<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with authentication</title>
      <link>http://ask.metafilter.com/tags/authentication</link>
      <description>Questions tagged with 'authentication' at Ask MetaFilter.</description>
	  <pubDate>Sun, 30 Aug 2009 15:33:06 -0800</pubDate> <lastBuildDate>Sun, 30 Aug 2009 15:33:06 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>iPhone RSS reader that supports SSL and authentication?</title>
	<link>http://ask.metafilter.com/131505/iPhone%2DRSS%2Dreader%2Dthat%2Dsupports%2DSSL%2Dand%2Dauthentication</link>	
	<description>Anyone know of an RSS reader for iPhone that supports SSL and authentication, and does NOT use an online aggregator? I need an iPhone RSS reader that will handle SSL and authenticated feeds, but it can&apos;t use an aggregator (the feed credentials must stay on the iPhone).  I&apos;ve been searching for a while and haven&apos;t come up with anything.  Anyone come across such an application?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.131505</guid>
	<pubDate>Sun, 30 Aug 2009 15:33:06 -0800</pubDate>
	<category>authentication</category>
	<category>iphone</category>
	<category>rss</category>
	<category>ssl</category>
	<dc:creator>aberrant</dc:creator>
	</item>
	<item>
	<title>I don&apos;t want to Twitter, you twat</title>
	<link>http://ask.metafilter.com/127246/I%2Ddont%2Dwant%2Dto%2DTwitter%2Dyou%2Dtwat</link>	
	<description>Doesn&apos;t Twitter authenticate email addresses when people sign up for new accounts? I was away from my computer for a while today, and when I came back to my email, someone had created a Twitter account using MY email address and started adding/receiving contacts (followers, whatever).  &lt;br&gt;
&lt;br&gt;
I reset the password and then deleted the account.  Moments later I got a request to restore the account.&lt;br&gt;
&lt;br&gt;
So Twitter, one of the most popular sites on the whole interwebs (but of which I am NOT a member), really lets people just sign up any email address and start posting immediately without verification of that email address?  Doesn&apos;t that seem... I don&apos;t know... like a terrible idea?  &lt;br&gt;
&lt;br&gt;
Has anyone else ever dealt with this?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.127246</guid>
	<pubDate>Sun, 12 Jul 2009 17:42:34 -0800</pubDate>
	<category>authentication</category>
	<category>email</category>
	<category>resolved</category>
	<category>twitter</category>
	<dc:creator>educatedslacker</dc:creator>
	</item>
	<item>
	<title>SSL Client Certificates</title>
	<link>http://ask.metafilter.com/122192/SSL%2DClient%2DCertificates</link>	
	<description>Please help a noob with client-side SSL certificates. What is the process for generating SSL client certs? What kind of information is needed? Who generates them? I have a web server SSL cert installed (IIS), when users try to connect they are prompted to choose their client certificate from a list. (This is the behavior I want). The web server SSL certificate was issued by Entrust.net</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.122192</guid>
	<pubDate>Fri, 15 May 2009 08:45:51 -0800</pubDate>
	<category>authentication</category>
	<category>certificates</category>
	<category>SSL</category>
	<category>webserver</category>
	<dc:creator>banshee</dc:creator>
	</item>
	<item>
	<title>WordPress 2.7 and Angsuman&#8217;s Authenticated WordPress Plugin</title>
	<link>http://ask.metafilter.com/109416/WordPress%2D27%2Dand%2DAngsumans%2DAuthenticated%2DWordPress%2DPlugin</link>	
	<description>On one of my WordPress hosted blogs, I previously used Angsuman&#8217;s Authenticated WordPress Plugin to restrict access to registered users. After upgrading to WordPress 2.7, the plugin doesn&apos;t work anymore. It won&apos;t let anybody log in, trapping people in a constant loop of entering (correct) passwords and being returned to the login screen. Does anybody know:&lt;br&gt;&lt;br&gt;

(a) how to alter the plugin so it works with 2.7. I don&apos;t want to shell out US$30 for &apos;Authenticator Plugin Pro&apos; when only about ten people access the site in question.&lt;br&gt;&lt;br&gt;

(b) of another plugin that does the same thing - blocks off a WordPress site to everyone other than registered users with passwords.&lt;br&gt;&lt;br&gt;

Many thanks.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.109416</guid>
	<pubDate>Tue, 16 Dec 2008 20:10:15 -0800</pubDate>
	<category>27</category>
	<category>authentication</category>
	<category>plugin</category>
	<category>wordpress</category>
	<dc:creator>sindark</dc:creator>
	</item>
	<item>
	<title>What do i do with all these RSA tokens?</title>
	<link>http://ask.metafilter.com/109282/What%2Ddo%2Di%2Ddo%2Dwith%2Dall%2Dthese%2DRSA%2Dtokens</link>	
	<description>I just had a bunch of RSA tokens land in my lap.
What&apos;s required on the other end of an RSA authentication scheme, and what&apos;s a good resource for learning what&apos;s necessary to implement it? So we got a mess of these IronKey secure flash drives.&lt;br&gt;
&lt;br&gt;
They came with an add-on I hadn&apos;t expected - each one has an RSA token generator (software, not hardware) included.&lt;br&gt;
&lt;br&gt;
I&apos;d like to roll them into our system, especially to harden access for a Terminal Server. (It&apos;s an all-Windows shop.)&lt;br&gt;
&lt;br&gt;
But where to get started?  New to me, and I&apos;m looking for information about what&apos;s involved in implementation, with a focus on doing it yourself or on the cheap.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.109282</guid>
	<pubDate>Mon, 15 Dec 2008 12:31:24 -0800</pubDate>
	<category>authentication</category>
	<category>RSA</category>
	<category>security</category>
	<category>token</category>
	<dc:creator>bartleby</dc:creator>
	</item>
	<item>
	<title>Authenticate with one domain, authorize with another.</title>
	<link>http://ask.metafilter.com/107129/Authenticate%2Dwith%2Done%2Ddomain%2Dauthorize%2Dwith%2Danother</link>	
	<description>In Active Directory, is it possible to direct the act of authenticating a user to one domain, but the subsequent authorization of that user to be handled by another? Situation: For &lt;strong&gt;political, non-technical, and unchangable reasons&lt;/strong&gt;, the users in our domain (Domain A), must now instead authenticate against Domain B. They are not in a forest together. &lt;br&gt;
&lt;br&gt;
We retain control of the machines in Domain A.   Domain A will still be used for management of machines, and possibly for authorization if we can find a way to pull it off.  &lt;br&gt;
&lt;br&gt;
Domain B will contain the users, just a giant mass of identities not separated into OUs.  We will have no ability to put these users into groups or otherwise administer to Domain B.  Account provisioning, some very light information, and password management is handled via Domain B.&lt;br&gt;
&lt;br&gt;
Due to a number of vendor issues, we must put all of our users in a single domain (many of these particular applications can only look at one domain for authentication).  Therefore, these users go into Domain B.  You know, the domain without OUs or groups we can touch.&lt;br&gt;
&lt;br&gt;
This means that in our area, our machines will be in Domain A, but the users will be logging in to the machine using Domain B.&lt;br&gt;
&lt;br&gt;
Problem #1: We won&apos;t be able to put users into groups within Domain B, but almost all of the security in our various applications depends on group assignments.  If we could separate authentication from authorization, users could log on to Domain B, but determining what groups, etc., could come from Domain A.&lt;br&gt;
&lt;br&gt;
Problem #2: Domain B &lt;strong&gt;will not support&lt;/strong&gt; roaming profiles, but a subset of our users (in a group in Domain A, not an OU, but that could change) need roaming profiles. We want to give users roaming profiles when they&apos;re logged onto our machines. Ideally, we&apos;d like to be able to work it such that the roaming profiles are only triggered for the aforementioned group, perhaps pulling said profiles from Domain A.&lt;br&gt;
&lt;br&gt;
Problem #1 is more important that Problem #2.  I&apos;m at a loss as to where to start with this, as I&apos;m not really an Active Directory person, aside from the ability to manipulate it programmatically.  Yes, I am aware that this scenario does not seem like a particularly great idea on the face of it.  I&apos;m just looking for technical solutions to what appears to be a technical problem generated by political issues.&lt;br&gt;
&lt;br&gt;
Avenues Already Explored: &lt;br&gt;
* Active Directory Federated Services isn&apos;t appropriate, as it is web-only.  &lt;br&gt;
* Dual sets of accounts could almost work, except for Domain B controlling the passwords.&lt;br&gt;
* Dropping my jaw and blinking cluelessly has also not been effective.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.107129</guid>
	<pubDate>Tue, 18 Nov 2008 07:19:51 -0800</pubDate>
	<category>activedirectory</category>
	<category>authentication</category>
	<category>authorization</category>
	<dc:creator>adipocere</dc:creator>
	</item>
	<item>
	<title>What&apos;s the best practice for authenticating Google&apos;s crawlers?</title>
	<link>http://ask.metafilter.com/101928/Whats%2Dthe%2Dbest%2Dpractice%2Dfor%2Dauthenticating%2DGoogles%2Dcrawlers</link>	
	<description>I manage a website.  Some content requires authentication by password or IP.  I want Google to crawl that content but not cache it, so that Google users can find it in searches but can&apos;t access it without authentication.  What&apos;s the best way to do this?

In 2006 Matt Cutts &lt;a href=&quot;http://googlewebmastercentral.blogspot.com/2006/09/how-to-verify-googlebot.html&quot;&gt;recommended&lt;/a&gt; doing a reverse DNS lookup to verify that a bot&apos;s name is in the googlebot.com domain, and then a forward DNS-&amp;gt;IP lookup using that googlebot.com name (to thwart spoofers).

Is that still the best solution? How do other people manage this?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.101928</guid>
	<pubDate>Wed, 17 Sep 2008 10:27:47 -0800</pubDate>
	<category>authentication</category>
	<category>Google</category>
	<category>Googlebot</category>
	<dc:creator>futility closet</dc:creator>
	</item>
	<item>
	<title>Can I combine htaccess and session variables from other systems?</title>
	<link>http://ask.metafilter.com/97321/Can%2DI%2Dcombine%2Dhtaccess%2Dand%2Dsession%2Dvariables%2Dfrom%2Dother%2Dsystems</link>	
	<description>Web server question. Can I combine htaccess and session variables from other systems? (more inside) OK, bear with me here--I&apos;m a page developer, not a server admin. I&apos;ve got an apache system that uses htaccess and a .db file to grant access to particular directories. I&apos;ve also got a set of users who aren&apos;t in the .db file, but will be logging in to another system (salesforce.com) and trying to access those restricted areas. Is there a way to allow the first set of users to continue logging in as always, but to allow a session variable that is established on the salesforce.com site to be passed, allowing this second set of users to access the area without having to log in again?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.97321</guid>
	<pubDate>Wed, 23 Jul 2008 10:03:34 -0800</pubDate>
	<category>apache</category>
	<category>authentication</category>
	<category>htaccess</category>
	<category>server</category>
	<category>session</category>
	<category>variables</category>
	<category>web</category>
	<dc:creator>jpoulos</dc:creator>
	</item>
	<item>
	<title>How do I access the internet through an ISA Server proxy?</title>
	<link>http://ask.metafilter.com/94503/How%2Ddo%2DI%2Daccess%2Dthe%2Dinternet%2Dthrough%2Dan%2DISA%2DServer%2Dproxy</link>	
	<description>I have an application installed on my PC at work that needs to connect to the internet through our ISA Server. The problem it has is that it can&apos;t connect directly unless I put in proxy settings. The problem that I have is that the proxy setting is just one long URL with no username or password. How can I get this application to connect? Whenever I connect to the internet with a browser (IE and Firefox) on the work computer (Windows XP) I need to use &lt;b&gt;http://isa.uk.mycompany.com:8080/array.dll?Get.Routing.Script&lt;/b&gt; as the automatic proxy configuration URL in the preferences otherwise it refuses to connect.&lt;br&gt;
&lt;br&gt;
The application I want to connect to the internet uses HTTP and gives me three options for the proxy: &quot;use default&quot;, &quot;direct&quot; and &quot;named proxy&quot;. &quot;Use default&quot; and &quot;direct&quot; don&apos;t work.&lt;br&gt;
&lt;br&gt;
&quot;Named proxy&quot; requires me to enter a proxy server, username and password. I&apos;m guessing that my windows username and password would be for the latter two, but I have no idea what to put for the proxy server.&lt;br&gt;
&lt;br&gt;
I&apos;ve tried putting the long URL in, but that doesn&apos;t work. The problem appears to be that it is expecting a server name, not a port number and certainly not a path to a script.&lt;br&gt;
&lt;br&gt;
I tried pasting the URL into a browser and it downloaded what looked to be about 300 lines of VB Script. There was nothing in there that gave me much of a clue on what I should use. I also tried running the VB script from the command line but nothing was outputted.&lt;br&gt;
&lt;br&gt;
Can anyone offer any insights into what I need to do to work out what the proxy server name would be? Failing that, what else can I do?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.94503</guid>
	<pubDate>Thu, 19 Jun 2008 11:15:31 -0800</pubDate>
	<category>application</category>
	<category>authentication</category>
	<category>isa</category>
	<category>proxy</category>
	<category>server</category>
	<category>windows</category>
	<dc:creator>mr_silver</dc:creator>
	</item>
	<item>
	<title>Is more simple bank web security better?</title>
	<link>http://ask.metafilter.com/93389/Is%2Dmore%2Dsimple%2Dbank%2Dweb%2Dsecurity%2Dbetter</link>	
	<description>I have noticed that there seems to be a split between some banks/financial institutions who maintain  complex security around their on-line account access and others who seem to have actively migrated towards a much simpler approach. Is there any evidence that the &quot;simple&quot; approach is either more or less secure than the &quot;complex&quot; one? By &quot;complex&quot; I am talking about institutions that ask their users to memorise several passwords and then ask for one or two of these at random on login. There is also a likelihood that use might be tied to a particular PC with a physical token or a cookie. An additional one-time access code may be required. By &quot;simple&quot; I am talking about cases where users are asked something like &quot;enter characters x, y and z from your password&quot; - and perhaps for one other fixed detail. Users are also able to log in from pretty much any PC they choose.&lt;br&gt;
&lt;br&gt;
My guess is that the latter group has lower support costs and less frustrated users. But are there real world difference in the security levels?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.93389</guid>
	<pubDate>Fri, 06 Jun 2008 06:22:15 -0800</pubDate>
	<category>authentication</category>
	<category>bank</category>
	<category>login</category>
	<category>password</category>
	<category>security</category>
	<category>usability</category>
	<dc:creator>rongorongo</dc:creator>
	</item>
	<item>
	<title>How do you set up pub key auth for Dreamweaver&apos;s sftp client on a windows box?</title>
	<link>http://ask.metafilter.com/81846/How%2Ddo%2Dyou%2Dset%2Dup%2Dpub%2Dkey%2Dauth%2Dfor%2DDreamweavers%2Dsftp%2Dclient%2Don%2Da%2Dwindows%2Dbox</link>	
	<description>How do you set up pub key auth for Dreamweaver&apos;s sftp client on a windows box? I have clients who want to connect to a unix webserver, that is running openssh, from Dreamweaver&apos;s sftp client on a windows box using only public key authentication.  Is this possible using Dreamweaver&apos;s internal sftp client?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.81846</guid>
	<pubDate>Thu, 24 Jan 2008 09:27:28 -0800</pubDate>
	<category>auth</category>
	<category>authentication</category>
	<category>dreamweaver</category>
	<category>key</category>
	<category>openssh</category>
	<category>pubkey</category>
	<category>public</category>
	<category>sftp</category>
	<dc:creator>jj27</dc:creator>
	</item>
	<item>
	<title>Authentication across Windows, Linux, and Mac</title>
	<link>http://ask.metafilter.com/80734/Authentication%2Dacross%2DWindows%2DLinux%2Dand%2DMac</link>	
	<description>How do you use a single authentication system for different kind of servers, systems, and workstations? We&apos;re a small Web development business of less than 20 employees. Currently, we have three local servers:&lt;br&gt;
&lt;br&gt;
Server A, using Windows Server 2003, is the &quot;main&quot; server for putting all of our document (including financial data) and most of our projects. For development and testing, we also host Web sites there which require a Windows server, ASP and MS SQL. It&apos;s also our main DHCP and DNS server.&lt;br&gt;
&lt;br&gt;
Server B, Fedora Core 6, is mainly for hosting projects requiring Linux, PHP or ColdFusion, and MySQL. It&apos;s the backup DHCP and DNS server.&lt;br&gt;
&lt;br&gt;
Server C, Windows Sever 2003 Web Edition, is for hosting projects requiring ColdFusion and Windows.&lt;br&gt;
&lt;br&gt;
We have various kinds of workstations at the office: Windows XP, Windows Vista, Ubuntu, Fedora, and Mac OS X 10.4.&lt;br&gt;
&lt;br&gt;
Our biggest annoyance at the moment is authentication. Every employee has a different account for everything. Windows file shares, Linux file shares, Linux shell accounts, MySQL, MS SQL...&lt;br&gt;
&lt;br&gt;
Server A already has Active Directory set up, though I&apos;m not too familiar with it. (I&apos;m more of a Linux system administrator.) I tried some ways to combine all one employee&apos;s accounts together, but it just won&apos;t work. One of the ways I tried was to set up PAM on server B to use LDAP or other mechanisms supposedly supported by the server A, but it doesn&apos;t work.&lt;br&gt;
&lt;br&gt;
Now, I&apos;m wondering, are there any methods to make the authentication process of every service work together?&lt;br&gt;
&lt;br&gt;
I&apos;m not even sure where to start to set this all up. Any suggestions will be appreciated! Thanks in advance!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.80734</guid>
	<pubDate>Fri, 11 Jan 2008 06:22:57 -0800</pubDate>
	<category>authentication</category>
	<category>linux</category>
	<category>mac</category>
	<category>mssql</category>
	<category>mysql</category>
	<category>server</category>
	<category>windows</category>
	<category>workstation</category>
	<dc:creator>remi</dc:creator>
	</item>
	<item>
	<title>RADIUS without realms?</title>
	<link>http://ask.metafilter.com/76242/RADIUS%2Dwithout%2Drealms</link>	
	<description>RADIUS without realms? I have been searching for a solution to this, to no avail. We are using RADIUS to authenticate users for network access using login name/password and @realm.&lt;br&gt;
&lt;br&gt;
I would like to do away from the @realm completely, however we use two different RADIUS servers. Which server a user authenticate is currently determined by a RADIUS proxy server using the users @realm.&lt;br&gt;
&lt;br&gt;
Is there a way to forward RADIUS requests to the appropriate RADIUS server based on the client IP address?&lt;br&gt;
&lt;br&gt;
Or is there a way for a RADIUS proxy to query one server, and not getting a positive response, then query the other server?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.76242</guid>
	<pubDate>Wed, 14 Nov 2007 09:15:04 -0800</pubDate>
	<category>authentication</category>
	<category>authorization</category>
	<category>networking</category>
	<category>radius</category>
	<dc:creator>doomtop</dc:creator>
	</item>
	<item>
	<title>Smart Cards for Windows Login?</title>
	<link>http://ask.metafilter.com/72085/Smart%2DCards%2Dfor%2DWindows%2DLogin</link>	
	<description>Help me figure out Smart Cards! I work for the IT department of a company looking to use smart cards for Windows domain login. Windows (XP/2003) has built-in support for several brands of smart card.  Great, it should be easy! It&apos;s not. It&apos;s taken me three days just to find some cards that are both still manufactured, and still supported in Windows. These are the Gemalto (aka Axalto aka Gemplus aka Schlumberger) Cryptoflex for Windows XP, and the Gemalto Cryptoflex .Net.  But the former isn&apos;t supported in Vista (and besides, I can only find &lt;i&gt;one&lt;/i&gt; website that sells them anymore, aside from the manufacturer). And the .Net cards are $40 each (the other&apos;s $15)!&lt;br&gt;
&lt;br&gt;
On top of this, I&apos;m finding it frustratingly difficult to find a USB reader that is both verifiably Plug &amp;amp; Play (I &lt;i&gt;really&lt;/i&gt; don&apos;t want to install drivers if I don&apos;t have to), &lt;i&gt;and&lt;/i&gt; is not being sold through a very shady-looking website.&lt;br&gt;
&lt;br&gt;
Why is this so difficult? Surely other businesses are using smart cards for login, and not everyone is paying hundreds of dollars per seat for an Enterprise Solution when Windows has built-in support? Or does the built-in support suck so much that an Enterprise Solution is the only realistic option? And if that&apos;s the case, well...what&apos;s good?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.72085</guid>
	<pubDate>Fri, 21 Sep 2007 09:00:22 -0800</pubDate>
	<category>authentication</category>
	<category>smartcard</category>
	<category>twofactor</category>
	<dc:creator>CrayDrygu</dc:creator>
	</item>
	<item>
	<title>Livejournal authenticated RSS problem</title>
	<link>http://ask.metafilter.com/68603/Livejournal%2Dauthenticated%2DRSS%2Dproblem</link>	
	<description>Livejournal authenticated RSS feeds on Mac OS 10.4.10: why do they keep losing my credentials?  May involve Keychain.
I have several friends on livejournal who I&apos;d like to read, along with all of my other feeds, using an RSS reader.  Subscribing to their friends-only feeds is easy enough, the URL is just http://username.livejournal.com/data/rss?auth=digest.  When I add this feed, the RSS reader prompts for my livejournal userid and password on the first refresh of the feed.  At this point, the credentials are stored in my keychain and the newsreader should access it whenever it refreshes the feed.  However, usually after a couple of days, the credentials are lost, and the RSS reader prompts for the username and password again.  This is really irritating since it does this for half a dozen feeds.  Some specifics:&lt;ul&gt;&lt;br&gt;
&lt;li&gt;I don&apos;t have any other authenticated feeds, so I don&apos;t know if this is livejournal-specific or a more general problem.&lt;br&gt;
&lt;li&gt;I have tried three newsreaders: Shrook, Vienna, and NetNewswire Lite.  They all have the same problem.&lt;br&gt;
&lt;li&gt;At least with NNWL, I know that the credentials are stored in my keychain as an internet login (one for each feed).  When I first authenticate, I can check in Keychain Access to see if the login is stored there, and indeed it is.  When NNWL starts prompting me again, I look in Keychain Access again and the login is GONE!  Why would that happen?  No other credentials are lost from my Keychain, and when I run Keychain First Aid, it reports no problems.&lt;br&gt;
&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/ul&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.68603</guid>
	<pubDate>Sun, 05 Aug 2007 11:57:21 -0800</pubDate>
	<category>authentication</category>
	<category>livejournal</category>
	<category>NetNewsWire_Lite</category>
	<category>RSS</category>
	<category>Shrook</category>
	<category>Vienna</category>
	<dc:creator>alopez</dc:creator>
	</item>
	<item>
	<title>Please, please tell me YAAL.</title>
	<link>http://ask.metafilter.com/67958/Please%2Dplease%2Dtell%2Dme%2DYAAL</link>	
	<description>I have a question about the authentication of a Cambridge University-issued document by a California lawyer or notary for use in Latvia. I am moving to Latvia at the end of August to teach English.  My teaching certificate, the CELTA, was issued by Cambridge University in England a few years ago.  Upon being hired by the school in Latvia, its director sent me an email saying &quot;it would be useful if you could start looking into the process of getting your CELTA accredited by a notary or lawyer and either sending it to us or bringing it with you.&quot;&lt;br&gt;
&lt;br&gt;
I&apos;m rather confused as to how to go about this, as the school&apos;s director is British, and I know that notaries in Britain have totally different powers to those in the States - hence his &quot;or&quot; with &quot;notary or lawyer&quot;; presumably he thinks they&apos;re similar.  Now, Cambridge offers a service where I pay them some amount of money, and they authenticate my results and send that to me or to the school, but I don&apos;t know if that will be the same, legally, as getting something official, if that&apos;s even possible here.  I&apos;ve seen references to apostilles, but only in reference to public documents like birth and death certificates, not academic results, let alone those issued abroad.&lt;br&gt;
&lt;br&gt;
I would ask the director to clarify, but he&apos;s on vacation and basically unreachable until a few weeks before I get there, and if I choose to go with the Cambridge certification of my results, I&apos;d need to allow enough time for it to get here so I can present it to an immigration officer or something should I be asked to do so.&lt;br&gt;
&lt;br&gt;
I also realize there are probably very few MeFites who&apos;ve ever had anything to do with Latvia, so my main question is: how can I prove the authenticity of a document issued in another country in a way that will satisfy officials somewhere else?  Or might this be a two-step process - first getting the certification from Cambridge sent to me, and then having a notary or lawyer in Britain (where I could theoretically stop en route to Latvia) accredit the certification?&lt;br&gt;
&lt;br&gt;
Thanks for your help, if anyone dares to respond to such a bizarrely technical question.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.67958</guid>
	<pubDate>Fri, 27 Jul 2007 13:20:47 -0800</pubDate>
	<category>authentication</category>
	<category>california</category>
	<category>cambridge</category>
	<category>CELTA</category>
	<category>document</category>
	<category>latvia</category>
	<category>law</category>
	<category>lawyer</category>
	<category>notary</category>
	<category>regulations</category>
	<dc:creator>mdonley</dc:creator>
	</item>
	<item>
	<title>What&apos;s the Secret Password?</title>
	<link>http://ask.metafilter.com/61507/Whats%2Dthe%2DSecret%2DPassword</link>	
	<description>How exactly does authentication work in a website like &lt;a href=&apos;http://www.basecamphq.com&apos;&gt;Basecamp&lt;/a&gt;, or more generally, a site built on Rails or LAMP.  When I sign-up, I enter a username and password.  I presume this is stored in a database table.  But after that, how does the server know who I am during the course of my &apos;visits&apos; and how does the SQL database know what I have access to ( only my projects ) and what I don&apos;t have access to ( Other peoples projects)?  Where do cookies, if at all, come into play.  If cookies do come into play, can they not simply be forged?  I am completely clueless regarding the subtleties of authentication, user sessions, and security.   Please enlighten me.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.61507</guid>
	<pubDate>Fri, 27 Apr 2007 16:51:36 -0800</pubDate>
	<category>authentication</category>
	<category>identity</category>
	<dc:creator>kaizen</dc:creator>
	</item>
	<item>
	<title>How do you access MS Access in a different domain?</title>
	<link>http://ask.metafilter.com/58765/How%2Ddo%2Dyou%2Daccess%2DMS%2DAccess%2Din%2Da%2Ddifferent%2Ddomain</link>	
	<description>I&apos;m trying to get my head around some Microsoft Access security issues, and could use some help. My company has a website (on IIS6). A portion of that website (written in ASP), pulls data from a Microsoft Access database, located on the same server.&lt;br&gt;
&lt;br&gt;
The ASP web site is now moving to a data centre, to a server in a different Active Directory domain (no trust yet exists between the two domains), but the Access database has to stay where it is (other applications reference it).&lt;br&gt;
&lt;br&gt;
Previously, the &quot;anonymous access&quot; internet account had permission to read/write to the Microsoft Access database. But now the &quot;anonymous access&quot; account is in a different AD domain, and as such can&apos;t be granted read/write access to the Access file (unless I&apos;m very much mistaken).&lt;br&gt;
&lt;br&gt;
So, my question is - what is the quickest/simplest way to grant the ASP application access to the Microsoft Access file? Is there someway I can specify the Active Directory account to authenticate as in the connection string or something?&lt;br&gt;
&lt;br&gt;
Thanks.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.58765</guid>
	<pubDate>Thu, 15 Mar 2007 07:50:17 -0800</pubDate>
	<category>Access</category>
	<category>authentication</category>
	<category>Microsoft</category>
	<category>security</category>
	<dc:creator>chill</dc:creator>
	</item>
	<item>
	<title>How is Google giving me access to this page?</title>
	<link>http://ask.metafilter.com/53894/How%2Dis%2DGoogle%2Dgiving%2Dme%2Daccess%2Dto%2Dthis%2Dpage</link>	
	<description>How come if I &lt;a href=&quot;http://www.google.com/search?q=%22The+Human+Rights+Watch+report+was+intended+as+a+shot+across+the+bow+%22&amp;sourceid=mozilla-search&amp;start=0&amp;start=0&amp;ie=utf-8&amp;oe=utf-8&quot;&gt;search for this page and click on the Google link&lt;/a&gt; I get to the page, but if I copy the link that Google gives me and try to &lt;a href=&quot;http://www.stratfor.com/products/premium/read_article.php?id=282226&quot;&gt;access it directly&lt;/a&gt;, I&apos;m taken to a login page? What I really want is to be able to e-mail this link to people, or include it in a fpp on the blue.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.53894</guid>
	<pubDate>Wed, 27 Dec 2006 14:29:00 -0800</pubDate>
	<category>authentication</category>
	<category>google</category>
	<category>security</category>
	<category>web</category>
	<dc:creator>alms</dc:creator>
	</item>
	<item>
	<title>Why a two-step login?</title>
	<link>http://ask.metafilter.com/44846/Why%2Da%2Dtwostep%2Dlogin</link>	
	<description>Why are many financial institutions moving to a two-step login process, where you enter your username on one page and then your password on the next?  For instance, &lt;a href=&quot;https://flagship2.vanguard.com/VGApp/hnw/HomepageOverview&quot;&gt;Vanguard&lt;/a&gt; and &lt;a href=&quot;https://secure.ingdirect.com/myaccount/InitialINGDirect.html?command=displayLogin&amp;device=web&amp;locale=en_US&amp;userType=Client&quot;&gt;ING&lt;/a&gt;.  Their rationale is just that it&apos;s &quot;more secure&quot;, but that&apos;s not much of a reason.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.44846</guid>
	<pubDate>Sun, 20 Aug 2006 09:15:51 -0800</pubDate>
	<category>authentication</category>
	<category>bank</category>
	<category>ing</category>
	<category>login</category>
	<category>password</category>
	<category>security</category>
	<category>username</category>
	<category>vanguard</category>
	<dc:creator>smackfu</dc:creator>
	</item>
	<item>
	<title>Salvador Dali Paintings Authentic?</title>
	<link>http://ask.metafilter.com/36779/Salvador%2DDali%2DPaintings%2DAuthentic</link>	
	<description>I have two paintings signed by Salvador Dali I am in the process in having them authenticated as legit or copies. To possibly save some resources I would like to do background on the paintings, but I am unable to find any information, any suggestions? Recently I found these two paintings that belong to an older family member.  They are both signed by &#8220;Salvador Dali&#8221; and have the representation of his surrealism work.  I know enough about Dali and art to know that there have been many fakes produced for this artist.  However, these paintings are signed and dated, have physical texture, and they are on canvas, I would believe to be hard to reproduce in a copy.&lt;br&gt;
I am unable to read the date as the frame covers most of it, because I am not an expert I do not feel comfortable removing the frame.&lt;br&gt;
Both paintings are also signed &#8220;Orican&#8221;, I have tried searching for these word but was unable to find any reference or information.&lt;br&gt;
Mostly the likeness of the paintings is all I have to search on.&lt;br&gt;
Before I spend the time and resources to have it shipped to a curator and/or authenticator I would like to do some preliminary research to see if I can&#8217;t find more information.&lt;br&gt;
&lt;br&gt;
If anyone has any suggestions of sites, easily accessible reading material, or even has knowledge, I would greatly appreciate it!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.36779</guid>
	<pubDate>Fri, 21 Apr 2006 12:52:06 -0800</pubDate>
	<category>Art</category>
	<category>Authentication</category>
	<category>Copy</category>
	<category>Dali</category>
	<category>Painting</category>
	<dc:creator>lutzla23</dc:creator>
	</item>
	<item>
	<title>PHP Security</title>
	<link>http://ask.metafilter.com/35429/PHP%2DSecurity</link>	
	<description>I&#8217;m working on a PHP/MySQL app and would like to ensure my security is up to scratch &#8211; need tips on authentication, globals and input sanitization. My current method of authenticating users is a simple MySQL username/password lookup, then storing their state with a session and a required cookie (which stores only the session id). To prevent fixation I am using session_regenerate_id whenever necessary. Am I missing anything?&lt;br&gt;
&lt;br&gt;
Register globals is on by default. I am not using globals, and I am trying to define all variables before use. Am I safe? Can global hacks affect my sessions?&lt;br&gt;
&lt;br&gt;
My current method of input sanitization is:&lt;br&gt;
&lt;br&gt;
1.	strip &lt; ,&gt;, &#8216;\r&#8217; and &#8216;\n&#8217; to prevent scripting attacks&lt;br&gt;
2.	convert everything to entities&lt;br&gt;
3.	escape anything left with mySQL_real_escape&lt;br&gt;
&lt;br&gt;
Is this sufficient to protect against any/all injection/xss attacks?&lt;br&gt;
&lt;br&gt;
PHP Security is giving me a big headache, and I keep feeling like I&#8217;m missing something important. Any tips, corrections, best practices or links would be very much appreciated.&lt;/&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.35429</guid>
	<pubDate>Thu, 30 Mar 2006 23:36:28 -0800</pubDate>
	<category>authentication</category>
	<category>injection</category>
	<category>php</category>
	<category>sanitization</category>
	<category>security</category>
	<dc:creator>MetaMonkey</dc:creator>
	</item>
	<item>
	<title>Permissions in PHP webapps without headaches?</title>
	<link>http://ask.metafilter.com/33852/Permissions%2Din%2DPHP%2Dwebapps%2Dwithout%2Dheadaches</link>	
	<description>Best practices for managing massive permission systems for a giant home-brewed PHP CMS? I&apos;m in a job that has a web CMS with a frontend and backend that has grown up over the years. User permissions are currently done with a mostly randomly assigned number on a one-to-one with username that relates back to a set of permissions. &lt;br&gt;
&lt;br&gt;
I&apos;d like to move to something that&apos;s a lot more customizeable, and doesn&apos;t force us to grant such large swaths of permissions. &lt;br&gt;
&lt;br&gt;
However, there&apos;s literally going to be 400 permissions for the site due to the need to extensively silo content. Is there an easier way to set things up? What best practices have been found in other situations for applications this large, and has anything been written about retrofitting this kind of functionality into an existing large application?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.33852</guid>
	<pubDate>Mon, 06 Mar 2006 15:03:23 -0800</pubDate>
	<category>authentication</category>
	<category>permissions</category>
	<category>php</category>
	<category>webapplication</category>
	<dc:creator>SpecialK</dc:creator>
	</item>
	<item>
	<title>Captive Portal with auth - help?</title>
	<link>http://ask.metafilter.com/24390/Captive%2DPortal%2Dwith%2Dauth%2Dhelp</link>	
	<description>Captive Portals. I&apos;d like one. I want it to work with a WRT54G, connected to a DSL line. I&apos;d like a login screen that looks up an auth database (probably RADIUS, but not definite) and I would like the whole auth infrastructure to be centralised, so I don&apos;t need anything but the wireless router on the end of the DSL line. I want to have multiple DSL lines sharing the auth infratructure. I want to control access, so only users with existing credentials gain access (not anyone like wifidog).&lt;br&gt;
Cheap or free is good.&lt;br&gt;
I&apos;m not the brains of the operation, but I think I can understand the answers, any recommendations?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.24390</guid>
	<pubDate>Thu, 22 Sep 2005 05:26:05 -0800</pubDate>
	<category>authentication</category>
	<category>captiveportal</category>
	<category>hotspot</category>
	<category>nocat</category>
	<category>radius</category>
	<category>wi-fi</category>
	<category>wifidog</category>
	<category>wisp</category>
	<dc:creator>bystander</dc:creator>
	</item>
	<item>
	<title>Security Cluelessness</title>
	<link>http://ask.metafilter.com/23913/Security%2DCluelessness</link>	
	<description>I&apos;d like to get a handle on computer security.  Where should I start?  I&apos;d like to stress that I am NOT talking about spyware and viruses here, but the more interesting things like authentication and authorization. At work, I&apos;ve had to get up to speed on a great number of things, but so far the new aspects of my experience haven&apos;t intersected the security aspects of the business.  I&apos;d like to know more before they do, and in support of that I want some advice on how to learn it.&lt;br&gt;
&lt;br&gt;
I&apos;m talking about (for example only!) JAAS, X.501 (?), SAML, et al.  Where do they fit in, what is a complete system made up of, what are some relative merits, et al.  Something not flat-out entry level (ie: Computer Security for Dummies) but rather an introduction for someone who knows how to program in a serious way, but doesn&apos;t know a damned thing about these beasties.&lt;br&gt;
&lt;br&gt;
I&apos;d prefer a book, if at all possible, although web sites are welcome as well.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.23913</guid>
	<pubDate>Sun, 11 Sep 2005 22:00:00 -0800</pubDate>
	<category>authentication</category>
	<category>authorization</category>
	<category>jaas</category>
	<category>networks</category>
	<category>saml</category>
	<category>security</category>
	<category>x501</category>
	<dc:creator>ChrisR</dc:creator>
	</item>
	
	</channel>
</rss>

