Set up password protected web pages

From SWCP Support Wiki
Jump to navigationJump to search

Password protected web pages

Modern web browsers have the ability to perform password authentication. These passwords are independent of system passwords. To set up password protected web pages, follow these steps.

  1. Create a new directory under your public_html directory which will store the protected pages.
  2. Create a file in that directory called .htaccess with the following contents (password dialogue is the text which will appear to the browser in the password dialogue window, and login-name is your SWCP login)
     AuthUserFile /users/login-name/.htpasswd
     AuthGroupFile /users/login-name/.htgroup
     AuthName "password dialogue"
     AuthType Basic
     <Limit GET>
     require group my-users
     </Limit>

     If your website is on our older web server (kumo) please remove the quotes from the AuthName argument.

  1. Create a file in your home directory called .htgroup with the contents
     my-users: pumpkin peanuts almonds walnuts

     These are the users who are allowed to access. They will also need to have passwords defined in .htpasswd. To create this file and add the first username use the following UNIX command:

     htpasswd -c /users/login-name/.htpasswd username
     After running the htpasswd command, you will be prompted for the users password twice. This will create a file /users/login-name/.htpasswd containing a encrypted form of the password. The -c option to the htpasswd command creates the password file so after adding the initial username use the following Unix command to add additional usernames:

     htpasswd /users/login-name/.htpasswd username

  1. Finally, all 3 files have to be world readable (chmod a+r). Now, when any files in password protected directory are accessed, the browser will get a password required dialogue.
     chmod a+r /users/login-name/.htpasswd
     chmod a+r /users/login-name/.htgroup
     chmod a+r /users/login-name/public_html/somedir/.htaccess

While very useful, there are a couple of drawbacks to this htpasswd mechanism. Users and their passwords have to be created using the command line utility, and then manually entered into .htgroup. Also, each time you run the htpasswd utility, it sets the mode of the file .htpasswd back to 600. So it will have to manually changed back to mode 644 (chmod a+r). Users who want to automate this procedure via CGI should keep these things in mind for their scripting.

More detailed info is available at http://hoohoo.ncsa.uiuc.edu/docs/tutorials/user.html