Re: HTTP Authentication



slebetman wrote:
Michael wrote:
[...]
Don't I need some kind of certificate for SSL?

Generally you'll need a certificate if you are a server. Clients
usually don't need certificates (after all, what people want is to know
that the server is legit - they are not being phished).

Somewhat off-topic, but: server-side SSL certificates, as
they are commonly used on the Web today, don't do squat
against phishing. That little padlock icon in the corner
of your web browser? All it means is that the party at
the other end of the connection has given a CA some money
to get a signed certificate. (That, and you can be confident
that no bad guys running a packet sniffer on your LAN
will be able to eavesdrop.)

Now it's possible to use SSL in a way that provides rock-solid
protection against phishing (and many other attacks). Unfortunately
today's generation of web browsers don't use it that way.


--Joe English
.



Relevant Pages

  • RE: SSL MITM not on port 443
    ... Have you ever done what you're trying to do on a "normal" SSL web ... My recommendation would be to set up a web server in your lab ... hopes that the client will accept that certificate. ... SSL MITM not on port 443 ...
    (Pen-Test)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Publish SSL Web Server behind SBS2003
    ... > How to configure a certificate for use with a Web publishing rule in ISA ... > Server 2004 ... > RWW/OWA for SSL encryption. ... Right click the SSL Web Site and click Properties. ...
    (microsoft.public.windows.server.sbs)
  • Re: "Could not connect to server" error when accessing Outlook 200
    ... Perhaps when you connect via RDP, you have to use SSL. ... The server you are connected to is using a security certificate ... A certificate chain processed, but terminated in a root certificate which is ... Settings on the Advanced tab. ...
    (microsoft.public.outlook.installation)
  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)