Re: Rewrite Rules, SSL, and .htaccess

From: Peter H. Lemieux (phl_at_cyways.com)
Date: 03/25/04

  • Next message: Frédéric Médery: "nis : how to avoid user1 becoming user2 using local root ?"
    Date: Thu, 25 Mar 2004 11:53:18 -0500
    To: davec <davec@webpipe.net>
    
    

    Try moving the authentication stuff out of .htaccess and place it in
    <Directory> tags inside httpd.conf instead:

    <VirtualHost 192.168.3.7:80>
    Redirect / https://www.mydomain.com/
    </VirtualHost>

    <VirtualHost 192.168.3.7:443>
    <Directory />
            AuthType Basic
            require valid-user
            etc.
    </Directory>
    </VirtualHost>

    Peter

    davec wrote:

    > Hi,
    > I have a .htaccess file protecting a certain directory on my site. When
    > I tried using the following Apache redirect, I was prompted for my
    > password once on the http version, and once on the https version:
    > <VirtualHost 192.168.3.7:80>
    > Redirect / https://www.mydomain.com/
    > </VirtualHost>
    > The point of using SSL on the password protected directory is to protect
    > the password from being passed in clear text. I think that a RewriteRule
    > would probably do the trick, but after reading the apache documentation
    > (version 2.0.40) I have still not been able to set one up that works
    > properly for the various ways of accessing the site such as
    > http://www.mydomain.com/dir or www.mydomain.com/dir or mydomain.com/dir
    > or http://www.mydomain.com/dir/index.html etc.
    > Any suggestions?
    > Thanks,
    > Dave


  • Next message: Frédéric Médery: "nis : how to avoid user1 becoming user2 using local root ?"

    Relevant Pages

    • Rewrite Rules, SSL, and .htaccess
      ... I have a .htaccess file protecting a certain directory on my site. ... tried using the following Apache redirect, I was prompted for my password ... once on the http version, and once on the https version: ...
      (Focus-Linux)
    • openssl and apache port 80 and 443
      ... My httpd.conf are defining the same host on port 80 and 443. ... The main problem is my .htaccess that isn't working for redirect http pages ...
      (RedHat)