in reply to mmmmm .. cookies
As a professional web server admin, I'm not a big fan of using cookies to perform authentication/admission control.
If you are using Apache (and if you aren't, you have no hope of secure webservers anyway), you can block access using an .htaccess file or by specifying in the Directory tag in the httpd.conf file. It is very simple to setup "accounts" using a www_passwd file and www_group file. You can even (if using SSL) create the www_passwd file and synchronize it with your /etc/passwd file at set time periods so that there isn't a chance of your web accounts and system accounts passwords from becoming unsynchronized.
Anyone have any different thoughts on using cookies for admission control? I have always thought it better to use a DB oriented access method.
Look into Chapter 5 of the Appaloosa book. Good stuff. I may even post my password syncing script to the snippet section.
J. J. Horner
Linux, Perl, Apache, Stronghold, Unix
jhorner@knoxlug.org http://www.knoxlug.org
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
RE: RE: mmmmm .. cookies
by merlyn (Sage) on May 28, 2000 at 21:40 UTC | |
by swiftone (Curate) on May 30, 2000 at 17:08 UTC | |
|
RE: RE: mmmmm .. cookies
by BBQ (Curate) on May 29, 2000 at 09:53 UTC | |
|
RE: RE: mmmmm .. cookies
by Anonymous Monk on May 28, 2000 at 20:35 UTC | |
by mdillon (Priest) on May 28, 2000 at 20:52 UTC |