Re: https-Question



Sherm Pendley <sherm@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> writes:
Wilhelm Kutting <wkutting@xxxxxxxx> writes:
Hello, i got a little understanding Problem.
on some http-Sites i can log into my Account with Name/Passwort.
The Form-Login-Page ist only http with form action directing to a
"secure" https page.
So - in my understanding the username and password is send uncrypted
over the Net.
Only the later Communication is done secure.

Am i right that only a https login-Form-page would be safe?

Whether the form itself was fetched from an http:// or https:// URL is
irrelevant. If the action of the form lists an https:// URL, the data is
encrypted when the form data is sent to that URL.

*However* it's worth having the form in https too, if that's
practical, so that a concerned user can be sure that the form they see
is the form your server sent (assuming they trust your server
certificate).

--
Chris
.



Relevant Pages

  • Re: http to https redirect for OWA
    ... web browser it automatically goes to the secure ... ISA server. ... beacuse I have a Server running Small Business Server ... >| http request to https for the OWA website? ...
    (microsoft.public.isa)
  • Re: SSL Encryption
    ... This question was asked because we're considering a web service scenario. ... consider it secure. ... >>send credentials to the secure server BEFORE the secure channel is there? ... > You're essentially never going to get the chance, if you ask for an HTTPS ...
    (microsoft.public.inetserver.iis.security)
  • Re: How secure is RWW
    ... Going https your browser sends encrypted info over the web...pretty secure. ... more secure connection between client and server than say previous VPN ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA and POP3 question
    ... As secure as a credit card transaction on banking sites. ... > So if I open port 443 for https and allow users to connect to my exchange ... >>> exchange server and allow them to retreive and send email via POP3, ...
    (microsoft.public.windows.server.sbs)
  • Re: Is this REALLY a secure site?
    ... >> How can anyone really know if an SSL or HTTPS connection is truly ... Even if it is theoretically secure ... major credit card company wound up making the authorization against my ... > site uses a numerical IP address: those are always bogus. ...
    (microsoft.public.windowsxp.general)