unencrypted > HTTP), then sure, someone could sniff the Basic auth credentials and use > them. If that's a concern, then don't do that. Use SSL or somesuch. That's great news -- thanks for the quick response! I am already using SSL to protect the transmission of the source code, and just wanted to make sure that the system is not vulnerable to people sniffing session cookies. Thanks for a great product, Jerry ------------------------------------------------------ http://viewvc.tigris.org/ds/viewMessage.do?dsForumId=4255&dsMessageId=2656622 To unsubscribe from this discussion, e-mail: [[email protected]].