Solved

difference between mod_ssl & mod_digest

Posted on 2002-04-27
7
218 Views
Last Modified: 2012-05-04
if i want to build a "Secure Website",which module should i use, mod_ssl or mod_digest.

as i know,mod_ssl could providing SSL connection through web,but every client should visit it by "https://xxxxxx",
right? if i edit my index.html to REDIRECT the visitor fro
m "http://xxxxx.com" to "https://xxxxx.com",the client sid
e would auto change normal connection to SSL connection ?

And,mod_digest would only encrypt the "stream code" during
the authorization,after succeed,any HTTP request would sti
ll use Normal "clear text" code to communicate,right ?

please answer my questions,it's very important to me,thank
s a lot.
0
Comment
Question by:wingboad
  • 4
  • 2
7 Comments
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6975365
https encryptes the complete stream
0
 
LVL 51

Accepted Solution

by:
ahoffmann earned 50 total points
ID: 6976534
mod_digest simply changes the encryption mode from Basic to Digest for the authorization dialog (where Basic is a weak encryption).
To use Digest authentification, you need to load the module, and then replace AuthType Basic by AuthType Digest in your .htaccess.
Keep in mind that not all browsers support Digest.
SSL is the more reliable and more secure way.
0
 

Author Comment

by:wingboad
ID: 6990747
but if i want our clients to use httpS,how could make them use it "tranparently" ? cause not all clients know to use
https://xxx.xxxx.com to visit those "secure pages".
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 51

Expert Comment

by:ahoffmann
ID: 6991612
assuming you administrate xxx.xxxx.com, either tell the web server to redirect any request to https, or place a index.html in corresponding directories which redirect
0
 

Author Comment

by:wingboad
ID: 6992576
so,after the redirection,all clients' requests would be
httpS automatically,right ?
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6993057
if it is done by the server, yes
0
 
LVL 5

Expert Comment

by:zenlion420
ID: 9709163
Hey people,

No comment has been added in roughly 1 year, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question
be PAQ'd and pts awarded to ahoffman.
Please leave any comments here within the next seven days.

PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!

Zenlion420
EE Page Editor
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now