Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread Robert Boyd
On 2/9/06, michael nt milne <[EMAIL PROTECTED]> wrote: > Over and out on this one from me and thanks for all your help Sorry but > SSL over virtual hosts *is* more involved that setting up a basic password > protect > My 2 cents on this thread: I've seen (ok, I've done, long ago) the following

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread Chris Withers
michael nt milne wrote: Over and out on this one from me You promise? ;-) Chris -- Simplistix - Content Management, Zope & Python Consulting - http://www.simplistix.co.uk ___ Zope maillist - Zope@zope.org http://mail.zope.org/mailman/li

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread michael nt milne
Over and out on this one from me and thanks for all your help Sorry but SSL over virtual hosts *is* more involved that setting up a basic password protectOn 2/9/06, Chris Withers <[EMAIL PROTECTED]> wrote: michael nt milne wrote:> Sorry but the SSL and virtual hosting through Apache is all wor

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread Chris Withers
michael nt milne wrote: Sorry but the SSL and virtual hosting through Apache is all working fine. It's only the authentication bit that I'm having an issue with. Should be easy compared to what I've configured previously. Yeahright, that gives some idea of the lack of understanding you have...

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread michael nt milne
Sorry but the SSL and virtual hosting through Apache is all working fine. It's only the authentication bit that I'm having an issue with. Should be easy compared to what I've configured previously. And isn't it Plone? :-) On 2/9/06, Chris Withers <[EMAIL PROTECTED]> wrote: michael nt milne wrote:>

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread Chris Withers
michael nt milne wrote: Look I'm having genuine issues here and to be honest there's no need to become personally insulting. And what do you think you're doing by continuously coming back with phantom problems that no-one else experiences because they don't exist? And how about your insiste

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-09 Thread Sascha Welter
(Wed, Feb 08, 2006 at 12:00:07PM -0500) [EMAIL PROTECTED] wrote/schrieb/egrapse: > From: michael nt milne <[EMAIL PROTECTED]> > Subject: [Zope] major problems placing authentication on an extranet > site-security flaw? > I have major problems here trying to set-up authentic

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
Look I'm having genuine issues here and to be honest there's no need to become personally insulting. I've just set-up Plone on an Windows server with SSL Apache and multiple virtual hosts so don't take kindly to a few of these remarks. The last piece of my jigsaw is authenication which is becoming

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Chris Withers
michael nt milne wrote: I have major problems here trying to set-up authentication over a whole Plone site using Zope. Using my superuser account I've navigated to the site root page in the ZMI where it lists all the site pages and objects etc. I've then gone into security, scrolled down to the b

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Andreas Pakulat
On 08.02.06 21:38:26, michael nt milne wrote: > Of course I did. Why on earth would you be able to view a front page of a > site when it is labelled as 'authenticated' and also as 'manager' ? just by > pressing cancel or return a few times. I just checked that with a plain Zope's index_html. I can

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Tino Wildenhain
Mark Barratt schrieb: > michael nt milne wrote: > ... > My other advice is to try not to touch ZMI security screens: if you're > using Plone you should try to set up the security you need in Plone as Ah yes, things are a bit different when plone comes in. Then Plone documentation should be consul

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Tino Wildenhain
michael nt milne schrieb: > Sorry but this is not my experience and I have experimented. Am using > gmail basic setting which I like. Be sure mailinglist people dont like it :-) Actually it should not bee too hard to 1) create a role, lets call it "Guests" (in / ) 2) create a user: guest (in /acl

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Mark Barratt
michael nt milne wrote: I find the Zope security, permissions set-up hideously complex and unusable to be honest and it doesn't even seem to work. Yes. But security is hard on any capable system, with users, groups, objects, applications all having security attributes and all those things in

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
Sorry but this is not my experience and I have experimented. Am using gmail basic setting which I like. On 2/8/06, Tino Wildenhain < [EMAIL PROTECTED]> wrote:michael nt milne schrieb:> Of course I did. Why on earth would you be able to view a front page of > a site when it is labelled as 'authentic

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Tino Wildenhain
michael nt milne schrieb: > Of course I did. Why on earth would you be able to view a front page of > a site when it is labelled as 'authenticated' and also as 'manager' ? > just by pressing cancel or return a few times. Big security flaw I'm > sorry. Also superuser passwords don't work when securi

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
I printed out the section on Zope security quite a while ago and read it. So it's not just in the last ten minutes. I haven't tried verbosesecurity just yet as I haven't had the time. Basically, the security should work without that. On 2/8/06, Andreas Pakulat <[EMAIL PROTECTED]> wrote: On 08.02.06

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Andreas Pakulat
On 08.02.06 21:25:33, michael nt milne wrote: > I've just tried this on a completely different server. I also made sure that > 'access contents information' was set to 'manager' and 'authenticated'. Wow, you read the zope-book on security, setup a new zope on a server and checked this in just 10 m

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
Of course I did. Why on earth would you be able to view a front page of a site when it is labelled as 'authenticated' and also as 'manager' ? just by pressing cancel or return a few times. Big security flaw I'm sorry. Also superuser passwords don't work when security is set up and I've tried this o

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Tino Wildenhain
michael nt milne schrieb: > Thanks for the advice. I'll have another look at the security settings > but this is undoubtedly an issue. The superuser password not working is > the main one etc. But ultimately my comments on usabiltity should be > taken on board because Zope security is overly com

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
I've just tried this on a completely different server. I also made sure that 'access contents information' was set to 'manager' and 'authenticated'.The same thing happens. The main password doesn't work and also you still get the main page contents if you keep cancelling or pressing return on the l

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
 Thanks for the advice. I'll have another look at the security settings but this is undoubtedly an issue.  The superuser password not working is the main one etc. But ultimately my  comments on usabiltity should be taken on board because Zope security is overly complex. On 2/8/06, Dieter Maurer <[E

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Dieter Maurer
michael nt milne wrote at 2006-2-8 16:48 +: >I have major problems here trying to set-up authentication over a whole >Plone site using Zope. Using my superuser account I've navigated to the site >root page in the ZMI where it lists all the site pages and objects etc. I've >then gone into securi

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Andreas Pakulat
On 08.02.06 16:48:08, michael nt milne wrote: > I have major problems here trying to set-up authentication over a whole > Plone site using Zope. Start simple, start up a plain Zope, create a ZPT or DTML and change it's view right. See what happens. > I find the Zope security, permissions set-up h

Re: [Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread Jens Vagelpohl
On 8 Feb 2006, at 16:48, michael nt milne wrote: I get a pop-up box but the superuser manager pass doesn't work. If the superuser password is indeed set up correctly then this is a fault of the user folder. There are some bad implementations out that that do not respect the superuser/emerg

[Zope] major problems placing authentication on an extranet site-security flaw?

2006-02-08 Thread michael nt milne
HiI have major problems here trying to set-up authentication over a whole Plone site using Zope. Using my superuser account I've navigated to the site root page in the ZMI where it lists all the site pages and objects etc. I've then gone into security, scrolled down to the bottom and for the 'View'