Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Secure LoginSecure Login
Previous
 
Next
New Post
3/17/2006 12:13 PM
 

Hi.  I verified that the login process for our DNN site is insecure.  I used the Ethereal to capture the packets when I logged into our DNN site, and the user name and password are definitely sent as clear text.  Because of the security issue, we haven't made our site available to the public yet, and have chosen to use it as an internal Intranet site for the time being.  I want to go ahead and secure the login procedure, though, so we can make the site available to the public without the security risk of passwords being sent as clear text.  I suspect that I can setup the entire site to be SSL, but that may have a significant on performance.

Question 1) Has anyone else setup their DNN site to use SSL, and if so what kind of a performance impact did you notice?

Question 2) Has anyone been able to setup the login session to use SSL without having to make the entire DNN site use SSL?

Question 3) Has anyone used another method besides SSL to secure the login to their DNN site?

 

Thanks,
Van


See Ya! Van
 
New Post
7/4/2007 12:42 PM
 

did you ever get an answer to your SSL question?

 
New Post
8/9/2007 1:23 PM
 

We have the exact same issues and concerns.  Is there an answer to the login name and password being sent in clear text?  Or any way other than setting up the entire website to be SSL?

We can do that, but what about current links, bookmarks, search engine placement, etc.  That isn't a pretty picture. 

The easiest solution would be a way to ssl the login module.  Can that be done?

Thanks, anyone that has a solution to this, that would be awesome.

 

 
New Post
8/9/2007 1:49 PM
 

This is how I do it:

http://www.snapsis.com/DotNetNuke/Support/tabid/560/forumid/12/postid/5068/view/topic/DNN-Tips-And-Tricks-5068.aspx

There is also a new feature in the latest version (DNN 4.5.5) that will let you force specific tabs to be secure:

http://www.snapsis.com/DotNetNuke/Support/tabid/560/forumid/16/postid/6400/view/topic/Default.aspx

 


DotNetNuke Modules from Snapsis.com
 
New Post
11/6/2007 2:21 PM
 

I've tested Mr. Mitchel's js by placing it in my default.aspx file of my instance folder - it does work, when the string 'login' is in the url the transfer protocol switches to https.  However my trouble lies with IIS itself in that I don't know how to install a certificate without the entire site requiring ssl.  I have a valid certificate in hand and I know how to go through the wizzard on the Direcotry Security tab on the website, I'm under the impression that this is going to require that all communication with this site be done using ssl.  I would like to pick and choose which dnn pages use ssl and not convert the entire site.  I've looked for a TID regarding this but I'm not having any luck locating instructions, can anyone here give me some direction?

Thanks much

Darin

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Secure LoginSecure Login


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out