On Mittwoch, 28. Februar 2007 21:26 Martin Hierling wrote:
> thats not how shibboleth is working .... as far as i can say the
> framework only tells the webapp the user is authenticated. A
> password exchange is  not possible.

So from a security point of view it's broken by design. Or is that the 
idea behind that app?

mfg zmi
-- 
// Michael Monnerie, Ing.BSc    -----      http://it-management.at
// Tel: 0676/846 914 666                      .network.your.ideas.
// PGP Key:        "curl -s http://zmi.at/zmi4.asc | gpg --import"
// Fingerprint: EA39 8918 EDFF 0A68 ACFB  11B7 BA2D 060F 1C6F E6B0
// Keyserver: www.keyserver.net                   Key-ID: 1C6FE6B0

Attachment: pgpVUHo3mRCMi.pgp
Description: PGP signature

_______________________________________________
DBmail mailing list
[email protected]
https://mailman.fastxs.nl/mailman/listinfo/dbmail

Reply via email to