Re: s/key authentication for Apache on FreeBSD?

bruce_at_nikkel.com
Date: 12/10/03

  • Next message: James Welcher: "Re: s/key authentication for Apache on FreeBSD?"
    Date: Wed, 10 Dec 2003 21:26:23 +0100
    To: security@freebsd.org
    
    

    > What's needed is one-time passwords for "basic" authentication in
    > Apache.

    The problem with using s/key (or opie) together with http basic auth is
    the repetive nature of http requests. The webserver would expect see
    the basic authentication string with every single request. You would be
    promtped for your next onetime password for every single gif or link on
    the page requested. I don't know how practical that would be.

    Bruce Nikkel

    -- 
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: James Welcher: "Re: s/key authentication for Apache on FreeBSD?"

    Relevant Pages

    • Long URL crashes My Web Server 1.0.2
      ... Sometimes the "My Webserver V1.0 Control Panel" disappears immediately, ... You have to restart the "My Webserver" to get a running web server. ... they acknowledged the vulnerability. ... Felipe Moniz) check such long requests. ...
      (Bugtraq)
    • Re: Blocking Pop-Ups
      ... If you set up a webserver running on your local network, ... requests to that webserver. ... A simple search and replace on the hosts file, ... Tony Whitmore ...
      (comp.security.firewalls)
    • Re: Falscheintragung in DNS
      ... Ist ein Webserver schon falsch konfiguriert, ... Requests ohne Rücksicht auf den Host-Header beantwortet? ... Ist ein Mailserver schon eine Spamschleuder, ...
      (de.soc.recht.datennetze)
    • Re: [SLE] The Linux Box: How To Speed Up Firefox
      ... > webserver to take one heck of a hit you could also be blocking other ... > as everyone doesnt start doing it, but its still very, very impolite. ... requests thing, that's *per page* - Firefix will still only make *one* ... connection for each resource - it just fetches more than one resource at ...
      (SuSE)
    • Re: alias in IIS5.0
      ... IIS does not care about how the requests makes it to the webserver, ... > I've set up IIS5.0 on our Win2k Advanced Server and set up a web site on ... > intranet consists of two Win2K domains and a Unix ...
      (microsoft.public.inetserver.iis)