Re: [Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Chris Travers
I.e. what password do we use to create our primary database connection for the application? Best Wishes, Chris Travers - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http:/

Re: [Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Chris Travers
On 10/1/07, Joshua D. Drake <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Chris Travers wrote: > > On 10/1/07, Joshua D. Drake <[EMAIL PROTECTED]> wrote: > >> - > >> > >> passwords will not be stored as plain text... they will be an encrypted > >> hash. I am not

Re: [Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Joshua D. Drake
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Chris Travers wrote: > On 10/1/07, Joshua D. Drake <[EMAIL PROTECTED]> wrote: >> - >> >> passwords will not be stored as plain text... they will be an encrypted >> hash. I am not understanding the problem. > > > Log in to LedgerSMB with your DB usern

Re: [Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Chris Travers
On 10/1/07, Joshua D. Drake <[EMAIL PROTECTED]> wrote: > > - > > passwords will not be stored as plain text... they will be an encrypted > hash. I am not understanding the problem. Log in to LedgerSMB with your DB username and password. Click on a link. How does the application know what passwo

Re: [Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Joshua D. Drake
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Chris Travers wrote: > In going to native DB accounts, one of the difficulties we have to resolve > is how to effectively authenticate serial requests. The major problem has > to do with how the password to the database is stored. I am going to > sug

[Ledger-smb-devel] Re-authentication proposal for LedgerSMB 1.3 (HTTP Auth)

2007-10-01 Thread Chris Travers
In going to native DB accounts, one of the difficulties we have to resolve is how to effectively authenticate serial requests. The major problem has to do with how the password to the database is stored. I am going to suggest that we move to using HTTP authentication as the primary mechanism of a