1/2 OT: ASA proxy auth behaviour...

From: Carlos G Mendioroz <tron_at_huapi.ba.ar>
Date: Wed, 15 Apr 2009 09:27:22 -0300

Hi,
I'm unwilling to believe something I have read:
cisco says that if you have basic (i.e. traditional intercept) http
authentication proxy enabled, your credentials are forwarded to
the initial web server you were accessing when the authentication
happens.
If this is http, this in turn goes in cleartext, so it makes a big
security issue.

Now, why would it do that ? I mean, forward the credentials...

Perplexed,
-Carlos

-- 
Carlos G Mendioroz  <tron_at_huapi.ba.ar>  LW7 EQI  Argentina
Blogs and organic groups at http://www.ccie.net
Received on Wed Apr 15 2009 - 09:27:22 ART

This archive was generated by hypermail 2.2.0 : Mon May 04 2009 - 07:39:12 ART