[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Apache security!



-----BEGIN PGP SIGNED MESSAGE-----


Ok, I (finally) found the AuthAny module and have it installed.  I've
created a temporary directory for people to put things into called
"protected".  It seems to work for me.

When someone creates a list of roles, I'll create the approprate
directories and set up security.

Also, I've seriously shut down access to our "secret" areas of the web
server.  No more free access.  I've taken the IP's/networks from the
hosts.allow and used that to give access.  I realize that probably leaves
certain people out.  

Those people can either:

1) Send me their prefered loginname/password and I'll added to the global
htpasswd file

or

2) Send me a list of IP's/Networks they will be coming from and I'll add
it to the trusted hosts.

One of these days I need to get SSL installed for the admin pages, but
not a priority right now.

If you have any problems either send me an email, or revert the httpd.conf
to rev 1.11 and restart Apache.

- -- 
Aaron Turner           | Either which way, one half dozen or another. 
aturner@pobox.com      | Check out the Red Hat Linux User's FAQ Online!
www.pobox.com/~aturner | http://www.pobox.com/~aturner/RedHat-FAQ/
All emails from this account are PGP signed.  Lack of a signature is "bad".
PGP Key fingerprint = FB E1 CE ED 57 E4 AB 80  59 6E 60 BF 45 1B 20 E8


On Fri, 5 Mar 1999, Micah Yoder wrote:

> "Aaron D. Turner" wrote:
> 
> > I wouldn't call them role1, role2, etc. but yeah that's the basic plan.  I
> > would say:
> > 
> > /comment
> > /post
> > /edit
> > /etc...
> 
> OK, but there's probably more than one activity for each role, so I
> wasn't sure if we wanted to name the specific functions of the
> directories.  But it's not really important.
> 
> > Auth::Any allows you to test your scripts by using ANY user/passwd
> > combination.  Of course you'll want to use a username in the DB for your
> > script to work! :-)
> 
> That's sweet.
> 
> > There's also some good code to support cookies too, but I'll worry about
> > that after I have something working.
> 
> I don't think we'll need cookies now!
> 


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNuB6hjM3jpXy1kJtAQGWuwP9GZ6nsyBmYEMOD9wlJIuslUfKN7NYxn4I
TSjhpue56iMC1k+FgALp91QGywYLD1/rVl2VZBhJh/l4zVYDAV6vJoVW6LAIbxAO
nJLZqMECxHpecJ5y8dArIZ+Tqind6WBTirS8VQLEfE49WvYHCU6HRVm8tW0pjJCq
rOZP/gsSNkk=
=i0+T
-----END PGP SIGNATURE-----