httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Joshua Slive" <jos...@slive.ca>
Subject Re: [users@httpd] HTDigest
Date Thu, 08 Nov 2007 23:47:22 GMT
On Nov 8, 2007 6:38 PM, Grant Peel <gpeel@thenetnow.com> wrote:
> Hi all,
>
> I have a security company hounding me to turn of HTDigest.
>
> Any idea how?

If they think it is so important, why not ask them? Or are they just
following some set of inflexible rules that even they don't really
understand?

Anyway, htdigest is a simple support utility that comes with apache.
As long as it isn't suid or called directly from the web, it poses
absolutely no security hazard. But if you want to "turn it off", find
it on your hard disk and remove it.

Joshua.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message