Chat Settings Board Management Board Security

Adding or Editing a Board

Authentication

WebBoard provides three different kinds of authentication: cookie, basic, and no authentication. The type of authentication you choose applies to a single, entire board. You can choose a different type of authentication for another board on the same WebBoard server. These options give you considerable flexibility in setting up your boards.

Cookie

Boards using cookie authentication present users with a friendly login form to start their WebBoard session. In addition, users have the option to log in to WebBoard without entering their login name or password again for six months, provided they check the remember my password option. All web servers and most web browsers support cookie authentication. It is easier to use, and has a pleasant, intuitive user interface. Note that a user’s browser must be configured to accept cookies to use WebBoard anyway, so cookie authtication is preferred. With cookie authentication, a user can also easily log in again as a different user.

Basic

Basic authentication is supported by most web browsers and provides the most secure type of login because it does not allow a user to save his password. WebBoard’s basic authentication uses the standard web challenge-response method for authenticating users. When a user requests a WebBoard URL, the server responds with a username and password dialog box, but there are no clues for the user as to what to do when the dialog appears.

Users who already know their WebBoard login name and password simply enter their login name and password, click Enter, and are logged into the board. But new users may wonder what should they enter in this dialog. They do not know that anything they enter is okay; the server responds with a page asking if they are new users or mistyped their information. Links on this page take the user to the page that creates a new profile or back to the login dialog to try again. Some novice users may click Cancel instead of entering a username and password. In this case, WebBoard returns the failed authentication page, which provides instructions to new users. There are no guest logins with basic authentication (this is a change with WebBoard 4.0). If you choose to use basic authentication, we highly recommend that you test it thoroughly so you can see what your users may encounter.


Note Note
If you are using IIS as an external server and choose basic authentication for a board, all users must be in the NT user database on the system running IIS in order to be authenticated.

None

Using no authentication lets users into a board without any login, name or a password. In essence, this is a transient board with no user database and no way to track user identities or activity. When users post to a no-auth board, they are prompted for their name and an email address. As you might suspect, these visitors are called unauthenticated users. No-auth boards provide a nonthreatening, seamless transition between a standard web site and your WebBoard. They can also introduce the uninitiated to the benefits of conferences and the sense of involvement and community WebBoard can foster. No-auth boards do not support some WebBoard features that depend on knowing the users’ identity, for example, user searches, user profiles, and paging.


Note Note
A no-auth board, once created, may never be edited to authenticate users. To achieve this, the board must be deleted and re-created. Likewise, boards created with either cookie or basic authentication may not be changed to be no auth.




Chat Settings Board Management Board Security

Powered by WebBoard Copyright ©2001 ChatSpace, Inc.