KB 429

From SWCP Support Wiki
Jump to navigationJump to search

How do I password protect my web pages?

Article:429
Created:2005-10-14 17:53:33
Categories:
  Web Publishing

Question or Symptom

Resolution

NCSA compatible web servers and modern web browsers have the ability to perform password authentication. These passwords are independent of system passwords. To set up password protected web pages, follow these steps.

   * Create a new directory under your public_html directory which will store 
     the protected pages.
   * Create a file in that directory called .htaccess with the following 
     contents (password dialogue is the text which will appear to the browser
     in the password dialogue window, and login-name is your SWCP login)
 
        AuthUserFile /users/login-name/.htpasswd
        AuthGroupFile /users/login-name/.htgroup
        AuthName "password dialogue"
        AuthType Basic
        <Limit GET>
        require group my-users
        </Limit>
   *  If your website is on our older web server (kumo) please remove the 
      quotes from the AuthName argument.   
 
   * Create a file in your home directory called .htgroup with the contents
 
       my-users: pumpkin peanuts almonds walnuts
 
     These are the users who are allowed to access. They will also need to have
passwords defined in .htpasswd. To create this file and add the first username
use the following UNIX command:
 
       htpasswd -c /users/login-name/.htpasswd username
 
     After running the htpasswd command, you will be prompted for the users 
password twice. This will create a file /users/login-name/.htpasswd containing
a encrypted form of the password. The -c option to the htpasswd command creates
the password file so after adding the initial username use the following Unix 
command to add additional usernames:
 
   htpasswd /users/login-name/.htpasswd username
 
   * Finally, all 3 files have to be world readable (chmod a+r). Now, when any
files in password protected directory are accessed, the browser will get a 
password required dialogue.
 
     chmod a+r /users/login-name/.htpasswd
     chmod a+r /users/login-name/.htgroup
     chmod a+r /users/login-name/public_html/somedir/.htaccess
 
While very useful, there are a couple of drawbacks to this htpasswd mechanism.
Users and their passwords have to be created using the command line utility, 
and then manually entered into .htgroup. Also, each time you run the htpasswd 
utility, it sets the mode of the file .htpasswd back to 600. So it will have to
manually changed back to mode 644 (chmod a+r). Users who want to automate this 
procedure via CGI should keep these things in mind for their scripting.


 http://hoohoo.ncsa.uiuc.edu/docs/tutorials/user.html