HTTP-only ACS URL
Tom Scavo
trscavo at gmail.com
Tue Aug 2 21:04:26 BST 2011
On Tue, Aug 2, 2011 at 3:52 PM, Chad La Joie <lajoie at itumi.biz> wrote:
> The only thing I could think of doing
> that would enable this (but should scare your users) is to server up
> the login page via HTTP but adjust the login page to submit to HTTPS.
> That would, I think, keep the credentials secure...
That, it would seem, would encourage phishing since a
man-in-the-middle could substitute a bogus URL in the HTML form.
Tom
More information about the users
mailing list