Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Password Security Question

Status
Not open for further replies.

Brit

Programmer
May 15, 2001
15
US
I have noticed a number of internet sites have the userid/password login screens on secure (https) pages while some sites have the login on a non-secure page that posts to a secure page. Is there a difference?

Does the browser encrypt all posts to secure pages even if the originating page is not secure?

Any help is appreciated.
 
Although I've never tried it I seem to recall from my IIS training course that credentials for Basic Authentication were encrypted for a Secure web page. Remember though that you cannot use a virtual server with HTTPS - Host Headers are encrypted too and IIS cannot decrypt them to decide which virtual web site to send the page request to.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top