19 Apr
2000
19 Apr
'00
3:41 p.m.
On Wed, Apr 19, 2000 at 03:18:11PM +0200, Joachim Werner wrote:
Having "native" SSL support in Zope surely would be a GOOD THING (tm).
It has been done, by yours truly, and is known as ZServerSSL. See http://www.post1.com/home/ngps/m2.
But SSL wouldn't help with the password issue! Getting into an SSL-secured page by guessing the password isn't any harder than without SSL. The only advantage is that the password cannot be "sniffed", only guessed.
I have thought about (and mentioned ;-) a certUserFolder which accepts authentication via X.509 certificates. Still thinking, no code yet. -- Ng Pheng Siong <ngps@post1.com> * http://www.post1.com/home/ngps