Astaro Security Gateway Feature Requests Forum

33 votes

proxy authentication SSL-encrypted

Please make the proxy authentication encrypted if the client does not support eDirectory SSO. Actually user and password are sent in human-readable cleartext.

Same thing for the transparent proxy with authentication. The login form is provided via http... Why not https?

  1. Comments
  1. 2

    pimp up the captive portal

  2. 3

    A non-encrypted proxy authentication is clearly unacceptable by any security standard. It looks like the eDirectory SSO could fallback to the transparent proxy auth page, rather than using basic http auth. The proxy auth page also needs to be SSL encypted using a generated cert signed by a client trusted CA.

  3. An alternatice mechanism was the support of digest authentication. Its not as secure as SSL but it is a first step.

  4. 2

    yes we can - encrypt everything

  5. 1

    I'd like it if all HTTP/S proxy traffic were encrypted. It'd be just one more layer of defense for a wireless network.

  6. 3

    Cleartext Password are very secure, isn't it ?
    I wish a https splace screen to auth. proxy.

powered by UserVoice