LSTSRV-L Archives

LISTSERV Site Administrators' Forum

LSTSRV-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Andrew Bosch <[log in to unmask]>
Fri, 17 Mar 2000 14:32:41 -0600
text/plain (13 lines)
The passwords are only sent once in a session, while the remainder of the session uses tickets (like Kerberos). I think you could protect the initial login by modifying the action tag in the login template so it doesn't use the &+SCRIPT macro to evaluate the WA url, but uses an URL with https in it.

>>> Kevin Williams <[log in to unmask]> 3/16/2000 2:02:28 PM >>>
Has anyone had any experience using Secure Socket Layers for the Web
interface to LISTSERV or Transport Layer Security with e-mail commands?

Some of our security people have expressed concern about the use of
clear-text passwords in managing LISTSERV.

--
Kevin Williams
Fermilab PC Support Group

ATOM RSS1 RSS2