Confluence Authenticates in Plaintext?

Matt Uebel September 18, 2013

When using active directory to authenticate users, is this authentication ever in plaintext?

2 answers

1 accepted

1 vote
Answer accepted
Tiago Comasseto
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 18, 2013

Hi Matt, are you referring to network traffic between Confluence and LDAP sending data in plaintext? If this is it, you can connect Confluence to the LDAP through SSL (as in this doc), then all communication will be encrypted.

Cheers

Matt Uebel September 18, 2013

I am talking from the client perspective. User logs into Confluence web interface, client sends auth data to Confluence server.

Is this in plaintext, or is there any mechanism to protect it starting at the client side?

2 votes
Sorin Sbarnea (Citrix)
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 18, 2013

The answer is quite simple, if not even obvious: to secure authentication you need to run Confluence on HTTPS instead of HTTP and to connect to LDAP using LDAPS.

This is more about how you configure it, not about the product itself.

Matt Uebel September 18, 2013

Thank you, yes it is obvious.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events