What are security problems with piggybacking authentication off another site (basic auth)?

I have a WSS installation that's behind basic authentication/SSL (it's hosted at a public web host). I'm creating a sister site in ASP.NET, and am considering just running the credentials through and allowing users to log into the new system providing there is no 401 Not Authorized error returned.

Both are internet-facing applications that will be used by about 20-50 people.

What am I missing? I've never heard of this recommended before, but I don't see why it wouldn't work.

Answers


I can't see any major problems with that - you'll obviously want to make sure both servers are using SSL if you've got to send that over the Internet, but other then that it sounds like an elegant way to share credentials between applications.


Need Your Help

How do I model relative scores between entities in CoreData

objective-c cocoa core-data orm entity-relationship

I am new to CoreData and am struggling to work out the correct way to model a particular relationship. I have an entity called 'Friend' with a few attributes such as 'name', 'age', 'sex' etc.

How to get AdSense on a Google Code project page?

adsense google-code

I must admit that I don't really know if this is the right place to ask this question, however: in your knowledge it possible to have AdSense on a Google Code project page? I have tried searching G...

About UNIX Resources Network

Original, collect and organize Developers related documents, information and materials, contains jQuery, Html, CSS, MySQL, .NET, ASP.NET, SQL, objective-c, iPhone, Ruby on Rails, C, SQL Server, Ruby, Arrays, Regex, ASP.NET MVC, WPF, XML, Ajax, DataBase, and so on.