[pve-devel] Two-Factor Authentication

Eric Blevins ericlb100 at gmail.com
Fri Jun 20 18:09:42 CEST 2014


>
> How exactly? The API uses the secret key to verify request/response. That key is unknown
> to the attacker.

You are correct, I was ignoring the fact the API provides verification
through the API keys.

https would only provide an additional layer of verification.



More information about the pve-devel mailing list