[TYPO3-english] Salted Passwords & RSA: temp directory path

Urs Bräm info at ursbraem.ch
Tue Mar 13 12:20:38 CET 2012


As TYPO3 Security Check has become quite insistent about that, have 
installed salted passwords, and it demands rsaauth. So I've installed 
that as well.

I've configured everything for Salt + RSA for BE Users (no FE Login 
yet). There are no error messages in the Salted Passwords configuration 
dialogue, everything seems fine. In the DB, the passwords are being 
converted to salted hashes.

But I can't set the RSA Extension's temporary path properly to store the 
temporary keys. I've created a folder above my public_html in the home 
directory (/home/username/rsaauth/) and chmodded it to 700 - but it 
stays empty. I can't find the keys in typo3temp neither.

My questions are:

* is the RSA Extension really needed for increased security?
* what form should the path in the EM Configuration dialogue have?
* any other hints to set this up for better security?

Thanks a lot

Urs Bräm
macht Websites
Certified Typo3 Integrator
CH-3011 Bern

More information about the TYPO3-english mailing list