mod_ssl with mod_auth

This is a discussion on mod_ssl with mod_auth within the Modssl Users forums, part of the Web Server and Related Forums category; Hi! I've come across the following: 1. Configure Apache (1.3.33 in this case) to listen with SSL ...


Go Back   Usenet Forums > Web Server and Related Forums > Modssl Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-04-2005
Christoph Schindler
 
Posts: n/a
Default mod_ssl with mod_auth

Hi!

I've come across the following:

1. Configure Apache (1.3.33 in this case) to listen with SSL on some
port (say 8100).

2. Protect it with mod_auth.

3. Connect to the port with a Web Browser using http:// (not https://!)
http://ssl.example.com:8100/

You get the following in error.log:

[Fri Jun 3 14:47:46 2005] [error] mod_ssl: SSL handshake failed: HTTP
spoken on HTTPS port; trying to send HTML error page...

What Apache actually sends though, is a "401 Authorization Required", so
you also get the authentication dialog in the web browser.

If you now fill in your Credentials and click the "OK" button your username
and password is sent to the server in the clear.

The problem with this is, that the user has no actual feedback that he
has entered a wrong URL and that the connection to the server is not
actually encrypted.

An immidiate fix is to SSLRequireSSL, which has the problem that the
user does not get the helpful 400 error with the correct link.

(I worked around this by using ErrorDocument to redirect the user
immediatly to the correct URL... ugly hack, I think.)

Is there some (easy) way around this problem that I have not found? Is
this even something mod_ssl can influence or must this be fixed in
mod_auth?

thanks!
Christoph Schindler


__________________________________________________ ____________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List modssl-users@modssl.org
Automated List Manager majordomo@modssl.org
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:06 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0