Skip to content. | Skip to navigation

Sections
Personal tools
You are here: Home News & views WebServerAuth 1.1 saves money on SSL certs

Posted Dec 03, 2008

WebServerAuth 1.1 saves money on SSL certs

by Erik Rose

Now you can specify where the login link and challenge handler take you, meaning you don’t need a separate SSL cert for each domain.

WebServerAuth 1.1 saves money on SSL certs

WebServerAuth’s config options, including shiny new custom regexes

Some WebLion Hosting pilot customers need to run several Plone sites, each on its own domain, and log into each. WebServerAuth 1.0 assumed it could just stick "https://" in front of wherever you were and thereby evoke the proper login prompt from the web server, but that gets expensive, since it means buying a separate SSL cert for each domain.

WebServerAuth 1.1 lifts that assumption: now you can go crazy with regexes to make your login links and challenge handler redirections point wherever you like. For example, the login links at fred.psu.edu and matilda.psu.edu could point to https://secure.psu.edu/fred and https://secure.psu.edu/matilda (where the user would remain for the remainder of his logged-in stay), making only one SSL cert to buy. Of course, you could buy a wildcard cert instead, but that doesn’t fly at Penn State for various reasons.

1.1 is an easy upgrade. All your old settings will be preserved, and you don’t even need to reinstall it in the Add-on Products control panel until you need fancy, regex-y login links.

Enjoy! 

Document Actions

How do you handle permissions?

Posted by Anonymous User at Jan 06, 2009 11:04 PM

If this is the wrong place for this question, let me know...it didn't really seem to be appropriate for a ticket, either.

I'm a little fuzzy on how to handle permissions when using WebServerAuth. Since users don't show up in the "Users and Groups" control panel, how does one assign them to groups or roles? The docs don't address that, nor have I been able to find any discussion online covering this topic.

So I've got Authenticated users, and I can go through and update security settings and workflows to grant access to Authenticated users, but that's a lot of work and it doesn't allow me to assign, say, Bob and Alice different levels of access.

Am I just missing something glaringly obvious? Thanks!

Need help now?

Immediate assistance is available during university work hours:

News & views…
Posted Oct 13, 2009 Portlets gone wild with ContentWellPortlets 2.0.1 This new release adds the ability to add portlets to the footer area. It also has 6 portlet managers per area. This means 20 total portlet managers including the 2 on the sides that ship with plone.
Posted Sep 17, 2009 Plone 4 – An interview with Zope News Jan Ulrich Hasecke interviews me for Zope News.
Posted Aug 31, 2009 Web Services API for Plone Alpha 3 Release Details the release of the wsapi4plone.core package and the plans for future releases. The final report of the AtomPub for Plone Google Summer of Code project.
Posted Aug 28, 2009 Content editing and creation in Plone is faster with archetypes.schematuning Some bench marks of content editing and creation in Plone with and without archetypes.schematuning installed.
More news & views…