HTTP-only ACS URL

Chad La Joie lajoie at itumi.biz
Tue Aug 2 21:13:54 BST 2011


Yes, the whole premise is based around things that are bad.  There is
a reason people get warnings when they try to do stuff like this.

On Tue, Aug 2, 2011 at 16:04, Tom Scavo <trscavo at gmail.com> wrote:
> On Tue, Aug 2, 2011 at 3:52 PM, Chad La Joie <lajoie at itumi.biz> wrote:
>> The only thing I could think of doing
>> that would enable this (but should scare your users) is to server up
>> the login page via HTTP but adjust the login page to submit to HTTPS.
>> That would, I think, keep the credentials secure...
>
> That, it would seem, would encourage phishing since a
> man-in-the-middle could substitute a bogus URL in the HTML form.
>
> Tom
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list