Your work is very much appreciated.
This will allow webmasters who wish to at least secure the login procedure to do so without having to obtain/install an SSL Certificate; something which isn't always possible/feasible.
I've tested this module and I guess it isn't compatible with other modules that alter the log-in dialog.
I've only tried it with OpenID, and after filling in my OpenID URL and submitting, the message which requests the user to wait while they are being logged in is displayed but the redirection to the OpenID server never takes place.
I haven't tested it with WinLiveID, but I guess it would be the same.
Thank you and regards,
Comments
Comment #1
selmanj commentedUnfortunately, I don't think there is anyway this could happen.
The module requires access to the password hash. Both OpenID, WinLiveID, and almost any other login module don't have access to the hash; they authenticate by forwarding the password on (securely) to whatever service is needed, and waiting for a 'success/fail' response (or something similar, I'm sure it's more complicated than that). The method that CRAM uses to send the password in a secure but non-ssl form requires access to the password hash.
Guess you'll have to use SSL for those. I don't think there is any other option. Sorry :(