[Koha-devel] Koha Security best practises

Robin Sheat robin at catalyst.net.nz
Mon Jun 20 07:16:03 CEST 2011


Mahesh T Pai schreef op ma 20-06-2011 om 10:36 [+0530]:
> Thanks.
> 
> Is it possible to use IP address based access controls from within koha?
> 
> Like specifying from where library staff can access / log in ?

These kinds of things are best handled by Apache, as it has all sorts of
controls that can be applied.

For example:
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=6296
allows Apache to require that the user has a correct client SSL
certificate (and if they do, it makes it possible to log them in without
a password.)

-- 
Robin Sheat
Catalyst IT Ltd.
✆ +64 4 803 2204
GPG: 5957 6D23 8B16 EFAB FEF8  7175 14D3 6485 A99C EB6D
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: </pipermail/koha-devel/attachments/20110620/dd96a827/attachment.pgp>


More information about the Koha-devel mailing list