I found that self signing a site cert and then enabling all admin through ssl is the best way to prevent passwords going in plain text.... Thanks! James Taylor jamestaylor@xxxxxxxxxxxxxxxxxxxx