Also, just to say that I did a test on only letting authenticated and managers view the root page of the site over ssl. If you just cancelled the login box or closed it, the whole front page was displayed without any css but you could still get all the content. I've had this quite a bit before so that's why I'm looking into Apache authentication. I just don't think that Zope authentication is secure.

On 2/7/06, michael nt milne <[EMAIL PROTECTED]> wrote:
Also I'm implementing an extranet solution where extra security is
required-so therefore an apache login and a further plone login for
editing the site.

On 2/7/06, michael nt milne < [EMAIL PROTECTED]> wrote:
> Sorry but there's alot of Apache knowledge here and it's completely
> relevant. Also Zope doesn't do SSL well and all password - login is
> basically insecure! I've found out that  I'm best using httpd.conf and
> not htaccess . Also irc.freenode is unusable.
>
> On 2/7/06, Chris Withers <[EMAIL PROTECTED]> wrote:
> > michael nt milne wrote:
> > > I've managed to set-up SSL over Apache and Zope/Plone virtual hosts on
> > > Windows but am slightly stuck on implementing the htaccess part of my
> > > solution. I've done extensive googleing but can't seen to find any
> solid
> > > documentation.
> >
> > This is an Apache question, go ask on #apache on irc.freenode.net!
> >
> > I really don't understand why you'd use htaccess is you're already using
> >   Zope...
> >
> > cheers,
> >
> > Chris
> >
> > --
> > Simplistix - Content Management, Zope & Python Consulting
> >             - http://www.simplistix.co.uk
> >
> >
>
>
> --
> Michael
>


--
Michael



--
Michael
_______________________________________________
Zope maillist  -  Zope@zope.org
http://mail.zope.org/mailman/listinfo/zope
**   No cross posts or HTML encoding!  **
(Related lists - 
 http://mail.zope.org/mailman/listinfo/zope-announce
 http://mail.zope.org/mailman/listinfo/zope-dev )

Reply via email to