[wplug] Opinion: restricting access to Apache

ARiley at edgarsnyder.com ARiley at edgarsnyder.com
Fri Jun 4 13:02:49 EDT 2004





It seems I can not read today.  _Basic_ Authorization is clear text, _DBM_
Authorization, on the other hand, I assume is a direct connection with
whatever database chosen.  The system hosts.allow/deny files is a great
idea too.  Thanks.


                                                                           
             "Vanco, Don"                                                  
             <don.vanco at agilys                                             
             ys.com>                                                    To 
             Sent by:                  "General user list"                 
             wplug-bounces+ari         <wplug at wplug.org>                   
             ley=edgarsnyder.c                                          cc 
             om at wplug.org                                                  
                                                                   Subject 
                                       RE: [wplug] Opinion: restricting    
             06/04/2004 12:39          access to Apache                    
             PM                                                            
                                                                           
                                                                           
             Please respond to                                             
             General user list                                             
             <wplug at wplug.org>                                             
                                                                           
                                                                           






wplug-bounces+don.vanco=agilysys.com at wplug.org wrote:
> I'm locking down an intranet web server , allowing only
> certain users and IP addresses to connect.  The people that
> will connect will be few in number but scattered across the US.
>
> Is the preferred way of restricting access to Apache still
> through mod_access, mod_auth as the documentation suggests?
> I get the impression that passwords are sent in clear text.
> Are there any other avenues that I should explore?

Aside from the Apache bits you could likely do something really simple
with hosts.allow/deny if it's only a few subnets/IPs/users

Don

_______________________________________________
wplug mailing list
wplug at wplug.org
http://www.wplug.org/mailman/listinfo/wplug





More information about the wplug mailing list