Re: [fossil-users] Secure auth without SSL

2012-08-07 Thread Bill Burdick
I believe Fossil sends passwords in clear text, right now, but it would be possible to change it to use a challenge handshake -- I don't know the details of the protocol, but maybe there's a provision for using alternate protocol versions, so that fossil server could support both types of authentic

Re: [fossil-users] Secure auth without SSL

2012-08-07 Thread Andreas Kupries
On 8/6/2012 8:57 AM, David Given wrote: I would like to run Fossil for a project on Sourceforge. This would live inside the project's CGI space. Unfortunately Sourceforge doesn't support SSL for project websites. This means that all Fossil communications would be in the clear. This isn't a probl

[fossil-users] Secure auth without SSL

2012-08-06 Thread David Given
I would like to run Fossil for a project on Sourceforge. This would live inside the project's CGI space. Unfortunately Sourceforge doesn't support SSL for project websites. This means that all Fossil communications would be in the clear. This isn't a problem content-wise, as this is an open source