LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 12-30-2008, 07:44 PM   #1
Dasc
Member
 
Registered: Jul 2004
Posts: 47

Rep: Reputation: 15
Apache authentication against machine users


Hello
I'm stuck on a configuration issue and i'm not able to find any documentation about it

i'm in a rather simple scenario: I have a web site (Trac) on a debian server which optionally requires user authentication.
Since high security on this machine is not really an issue (but ease of managing is) I'd like the users to log in with the same user/pass they use to authenticate onto the server, so avoiding the need to manually mantain an htpasswd file etc

Is there a way to achieve this?
if the burden goes beyond managing an htpasswd file i'll probably have stick with that, but any solution is well appreciated
 
Old 12-31-2008, 06:17 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Maybe see http://www.unixpapa.com/mod_auth_external.html and http://sourceforge.net/projects/mod-auth-shadow/. If you use 'em please read the "security considerations" part. Increase your mana additionally by pondering the reasons for applications to *not* require /etc/shadow access but use the "virtual user" concept instead.
 
Old 12-31-2008, 08:03 PM   #3
Dasc
Member
 
Registered: Jul 2004
Posts: 47

Original Poster
Rep: Reputation: 15
Thank you very much, mod-auth-shadow was exactly what I was looking for
(I see mod-auth-external reaches the same goals with more flexibility but with options I don't need)

it's already working
thanks again and Happy New Year
 
Old 01-01-2009, 04:54 PM   #4
Dasc
Member
 
Registered: Jul 2004
Posts: 47

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by unSpawn View Post
If you use 'em please read the "security considerations" part. Increase your mana additionally by pondering the reasons for applications to *not* require /etc/shadow access but use the "virtual user" concept instead.
yep, i did
the fact is this is an internal lan server that almost only serves as svn repository and trac. having to manage different auths for shell/svn/trac etc really goes beyond the added risk of having www-data access the shadow pw file

btw since currently there isn't a main deb package for mod_auth_shadow, I found out that you can achieve the same result using mod_auth_pam and pointing to /etc/shadow as AuthUserFile

thanks again for your suggestions
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
PAM vs WEP authentication between users heffo_j Linux - Networking 6 04-24-2008 09:19 PM
Migrating machine users to virtual users p_penduko Linux - General 2 11-04-2004 07:37 AM
ISA authentication from a RH90 virtual machine (VMware) mdanc Linux - Networking 0 02-04-2004 08:56 AM
ssh-key authentication failing on one machine chr15t0 Linux - Security 3 08-21-2003 04:24 PM
Apache users - Basic login authentication with Apache2 piglingz Linux - Software 1 04-06-2003 09:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 08:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration