Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Apache mod_auth_pam module




On Wednesday, November 27, 2002, at 02:29  AM, Josh Glover wrote:
>
> The mod_auth_pam documentation specifically says to use Basic, since 
> the
> user's web browser will transmit the password in the clear to Apache.
>
Yow - I had set up basic auth for a WebDAV share, against my better 
judgment and the advice of just about every site I came across, just 
because it goes in clear text. (But of course, I just wanted it to work 
quickly.) Clear text passwords give me the willies:
I had to empty my girlfriend's mailbox today (she was over her quota) 
and did it by telnetting in to port 110 of her server and it struck me 
again how totally insecure the whole mess is - I don't even telnet 
around on my own private network. I'd hate to set up a system that 
relied on it over a public network. I've messed about setting up Samba 
servers and always chose the "encrypted password" (or whatever it is) 
option. You sure there's nothing like that here?

> No chance of that, but a Quick-n-Dirty Guide should be forthcoming.
I look forward to it -
>
> Slightly off-topic, the Samba codebase is a bigger mess than I would 
> have
> believed before looking at it. I guess "real C coders" do not need to
> comment their code...
Other than this, how is Samba behaving?  It can be a bit tricky if you 
have to use a Win2K PDC, but it shouldn't have too much trouble 
otherwise. As a standalone PDC, it's pretty simple, really - I did it a 
while ago, when I was just starting to use Samba and don't remember any 
problems.  The only complaint I have is that it's too forgiving of 
misconfiguration - even if it's not all set up right, you can usually 
seem to get in...
>
Oh, well, it's after 3:00am here and I've been digging into my good 
whiskey as I try to get DNS (delegating reverse arpa on
non-octet boundaries) sorted out.  I hate DNS...

>
> -- 
> Josh Glover <jmglov@example.com>
>
> Associate Systems Administrator
> INCOGEN, Inc.
> http://www.incogen.com/
>
> GPG keyID 0x62386967 (7479 1A7A 46E6 041D 67AE  2546 A867 DBB1 6238 
> 6967)
> gpg --keyserver pgp.mit.edu --recv-keys 62386967
> <mime-attachment>


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links