[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ssl certificate to authenticate users in a web aplication



In <[🔎] AANLkTinj-V5Sp3DwdGXxKuEPbFzpemTkH1GqGwfv+ExJ@mail.gmail.com>, Jesus 
arteche wrote:
>Anyone knows if it's possible to authenticate an user with ...user, pass and
>a personal certificate....I mean, each user has name, pass and a certificate
>to login in aplication.

It certainly is possible.

However, it is non-trivial to convert an application from user/pass to 
user/pass+certificate.

Also, if the method you use to associate a certificate generated by the user 
to a username OR the method you use to transfer a certificate generated by the 
application (or something server-/organization-side) to the user is less 
secure, it may not be worth the trouble.
-- 
Boyd Stephen Smith Jr.                   ,= ,-_-. =.
bss@iguanasuicide.net                   ((_/)o o(\_))
ICQ: 514984 YM/AIM: DaTwinkDaddy         `-'(. .)`-'
http://iguanasuicide.net/                    \_/

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: