HTTP-only ACS URL

Tom Scavo trscavo at gmail.com
Tue Aug 2 21:04:26 BST 2011


On Tue, Aug 2, 2011 at 3:52 PM, Chad La Joie <lajoie at itumi.biz> wrote:
> The only thing I could think of doing
> that would enable this (but should scare your users) is to server up
> the login page via HTTP but adjust the login page to submit to HTTPS.
> That would, I think, keep the credentials secure...

That, it would seem, would encourage phishing since a
man-in-the-middle could substitute a bogus URL in the HTML form.

Tom


More information about the users mailing list