Re: [rt.blitzed.org #189] staff site authentication
"Andy Smith via RT" <[email protected]>
| Newsgroups | gmane.network.irc.blitzed.web |
|---|---|
| Message-ID | <[email protected]> |
<URL: http://rt.blitzed.org:80/Ticket/Display.html?id=189 > On Tue, Dec 16, 2003 at 09:12:02PM +0000, David Leadbeater via RT wrote: > I think maybe what would be best is if http://blitzed.org/login/ was > made to use SSL - then the staff site could use that along with the > other things and things like quotes.blitzed.eu.org would benefit from > SSL encrypted passwords. I have a couple of slight problems with this: 1) We can't afford to buy a real certificate from a CA, so it would have to be self-signed, which will pop up a scary dialog in users' browsers. This is acceptable for staff site, but might not be so good for general users. 2) The individual users themselves won't get the chance to pick which version they use (http or ssl) because it is a form on the third party site that sends them there. If a lot of people couldn't/wouldn't use SSL then sites would have to provide two forms. I guess (2) isn't so bad, but (1) is a real shame.