Re: [rt.blitzed.org #189] staff site authentication

"Andy Smith via RT" <[email protected]>
Newsgroups gmane.network.irc.blitzed.web
Message-ID <[email protected]>
<URL: http://rt.blitzed.org:80/Ticket/Display.html?id=189 >

On Tue, Dec 16, 2003 at 09:12:02PM +0000, David Leadbeater via RT wrote:
> I think maybe what would be best is if http://blitzed.org/login/ was
> made to use SSL - then the staff site could use that along with the
> other things and things like quotes.blitzed.eu.org would benefit from
> SSL encrypted passwords.

I have a couple of slight problems with this:

1) We can't afford to buy a real certificate from a CA, so it would
   have to be self-signed, which will pop up a scary dialog in
   users' browsers.  This is acceptable for staff site, but might
   not be so good for general users.

2) The individual users themselves won't get the chance to pick
   which version they use (http or ssl) because it is a form on the
   third party site that sends them there.  If a lot of people
   couldn't/wouldn't use SSL then sites would have to provide two
   forms.

I guess (2) isn't so bad, but (1) is a real shame.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.