User Story #3344 (closed)
Configure clients for certificate authentication
| Reported by: | jburel | Owned by: | |
|---|---|---|---|
| Priority: | minor | Milestone: | Unscheduled |
| Component: | Insight | Keywords: | n.a. |
| Cc: | jamoore | Story Points: | n.a. |
| Sprint: | n.a. | Importance: | n.a. |
| Total Remaining Time: | n.a. | Estimated Remaining Time: | n.a. |
Description
In addition to securing the transport (cf. omero#838), it would be benefitial to allow logging in without a password, and instead use certificates.
This has the added benefit of being able to prevent man-in-the-middle attacks.
See also #1747
Change History (3)
comment:1 Changed 4 years ago by jburel
- Resolution set to fixed
- Status changed from new to closed
comment:2 Changed 4 years ago by jamoore
Just as a note for posterity: cert auth was not added as part of the current work linked here. That will/can take place as a separate body.
comment:3 Changed 4 years ago by jburel
Better to move to card or whatever system we use when the time comes.
But yes only re-use of session has been implemented.
Closing.