Additional comment: it pays to have a staging server which is exactly configured like the live server. This way you can test for all kind of unexpected behaviour due to omissions you otherwise lightly overlook.
I still remember the time when libcrypt on my linux box was different from the live version (running Free BSD) and suddenly no of our customers could log in any more through a new series of CGI scripts. Big shame on us!
--
Cheers, Joe | [reply] |