Re: apache2.conf AuthType Basic

Egon Frerich <[email protected]> Wed, 11 Mar 2026 15:42:07 +0100
Newsgroups gmane.comp.apache.user
Message-ID <[email protected]>
--------------uVNCjstCfhERbi9YlUxURmQS
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit


On 3/11/26 14:33, Adam Mihai Gergely wrote:
>
> People... Learn how to use AI (securely or with anonymous data), 
> seriously...
>
> 1. Does that path exist ?
> 2. Does the passwords file have the exact format a htpasswd file 
> should have ?
> 3. Did you restart apache2 if you modified the config file ?
> 4. Do you have user xxx in /etc/apache2/passwd/passwords defined 
> correctly with the correct form of the password ?...
>
everything is ok

Egon



> I use this script for generating htpasswd conf files:
> (of course, you need to adapt it to your paths)
>
> compile.sh:
>
> #!/bin/bash
>
> # Path to your existing htpasswd file
> HTPASSWD_FILE=/etc/apache2/htpwd/htpasswd
>
> # Your source file with plain passwords
> SRC=/etc/apache2/htpwd/src.txt
>
> # Truncate existing file (empty it)
> > "$HTPASSWD_FILE"
>
> # Loop through your source file and add users/passwords
> while IFS=: read -r user pass; do
>   # -b = use password from command line (non-interactive)
>   # -B = bcrypt (better security than SHA; but Apache must support)
>   # You can use -s for SHA1, but bcrypt (-B) is better if supported
>   htpasswd -bB "$HTPASSWD_FILE" "$user" "$pass"
> done < "$SRC"
> echo ""
> echo "Restarting Apache..."
> systemctl restart apache2
> echo "... done !"
> echo ""
>
> I enter "username:password" in my src.txt and run this script.
> It produces the entry with hashed password in htpasswd.
>
> Then, I point my conf to that file:
>
>     <Directory "/path/to/secure/dir">
>         SSLRequireSSL
>         Options -Indexes +FollowSymLinks
>         AllowOverride None
>
>         AuthType Basic
>         AuthName "<> Red Authentication Required <>"
>         AuthBasicProvider file
>         AuthUserFile /etc/apache2/htpwd/htpasswd
>         Require user RedUser
>         ErrorDocument 401 /401.html
>     </Directory>
>
> Ensure that this declaration is in a VirtualHost 443 or some form of 
> SSL ! (HTTPS !)
>
> Do NOT use this in non-https because it exposes your password as 
> plain-text. Someone on the network could sniff your password in 
> certain conditions.
>
> Cu stima,
> Adam Mihai Gergely
> Informatician
> www.infosky.ro
> On 3/11/26 15:07, Egon Frerich wrote:
>>
>> I want to allow only user with password to see /gitweb. I put this 
>> into apache.conf:
>>
>> |<Directory /opt/gitweb> Options Indexes FollowSymLinks AllowOverride 
>> None #Require all granted AuthType Basic AuthName "flora" 
>> AuthBasicProvider file AuthUserFile "/etc/apache2/passwd/passwords" 
>> Require user xxx </Directory> |
>>
>> But could see gitweb without a password.
>>
>> What should I do?
>>
>> Egon
>>
>>
--------------uVNCjstCfhERbi9YlUxURmQS
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 3/11/26 14:33, Adam Mihai Gergely
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p>People... Learn how to use AI (securely or with anonymous
        data), seriously...</p>
      <p>1. Does that path exist ?<br>
        2. Does the passwords file have the exact format a htpasswd file
        should have ?<br>
        3. Did you restart apache2 if you modified the config file ?<br>
        4. Do you have user xxx in /etc/apache2/passwd/passwords defined
        correctly with the correct form of the password ?...</p>
    </blockquote>
    <p>everything is ok</p>
    <p>Egon</p>
    <p><br>
    </p>
    <p><br>
    </p>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <p>I use this script for generating htpasswd conf files:<br>
        (of course, you need to adapt it to your paths)</p>
      <p>compile.sh:</p>
      <p>#!/bin/bash<br>
        <br>
        # Path to your existing htpasswd file<br>
        HTPASSWD_FILE=/etc/apache2/htpwd/htpasswd<br>
        <br>
        # Your source file with plain passwords<br>
        SRC=/etc/apache2/htpwd/src.txt<br>
        <br>
        # Truncate existing file (empty it)<br>
        &gt; "$HTPASSWD_FILE"<br>
        <br>
        # Loop through your source file and add users/passwords<br>
        while IFS=: read -r user pass; do<br>
          # -b = use password from command line (non-interactive)<br>
          # -B = bcrypt (better security than SHA; but Apache must
        support)<br>
          # You can use -s for SHA1, but bcrypt (-B) is better if
        supported<br>
          htpasswd -bB "$HTPASSWD_FILE" "$user" "$pass"<br>
        done &lt; "$SRC"<br>
        echo ""<br>
        echo "Restarting Apache..."<br>
        systemctl restart apache2<br>
        echo "... done !"<br>
        echo ""</p>
      <p>I enter <a class="moz-txt-link-rfc2396E"
          href="username:password" moz-do-not-send="true">"username:password"</a>
        in my src.txt and run this script.<br>
        It produces the entry with hashed password in htpasswd.</p>
      <p>Then, I point my conf to that file:</p>
      <p>    &lt;Directory "/path/to/secure/dir"&gt;<br>
                SSLRequireSSL<br>
                Options -Indexes +FollowSymLinks<br>
                AllowOverride None<br>
        <br>
                AuthType Basic<br>
                AuthName "&lt;&gt; Red Authentication Required &lt;&gt;"<br>
                AuthBasicProvider file<br>
                AuthUserFile /etc/apache2/htpwd/htpasswd<br>
                Require user RedUser<br>
                ErrorDocument 401 /401.html<br>
            &lt;/Directory&gt;</p>
      <p>Ensure that this declaration is in a VirtualHost 443 or some
        form of SSL ! (HTTPS !)</p>
      <p>Do NOT use this in non-https because it exposes your password
        as plain-text. Someone on the network could sniff your password
        in certain conditions.</p>
      <pre class="moz-signature" cols="72">Cu stima,
Adam Mihai Gergely
Informatician
<a class="moz-txt-link-abbreviated" href="http://www.infosky.ro"
      moz-do-not-send="true">www.infosky.ro</a></pre>
      <div class="moz-cite-prefix">On 3/11/26 15:07, Egon Frerich wrote:<br>
      </div>
      <blockquote type="cite"
        cite="mid:[email protected]">
        <meta http-equiv="content-type"
          content="text/html; charset=UTF-8">
        <p>I want to allow only user with password to see /gitweb. I put
          this into apache.conf:</p>
        <pre><code>&lt;Directory /opt/gitweb&gt;
        Options Indexes FollowSymLinks
        AllowOverride None
        #Require all granted
   AuthType Basic
   AuthName "flora"
   AuthBasicProvider file
   AuthUserFile "/etc/apache2/passwd/passwords"
   Require user xxx
&lt;/Directory&gt;
</code></pre>
        <p>But could see gitweb without a password.</p>
        <p>What should I do?</p>
        <p>Egon</p>
        <p><br>
        </p>
      </blockquote>
    </blockquote>
  </body>
</html>

--------------uVNCjstCfhERbi9YlUxURmQS--