Re: SSL & Basic Authentication



I suppose I was asking in relative terms. Since we need some form of
authentication, how does Basic Authentication with SSL using a 1024 bit key
rate to some of the other forms of authentication? I understand that Basic
Authentication by itself isn't considered secure by any measure, but when
adding SSL to the mix how much does that increase the security, since the
user ID & password are now encrypted? I assume the user ID & password are
encrypted, please correct me if I'm wrong on that matter.

Thanks,

BigSam

"David Wang" wrote:

On Aug 14, 12:53 pm, BigSam <Big...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
We've a web site that has a certificate in use & all pages are using SSL.
Some pages are configured to use Basic Authentication; we're connecting to
these with mobile devices.
How secure is the process? Should I look for better methods?


You need to first define your security threshold and tolerence before
asking/evaluating the security of any configuration.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//

.



Relevant Pages

  • Re: SSL & Basic Authentication
    ... Basic over SSL directly fails all the points I listed, ... you want to have control of how authentication is ... you can control security from start to finish. ... "more" secure than no encryption. ...
    (microsoft.public.inetserver.iis.security)
  • Re: is ssl secure enough ?
    ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... Not "is SSL perfect". ... The fact that I am using a two factor authentication should ... > If you really want to start being impractical then stop using TCP/IP ...
    (microsoft.public.windows.server.security)
  • RE: ASP.NET + SQL Server Windows authentication
    ... The problem is actually related to ASP.NET security. ... | Trying to understand why I can not get SQL server to trust my IIS server. ... | applications access to the DB server via NT Authentication. ... Basic Authentication will transfer the PW ...
    (microsoft.public.sqlserver.security)
  • Re: General (simple) question on web security
    ... Form authentication plus SSL is OK. ... Just keep in mind that security ... !any interaction to the web application trough stored procedures and granted ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle att
    ... You don't need additional message based security. ... SSL also does server authentication by default. ... I plan on upgrading my .NET 2.0 web service to use WSE 3.0. ...
    (microsoft.public.dotnet.framework.aspnet.security)