[Zope] sending a encrypted login URL

Tino Wildenhain tino at wildenhain.de
Wed Mar 4 11:46:24 EST 2009


Andreas Jung wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Use SSL and you're done.

SSL solves SSO? I don't think so.

Cheers
Tino

> - -aj
> 
> On 04.03.2009 17:29 Uhr, Joseph Thomas (s) wrote:
>> We’d like to construct a zope login URL of the form on another server:
>>
>>  
>>
>> http://zope.domain:port/context/logged_in?__ac_name=uzzzzzz&__ac_password=xxxxxxx&submit=Log+in
>> <http://zope.domain:port/context/logged_in?__ac_name=uzzzzzz&__ac_password=xxxxxxx&submit=Log+in>
>>
>>  
>>
>>  
>>
>> where the ac_name and ac_password parameters are encrypted using zope
>> public key (?) and have the parameters decrypted when zope receives the
>> request and login the user.
>>
>>  
>>
>> Is there an API or some way to encrypt the username and password on the
>> 3^rd party app server and configure zope so that it treats the
>> parameters as encrypted values rather than plaintext?
>>
>>  
>>
>> Joseph Thomas
>>
>> College of American Pathologists
>>
>> http://www.cap.org <http://www.cap.org/>
>>
>>  
>>
>>
>> ------------------------------------------------------------------------
>>
>> _______________________________________________
>> Zope maillist  -  Zope at zope.org
>> http://mail.zope.org/mailman/listinfo/zope
>> **   No cross posts or HTML encoding!  **
>> (Related lists - 
>>  http://mail.zope.org/mailman/listinfo/zope-announce
>>  http://mail.zope.org/mailman/listinfo/zope-dev )
> 
> 
> - -- 
> ZOPYX Ltd. & Co. KG - Charlottenstr. 37/1 - 72070 Tübingen - Germany
> Web: www.zopyx.com - Email: info at zopyx.com - Phone +49 - 7071 - 793376
> Registergericht: Amtsgericht Stuttgart, Handelsregister A 381535
> Geschäftsführer/Gesellschafter: ZOPYX Limited, Birmingham, UK
> - ------------------------------------------------------------------------
> E-Publishing, Python, Zope & Plone development, Consulting
> 
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.9 (Darwin)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
> 
> iEYEARECAAYFAkmurnAACgkQCJIWIbr9KYylKQCgn3WWP5SzGrrAQbJIQXv7Bfac
> 3fwAoIiI4iwtVBFVRg7jtZu5Vgy5fw3f
> =MHol
> -----END PGP SIGNATURE-----
> 
> _______________________________________________
> Zope maillist  -  Zope at zope.org
> http://mail.zope.org/mailman/listinfo/zope
> **   No cross posts or HTML encoding!  **
> (Related lists - 
>  http://mail.zope.org/mailman/listinfo/zope-announce
>  http://mail.zope.org/mailman/listinfo/zope-dev )


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3241 bytes
Desc: S/MIME Cryptographic Signature
Url : http://mail.zope.org/pipermail/zope/attachments/20090304/5a73a597/attachment.bin 


More information about the Zope mailing list