Unencrypted login to BlogEngine.Net

by Chris 11/28/2007 4:34:00 AM

I noticed that after installing BlogEngine.Net I was able to login to manage the services.  I also noticed that I was doing this using HTTP instead of HTTPS.  This may be fine if I am sitting on the server running the service but it is definitely not how I want to connect when I am sitting in my office...  I get the impression that many people don't want to deal with SSL and figure what the heck, it's only my blog. 

But interestingly enough I believe many people use the same password for most of their logins.  So I would recommend that you seriously consider using SSL when logging into BlogEngine.Net.   If you are hosting your own blog service than you have a couple of options:

  • » Use a self-signed certificate (selfssl.exe found in the Windows IIS Resource Kit)
  • » Purchase a very expensive certificate from someone like Verisign
  • » Get a free certificate from StartSSL

If you are not hosting your own blog service than you might want to check with your provider for their SSL offerings. 

Another thing worth mentioning is how you would control the switch from HTTP to HTTPS to HTTP when you are logging into your blog.  I use Sanibel Logic's SSLRedirect to handle this task and it works perfectly.

Cheers!

Add comment


(Will show your Gravatar icon)  

  Country flag

biuquote
Loading



Powered by BlogEngine.NET Theme by Mads Kristensen Hosted by 1and1 Hosting Sign in
The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way. © 2008 Chris Blankenship

Welcome to my blog

Welcome to my site

Villainy wears many masks,
none of which so dangerous as virtue…



Subscribe to comments feed Recent comments exp/col

View Chris Blankenship's profile on LinkedIn   DSCODUC on Technorati

check out my neighbors in meatspace  

Stop Spam Harvesters, Join Project Honey Pot   This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License