Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...SSL for Login and passwords in clear textSSL for Login and passwords in clear text
Previous
 
Next
New Post
4/4/2011 4:21 AM
 
Hello All,

SSL for login
I recently had some criticism on a site I developed because we are not using SSL on the login page.  I had hoped to avoid the hassle of implementing that, however, I now have to respond to my customer, and justify not using it, or else implement it.

Can I has if there is any recommended reading on this topic?  Do I really need it, what are the downsides of now encrypting the U and P other than to avoid sniffing of the traffic.



the second question that was raised was why we are supplying the password in clear text, in an obviously two way encryption algorithm.  I was accused of having '5 year old technology'.  That smarted a little :)  However, I do think his question is valid,
why do we store our passwords like this,
is there an option in DNN to use one way encryption for passwords, and 
is there a way to avoid sending the password out, IOW, to pretend we are using one way encryption.

thanks in advance for any comments on these two related questions,

Mark





Mark Breen Ireland 1987 BMW R80 g/s
 
New Post
4/4/2011 10:07 AM
 
Hi Mark,

Can't help with your first question, but you might want to look at what Mitchel wrote here:
http://www.iowacomputergurus.com/blog... 

and then here:
http://www.iowacomputergurus.com/blog... 

Hope this helps

Barry
 
New Post
4/4/2011 2:41 PM
 
Mark Breen wrote:
SSL for login
I recently had some criticism on a site I developed because we are not using SSL on the login page.  I had hoped to avoid the hassle of implementing that, however, I now have to respond to my customer, and justify not using it, or else implement it.

 I've not tested this, but I would think it was quite easy.
- add a new page to the site - named (say) Login
- add an Account Login module to the page.
- TEST IT TO MAKE SURE YOU CAN LOGIN WITH THE NEW PAGE
- in site settings choose the new Login page for logging in
- mark the new page (in settings) to require a secure connection

Am I missing somthing?


Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
New Post
4/4/2011 3:40 PM
 
Your not missing anything in that aspect. Securing the entry points (Login/Registration and any other form input that may disclose user information) is always a good idea, However, this does nothing to resolve sending "lost" passwords/password retrievals.

Mitch's solution posted above looks promising...


 
New Post
5/12/2011 2:48 PM
 
Hello Guys,

thanks for the very useful responses here.

I appreciate your time,

Mark

Mark Breen Ireland 1987 BMW R80 g/s
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...SSL for Login and passwords in clear textSSL for Login and passwords in clear text


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out