[Zope] Re: htaccess with zope/plone ?

Robert Boyd robert.h.boyd at gmail.com
Thu Feb 9 10:51:51 EST 2006


On 2/7/06, michael nt milne <michael.milne at gmail.com> wrote:
> Also Zope doesn't do SSL well and all password - login is
> basically insecure!

If you mean that logins without SSL are basically insecure, ok. But
given your other posts, if you mean that Zope authentication is
somehow inherently insecure (other than non-SSL traffic being in the
clear), please consider that the problems you experienced with it
don't lead to that conclusion. I run secured Zope sites on Classified
networks, and wouldn't be able to if Zope security was as broken as
you make it out to be.

If you need Apache auth and then need Plone auth, and you have a
question about configuring Apache auth, then it's appropriate to ask
an Apache list. The Apache httpd docs are also very good.


More information about the Zope mailing list