[Spacewalk-list] API using hashed SATELLITE_PASSWORD

Grant Gainey ggainey at redhat.com
Thu May 8 22:10:59 UTC 2014


Tangentially, just noticed this:

----- Original Message -----
> SATELLITE_URL = " http://satellite.example.com/rpc/api "

I'm assuming this is just a typo, but just in case - Don't use HTTP to talk over an authenticating link. Anybody with a network sniffer between the client and the SW server can get your login/pwd that way :(  Always use HTTPS.

G




More information about the Spacewalk-list mailing list