Re: SSL How-TO

dl
Date: 06/21/05


Date: Tue, 21 Jun 2005 22:25:52 +0800

I thought the content of the authentication cookie is an encrypted session
ticket, with no username / password information, isn't it?

"Dominick Baier [DevelopMentor]" <dbaier@pleasepleasenospamdevelop.com>
wrote in message news:501385632549583320741864@news.microsoft.com...
> Hello dl,
>
> i guess you are using FormsAuth - so authentication is based on a cookie.
> This cookie has to be transmitted to every pages that requires
authentication.
>
> This would mean that you secure the login page, but all remaining pages
will
> receive the cookie in clear text. If someone can steal/sniff that cookie
> he can hijack the authenticated users identity.
>
> or short - No.
>
> ---------------------------------------
> Dominick Baier - DevelopMentor
> http://www.leastprivilege.com
>
> > Hi
> > Can we set SSL enable only for the login page, in an ASP.NET
> > application
> > TIA
>
>
>



Relevant Pages

  • RE: A little problem with Forms authentication :-(
    ... I'm using forms authentication and the user is getting authenticated no ... should be redirected to the login page. ... I've set the time out for the cookie to the test value of 1 ... redirect from login bit because as I understand it, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Forms Authentication Name property
    ... you specify the name to be used for the authentication ... login page, then this can work. ... A cookie is saved by the BROWSER and ... The BROWSER chooses ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SSL Forms Authentication Redirect - Problem Redirecting out of HTTPS
    ... allowing an authentication cookie to be passed over an HTTP ... My login script goes into SSL just fine. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Forms authentication cookie handling question (C#)
    ... I also replaced all of my ticket authentication code with the ... // Username and or password not found in our database... ... LoginControl's default code logic to generate authentication cookie. ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: Authentication Ticket Persistance
    ... applications which both use forms authentication. ... web.config that points the login page to the login page of the second ... The second application has one button which gets the cookie, ... My sample worked fine if both web applications were on the same machine ...
    (microsoft.public.dotnet.framework.aspnet.security)