Forums / Setup & design / SSL Login

SSL Login

Author Message

Yannick Koehler

Friday 04 April 2003 12:19:06 pm

I have a web hosting service that will provide me a proper SSL login secure with the correct SSL certificate sign with proper authority except that the domain name is different.

my site

http://ezpublish.mysite.com/index.php/user

my ssl secure login site

https://businessx.secure.com/mysite/index.php/user

Does ezpublish support this kind of scenario? What I'd like is for ezpublish to post the login form to the secure URL and once confirmed the identification that it return to the non-secure version for normal usage.

I would need such trick to occurs as well for password changing.

Any help would be appreciated, I'm a complete newbie for ezPublish and I'm investigating how easy it would be to move my own CMS to this one as it is more a framework and I like the idea.

Yannick Koehler
ykoehler@hotmail.com

Volker Lenz

Sunday 06 April 2003 3:20:10 am

If the content you offer is not worth SSL, why then making a big razzmatazz about encrypted user registration? This is nothing but fooling users. I dislike sites where you start with https just to be slightly redirected to http after login. If there is no content to protect, I recommend that you go the gmx-way of open registration with email adresses. This is very easy to accomplish with ezp3.
On the other hand, if you want to provide serious SSL sessions, the main piece of work is to create a good web server configuration with appropriate rewrite rules the redirection purposes as needed. Within ezp3, you may associate your content and site access with SSL-sessions or not as you like.

My site www.leportal.net is build that way (ezp3 + 1 public + 2 SSL-site access modes on a single ezp3 instance. Not much stuff inside yet, but it works as you would expect.

Regards

Volker

 

Kai Duebbert

Sunday 06 April 2003 10:37:08 pm

well, the obvious advantage of having an ssl login page is that you don't send the password unencrypted. Makes a lot of sense in my eyes. (One security hole less, always good.)

(sorry, can't answer the original question.)

Yannick Koehler

Tuesday 08 April 2003 11:25:21 am

Hi Volker,

>SSL-Login ? Possible, but what is it good for ...

To protect user's password and personal information. Many users re-use their password on several sites some of them using simple HTTP. This is a very highly security problem. While I personnaly can't force the user to use a different password I can at least attempt to minimize the impact of such insecure behavior by reducing the amount of public awareness of this piece of information. If I do so, maybe other site will also get the idea and support proper secure authentication scheme and will reduce the amount of identity theft going on.

> This is nothing but fooling users.

I disagree with you here. I believe that the password is transmitted securely between the home user and the site. It surely doesn't say that at the site only my script will get it but at least it reduce the possibilities. It also ensure that brothers and sisters who on community site may be interested in hacking access and posting stuff under other name won't be able to do so on the site without more thinking on their side.

>I recommend that you go the gmx-way of open registration
>with email adresses. This is very easy to accomplish with
>ezp3.

Hmm, maybe but people do not like to be enforced a certain password and are more likely to never come back to my site which is in the opposite direction of my goals. Also the idea of using an identity and password is to allow a more personal approach and if that identity is not strong then there's no real point in having it at all which again is not going toward my goals for my site.

There is also the part about providing the email address. Many site take this information as granted while many users are starting to be annoyed with spam and stop wanting to provide that piece of information. One of my goal is to go back in time where web site didn't require email addresses.

> On the other hand, if you want to provide serious SSL
> sessions, the main piece of work is to create a good web
> server configuration with appropriate rewrite rules the
> redirection purposes as needed. Within ezp3, you may
> associate your content and site access with SSL-sessions or
> not as you like.

Unfortunately, at the current time, I am not fortunate enough to own my web server/permanent connection or to have access as I wish to all its configuration. The scenario I described is the one I have to live with at the moment and I would appreciate help that support the scenario and not ask to change it, unless a hosting service allowing me such support be provided as well at the same cost as my current one 9$US a month, as I don't have that control at the present host.

Sincerely,

Yannick Koehler
ykoehler@hotmail.com

eZ debug

Timing: Jan 29 2025 23:44:36
Script start
Timing: Jan 29 2025 23:44:36
Module start 'content'
Timing: Jan 29 2025 23:44:37
Module end 'content'
Timing: Jan 29 2025 23:44:37
Script end

Main resources:

Total runtime1.1222 sec
Peak memory usage4,096.0000 KB
Database Queries199

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0060 588.8906180.8516
Module start 'content' 0.00601.0177 769.7422533.8594
Module end 'content' 1.02370.0985 1,303.6016337.3984
Script end 1.1222  1,641.0000 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00340.3060210.0002
Check MTime0.00140.1204210.0001
Mysql Total
Database connection0.00090.081310.0009
Mysqli_queries1.043192.94511990.0052
Looping result0.00140.12421970.0000
Template Total1.098697.920.5493
Template load0.00210.187820.0011
Template processing1.096597.706320.5482
Template load and register function0.00020.015310.0002
states
state_id_array0.00160.143610.0016
state_identifier_array0.00100.093320.0005
Override
Cache load0.00180.1594450.0000
Sytem overhead
Fetch class attribute can translate value0.00110.100440.0003
Fetch class attribute name0.00160.143250.0003
XML
Image XML parsing0.00310.274040.0008
class_abstraction
Instantiating content class attribute0.00000.001050.0000
General
dbfile0.01040.9242270.0004
String conversion0.00000.000430.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
4content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
8content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
5content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 20
 Number of unique templates used: 6

Time used to render debug report: 0.0001 secs