Dead simple authentication for one user

I have written a small internal web application using (subset of) pylons . As it turned out, now I have to allow the user to access it from the Internet. This is not an application that was written to be viewed on the internet, and it has a bunch of tearing security holes.

What is the easiest way I can ensure that this site is reliably accessible to this user, but no one else?

I think something like simple Apache HTTP Authentication but more secure. (Is OpenID a good match?)

There is only one user. No need to manage users, don't even change your password. Also, I trust the user not to damage the server (that's actually his).

If it were for me, I would just leave it behind a firewall and use ssh port forwarding, but I would like to have something simpler for this user.

EDIT : Hmm ... judging from the answers, it should have been on the server. If a moderator is reading this, consider migrating it.

0


a source to share


3 answers


if only one user, using a certificate is probably the easiest.



+8


a source


How about a VPN? There should be plenty of convenient VPN clients out there. He may already be familiar with the technology, as many corporations use them to give workers access to the internal network on the road.



+4


a source


Basic HTTP authentication can be done easily with tools like brutus. If his ip is static, you can allow his ip and deny all others with htaccess.

+2


a source







All Articles