Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Cross site authentication - is it safe?Cross site authentication - is it safe?
Previous
 
Next
New Post
1/13/2011 7:24 PM
 
We need to set up several different sites, or rather, different version of the same site, because of different site settings regarding SSL client certificates. Because they are actually the same site, they will use the same website directory on disc, and so web.config, machinekeys etc. will be the same.

Now, what we want to do is to redirect all users to the same "base site" (same URL) once they have passed the authentication and have been logged into each respective site, and naturally, we wan't them to stay logged even after redirection. To do this, we have modified the <authenticaion> in web.config to include domain like:

<authentication mode="Forms">
      <forms name=".DOTNETNUKE" protection="All" timeout="30" cookieless="UseCookies" domain="mydomain.com"/>
</authentication>

which seem to work well in the testing we have done so far.

But still, we would like some feedback if this is a safe way to do it, if there are better ways and if there are any DotNetNuke specifics to consider here?

Thank you!
 
New Post
1/14/2011 2:29 PM
 
By setting the domain you are simply ensuring that the cookie can be read as they go across the different portals/sites.

-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
1/17/2011 5:46 AM
 
Yes, this I know Was just conserned if this could have security drawback or similar, or perhaps DNN issues, especially for the "abandoned" DNN portal (we use Response.Redirect after successful login)?

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Cross site authentication - is it safe?Cross site authentication - is it safe?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out