Which passwords?
- passwords sent in a url: yes
- passwords sent via the login page: no
- passwords sent for the mid-tier config page: no
- passwords for each server as configured in the mid-tier config page: no

In the first case, an ssl cert will not help you.  In the 2nd and 3rd
cases, an ssl cert will strengthen the data against outside
eavesdroppers.  In the 4th case, configuring encryption on the
arserver will strengthen the data against outside eavesdroppers.

Axton Grams

On 9/27/07, Greg Donalson <[EMAIL PROTECTED]> wrote:
> ARSList,
>
> Are Mid-Tier passwords passed in clear text?  If so, is the best way to get 
> around this is to add a security certificate to the Mid-Tier server?  Or are 
> there other ways to get around it?  Thanks!
>
> Greg
>
> _______________________________________________________________________________
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the 
> Answers Are"
>

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the 
Answers Are"

Reply via email to