Hi All,I need to provide my corporate security team with a little more information regarding how we secure the TeamSite Login Screen, especially the password encryption portion. I see the login form "encrypts" the password before posting back to the serverThe question is: How does it do this? via some simple JavaScript client library? via some custom TeamSite magic? via an industry standard encryption library?Yes, I RTFM, but that didn't help and searching this forums didn't turn up any prior discussions, and something a little more concrete than telling others not t worry, its taken care of by the vendor :-)Thanks for any info.Keith
After more research, I found my answer, and the TeamSite login screen does a really poor job of securing credentials. I won't post them here so as to not cause a firestorm. I'll talk to support on this as its easy to exploit. The login screen should at a minimum force https. I've been doing Interwoven development and support since 2000 and this one slipped by. Its actually quite shocking and unacceptable in today's global enterprise climate. Thanks Boris.