General discussion on installation and configuration of SOGo

Text archives Help


Re: [SOGo] Secured session cookies


Chronological Thread 
  • From: Ludovic Marcotte < >
  • To:
  • Subject: Re: [SOGo] Secured session cookies
  • Date: Tue, 28 Dec 2010 15:46:14 -0500
  • Organization: Inverse inc.

On 10-12-28 3:42 PM, Jan-Frode Myklebust wrote:
Couldn't this also be the same string as is stored server side for the
secured session cookie, and xor'ed when checking validity ?
Yes but that wouldn't work with other authenticators - like the proxy one (for WebAuth or Apache authentication) or the DAV one (for all DAV clients, like Thunderbird, Apple iCal / iPhone, etc.).

--
Ludovic Marcotte

:: +1.514.755.3630 :: www.inverse.ca
Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence
(www.packetfence.org)




Archive powered by MHonArc 2.6.16.

Top of page