Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Understanding htaccess (htpasswd)

Posted on 2010-09-07
7
Medium Priority
?
513 Views
Last Modified: 2012-05-10
I've inherited a website template from another programmer. The task was simple enough, copy the entire website, change the content (including database links). He is using the .htaccess file, a file I am not familiar with.

I'm currently working on the admin section of this site.
There a note in the code, on the line for the username and password for the admin section, that says "// change this value when password changes for admin along with htpasswd file". I've done a site search and can't find a file named htpasswd.
If I change the password in the admin file, the website can never authenticate the password and I can't login.

There is the .htaccess file. The code for that is below. If I change "oldsite" to "newsite" the page, after login, will display a 500 Internal Server Error.

I've never used the .htaccess file before, and I'm not really sure where to start.
Everything else on the site is ready to go, except for changing the password to the current site. If I use the old password, everything works just fine.


AuthName "Restricted Area" 
AuthUserFile "/home/oldsite/etc/passwd"
AuthType Basic
require valid-user

Open in new window

0
Comment
Question by:kentcommunications
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 15

Expert Comment

by:Insoftservice
ID: 33619903
HI,
may i get the complete  htaccess rule
0
 

Author Comment

by:kentcommunications
ID: 33620645
The code I attached is the entire contents of the .htaccess file.
0
 
LVL 15

Expert Comment

by:Insoftservice
ID: 33624192
hi,

chk the path of the htpasswd file

AddType text/x-component .htc
RewriteEngine on
AuthType Basic
AuthName "Restricted Area"
AuthUserFile "/home/oldsite/etc/passwd"
require valid-user
0
Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

 
LVL 4

Accepted Solution

by:
chrisbloom7 earned 2000 total points
ID: 33626465
AuthUserFile "/home/oldsite/etc/passwd"

That line contains the path to the password file. You can either grab it from the old server, or create a new one and update the path to the new file. If you have to create a new one, note the next line in the htaccess file:

require valid-user

That line probably describes a group of users rather than a single user. You can find out more about the process of creating passwords and groups at http://httpd.apache.org/docs/2.2/howto/auth.html
0
 
LVL 4

Expert Comment

by:chrisbloom7
ID: 33626513
Sorry - I need to correct that last part. valid-user is actually a keyword, not a user nor a group. If it were a group there would be an extra AuthGroupFile directive and the group name would be preceded with the word "group", as in

require group valid-user

Instead the keyword valid-user means allow anyone in that is using a valid username and password, as defined in the password file. Again, refer to the documentation I linked to.
0
 
LVL 4

Expert Comment

by:chrisbloom7
ID: 33626533
Also, I feel compelled to say that Basic Authentication is not the best way to protect an administration area as it requires external functionality to protect the pages. In other words, if Apache isn't configured properly the pages are unprotected but still accessible. Better to use the scripting language itself (PHP) to restrict access to the files. You will have much more control and flexibility and no external requirements.
0
 

Author Comment

by:kentcommunications
ID: 33627437
I copied the passwd file from the original site to the new one. It only contains one line, an encrypted password.

As you said, this isn't the best way to do user authentication (I've never worked with this method) so I'm just going to set it up through PHP, I'm thinking its less of a hassle at this point.

Thanks!
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a good reason for why it’s called a homepage – it closely resembles that of a physical house and the only real difference is that it’s online. Your website’s homepage is where people come to visit you. It’s the family room of your website wh…
There are times when I have encountered the need to decompress a response from a PHP request. This is how it's done, but you must have control of the request and you can set the Accept-Encoding header.
The viewer will learn how to count occurrences of each item in an array.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question