Authentication and Access

Authentication, Access Control and Protecting Files

Apache 129 asks who is asking (authentication) and whether they may have the file (authorization). An authn module checks a password, authz modules each test one condition, and mod_authz_core combines their answers:

How Apache decides between 200, 401 and 403 for a protected directory
How Apache decides between 200, 401 and 403 for a protected directory

Ubuntu 225 loads every module used here except mod_authz_groupfile (a2enmod authz_groupfile). Basic Authentication to IP and Referrer Checks need AllowOverride AuthConfig (AllowOverride), and 2.8.5 and 2.8.6 add FileInfo. The test site runs on port 8108; curl 3,008 --interface 127.0.0.2 plays an outsider.

Subsections