Return-Path: Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 85273 invoked by uid 500); 7 Jul 2003 19:20:39 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: list-post: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 85260 invoked from network); 7 Jul 2003 19:20:39 -0000 Received: from mta9.wss.scd.yahoo.com (66.218.85.40) by daedalus.apache.org with SMTP; 7 Jul 2003 19:20:39 -0000 Received: from [198.241.217.3] by mta9.wss.scd.yahoo.com with HTTP; Mon, 7 Jul 2003 12:20:44 -0700 Date: Mon, 7 Jul 2003 15:20:44 -0400 Message-ID: <3EDCE81900014AAE@mta9.wss.scd.yahoo.com> In-Reply-To: From: "John K. Sterling" To: users@httpd.apache.org MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N Subject: Re: [users@httpd] Multiple auth sources >-- Original Message -- >From: SAQIB > >I dont think this is possible. Even if it was it would be a security >issues. A long while back I was looking into this, but didnt pursue due to >possible security issues. how is this a security issue? the way i read the question he simply want= s to have a couple of auth modules have a chance to authenticate for a give= n location. Apache definitely does not make this easy, but it is theoretically possib= le by figuring out which auth module runs last (either in the module definit= ion, or based on the order they are loaded) and set it to 'Authoritative on' (most auth modules have this ability). Then set all of the other auth mo= dules to 'Authoritative off'. By convention most auth modules support the authoritative concept. So th= e ones that have 'Authoritative off' return DECLINED if they fail (not unau= thorized) allowing other auth modules to get the opportunity to try as well - then the last one (which is set to 'Authoritative on' returns unauthorized if it fails too. hope this helps. sterling --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See for more info. To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org " from the digest: users-digest-unsubscribe@httpd.apache.org For additional commands, e-mail: users-help@httpd.apache.org