PNG IHDR ; IDATxܻn0K )(pA7LeG{ §㻢|ذaÆ 6lذaÆ 6lذaÆ 6lom$^yذag5 bÆ 6lذaÆ 6lذa{ 6lذaÆ `}HFkm,mӪôô!x|'ܢ˟;E:9&ᶒ}{v]n&6 h_tڠ͵-ҫZ;Z$.Pkž)!o>}leQfJTu іچ\X=8Rن4`Vwl>nG^is"ms$ui?wbs[m6K4O.4%/bC%tMז -lG6mrz2s%9s@-k9=)kB5\+͂ZsٲRn~GRCwIcIn7jJhۛNCS|j08yiHKֶۛkɈ+;SzL /F*\Ԕ#"5m2[S=gnaPeғL lذaÆ 6l^ḵaÆ 6lذaÆ 6lذa; _ذaÆ 6lذaÆ 6lذaÆ R IENDB`
Apache HTTP Server Version 2.4
(authentication) ڽ ϴ Ȯϴ ̴. Ѻο(authorization) Ȥ ϴ ϴ ̴.
õ | õ þ |
---|---|
ۿ ٷ þ ּ(Ϲ
<Directory>
)̳ 丮 (.htaccess
)
Ѵ.
.htaccess
Ϸ Ͽ ִ
þ ϵ ؾ Ѵ. ̸
丮 Ͽ þ ִ ϴ
AllowOverride
þ
Ѵ.
⼭ ٷ ,
AllowOverride
þ ʿϴ.
AllowOverride AuthConfig
Ȥ þ ּϿ ´ٸ, Ͽ ־ Ѵ.
ȣ ִ ˱ 丮 ˾ƾѴ. ʰ, ڼ ̴.
丮 ȣ ȣϴ ⺻ Ѵ.
ȣ Ѵ.
־ Ѵ. ٸ ȣ ٿε
ϰϱ ؼ. ,
/usr/local/apache/htdocs
ִٸ ȣ()
/usr/local/apache/passwd
д.
ġ Ե htpasswd Ͽ
ȣ . α ġ ġ
bin
丮 ִ.
ԷѴ.
htpasswd -c /usr/local/apache/passwd/passwords rbowen
htpasswd
ȣ , Ȯ
ȣ ٽ Է϶ ûѴ.
# htpasswd -c /usr/local/apache/passwd/passwords rbowen
New password: mypassword
Re-type new password: mypassword
Adding password for user rbowen
htpasswd
ο ٸ
ü θ Էؾ Ѵ. ϴ
/usr/local/apache/bin/htpasswd
ִ.
ȣ ûϵ ϰ,
˷ Ѵ.
httpd.conf
ϰų .htaccess
Ͽ Ѵ. ,
/usr/local/apache/htdocs/secret
丮
ȣϷ, Ʒ þ
/usr/local/apache/htdocs/secret/.htaccess
̳
httpd.conf
<Directory
/usr/local/apache/apache/htdocs/secret> ǿ
Ѵ.
AuthType Basic
AuthName "Restricted Files"
AuthUserFile /usr/local/apache/passwd/passwords
Require user rbowen
þ ϳ 캸. AuthType
þ ڸ
Ѵ. Ϲ Basic
,
mod_auth_basic
Ѵ. Basic
ȣ ȣȭ ʰ .
Ƿ ڷḦ ȣϱ ϸ ȵȴ.
ġ AuthType Digest
Ѵ.
mod_auth_digest
ϸ, ſ
ϴ. ֱ Ŭ̾Ʈ鸸 Digest Ѵٰ
Ѵ.
AuthName
þ
(realm) Ѵ.
ΰ Ѵ. ù° Ŭ̾Ʈ
ȣ ȭâ ش. ι° Ͽ
Ŭ̾Ʈ Ư ȣ Ѵ.
, ϴ Ŭ̾Ʈ "Restricted Files"
Ͽٸ, Ŭ̾Ʈ ڵ
"Restricted Files"
ǥõ
ȣ õѴ.
ϸ ڰ ȣ Է ʾƵ ȴ.
Ȼ Ŭ̾Ʈ ȣƮ ٸ
ȣ .
AuthUserFile
þ 츮 htpasswd
ȣ
θ Ѵ. ڰ ٸ û Ź ڸ
ϱ Ϲ ˻ϴµ ð
ɸ ִ. ġ Ÿ̽ Ͽ
ִ. mod_authn_dbm
AuthDBMUserFile
þ
Ѵ. dbmmanage
α Ͽ ȣ ٷ. ġ
Ÿ̽ ٸ ϴ ڰ
ִ.
Require
þ Ư ִ ڸ Ͽ
Ѻο Ѵ. require
þ
ϴ پ Ѵ.
þ 丮 (ڸ rbowen
)
鿩. κ 鿩
̴. AuthGroupFile
.
鿩 ʹٸ 쿡 ڵ ִ ˷ִ ʿϴ. ſ Ͽ, ƹ γ ִ. ϳ .
GroupName: rbowen dpitts sungo rshersey
׳ ̴.
ȣϿ ڸ ߰Ϸ ԷѴ
htpasswd /usr/local/apache/passwd/passwords dpitts
, ʰ Ͽ ڸ
߰Ѵ. (-c
ɼ ȣ ).
.htaccess
Ѵ.
AuthType Basic
AuthName "By Invitation Only"
AuthUserFile /usr/local/apache/passwd/passwords
AuthGroupFile /usr/local/apache/passwd/groups
Require group GroupName
GroupName
쿡 ϸ
password
Ͽ ִ ڰ ùٸ
ȣ Էϸ Ѵ.
Ϲ ڸ 鿩 ٸ ִ. ʿ þ ϱ⸸ ϸ ȴ.
Require valid-user
Require user rbowen
þ ϸ
ȣϿ ִ ùٸ ȣ Էϱ⸸ ϸ
Ѵ. 캰 ٸ ȣ Ͽ
ȿ ִ. ġ ΰ(ȣϰ
) ƴ Ѱ(ȣ) ˻ϸ ȴٴ
̴. ȣ ؾ ϰ, AuthUserFile
þ
Ȯ ȣ ؾ ϴ ̴.
Basic û ڸ ȣ ȮѴ. ħ ( ȣ ȣϴ 丮 ִ ) ִ ٽ ȮѴ. ϵ ӵ . ȣ ڸ ã ϱ ȣ ũⰡ Ŀ . ۾ û Ѵ.
ȣϿ ִ ڼ Ѱ谡 ִ. Ѱ ϴ ɿ ٸ, 鰳 Ѵ´ٸ ٰ ϰ ٸ ؾ Ѵ.
ڸ ȣ ٰ ƴϴ. ҿ ٸ ڸ 鿩 ִ.
Allow
Deny
þ
û ǻ ȣƮ Ȥ ȣƮ ּҸ
ϰų źѴ. Order
þ
þ Ͽ, ġ Ģ
˸.
̵ þ .
Allow from address
⼭ address IP ּ(Ȥ IP ּ Ϻ) θ(Ȥ θ Ϻ)̴. Ѵٸ ּҳ θ ִ.
, Խǿ ø ִٸ ִ.
Deny from 205.252.46.165
ּҿ 湮ڴ þ ȣϴ . IP ּ ǻ ִ.
Deny from host.example.com
, ü ּҳ θ Ϻθ Ѵ.
Deny from 192.101.205
Deny from cyberthugs.com moreidiots.com
Deny from ke
Order deny,allow
Deny from all
Allow from dev.example.com
Allow
þ ϸ, ش ȣƮ ڸ ϰ ű
߰ ϹǷ ϴ Ѵ.
Ư ϱ Ѵ.
mod_auth_basic
mod_authz_host
ϴ
ִ.