mod_auth_dbm.html revision e3d0ad4177632a17c3f1fa733a9623abf54cd289
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<HTML>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<HEAD>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<TITLE>Apache module mod_auth_dbm</TITLE>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</HEAD>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<BODY>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<!--#include virtual="header.html" -->
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<H1>Module mod_auth_dbm</h1>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeThis module is contained in the <code>mod_auth_dbm.c</code> file, and
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeis not compiled in by default. It provides for user authentication using
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeDBM files. See the <A HREF="auth_dbm.html">DBM user documentation</a>.
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<menu>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<li><A HREF="#authdbmgroupfile">AuthDBMGroupFile</A>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<li><A HREF="#authdbmuserfile">AuthDBMUserFile</A>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</menu>
d5c5bbb465522850e1cf14447d3ecb86d4c32213Knut Anders Hatlen<hr>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<A name="authdbmgroupfile"><h2>AuthDbmGroupFile</h2></A>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<!--%plaintext &lt;?INDEX {\tt AuthDbmGroupFile} directive&gt; -->
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<strong>Syntax:</strong> AuthDBMGroupFile <em>filename</em><br>
b83ec1ad246d9827a68e9bb6ec2669908ab75d98Knut Anders Hatlen<Strong>Context:</strong> directory, .htaccess<br>
b83ec1ad246d9827a68e9bb6ec2669908ab75d98Knut Anders Hatlen<Strong>Override:</strong> AuthConfig<br>
013b5dd2cc9412960b4ebb2fcce23dc54c901a26Trond Norbye<strong>Status:</strong> Extension<br>
013b5dd2cc9412960b4ebb2fcce23dc54c901a26Trond Norbye<strong>Module:</strong> mod_auth_dbm<p>
a92ced6cf7126aca5fed821c5349a642196c67d9Trond Norbye
a92ced6cf7126aca5fed821c5349a642196c67d9Trond NorbyeThe AuthDBMGroupFile directive sets the name of a DBM file containing the list
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeof user groups for user authentication. <em>Filename</em> is the absolute path
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeto the group file.<p>
f9fd2b96d1c5ea62664f74da0e34a04b6511a8ffLubos Kosco
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeThe group file is keyed on the username. The value for a user is a
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyecomma-separated list of the groups to which the users belongs. There must
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyebe no whitespace within the value, and it must never contain any colons.<p>
b83ec1ad246d9827a68e9bb6ec2669908ab75d98Knut Anders Hatlen
a92ced6cf7126aca5fed821c5349a642196c67d9Trond NorbyeSecurity: make sure that the AuthDBMGroupFile is stored outside the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyedocument tree of the webserver; do <em>not</em> put it in the directory that
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeit protects. Otherwise, clients will be able to download the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeAuthDBMGroupFile unless otherwise protected.<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeCombining Group and Password DBM files: In some cases it is easier to
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyemanage a single database which contains both the password and group
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyedetails for each user. This simplifies any support programs that need
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Koscoto be written: they now only have to deal with writing to and locking
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyea single DBM file. This can be accomplished by first setting the group
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeand password files to point to the same DBM:<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<blockquote><code>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeAuthDBMGroupFile /www/userbase<br>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeAuthDBMUserFile /www/userbase
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</code></blockquote>
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Kosco
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos KoscoThe key for the single DBM is the username. The value consists of <p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<blockquote><code>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeUnix Crypted Password : List of Groups [ : (ignored) ]
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</code></blockquote>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos KoscoThe password section contains the Unix crypt() password as before. This is
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyefollowed by a colon and the comma separated list of groups. Other data may
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Koscooptionally be left in the DBM file after another colon; it is ignored by the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeauthentication module. This is what www.telescope.org uses for its combined
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyepassword and group database. <p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos KoscoSee also <A HREF="core.html#authname">AuthName</A>,
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Kosco<A HREF="core.html#authtype">AuthType</A> and
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Kosco<A HREF="#authdbmuserfile">AuthDBMUserFile</A>.<p><hr>
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Kosco
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<A name="authdbmuserfile"><h2>AuthDBMUserFile</h2></A>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<!--%plaintext &lt;?INDEX {\tt AuthDBMUserFile} directive&gt; -->
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<strong>Syntax:</strong> AuthDBMUserFile <em>filename</em><br>
f91fda86b928fae2fbfda0e5691e031cdd9c36e4Lubos Kosco<Strong>Context:</strong> directory, .htaccess<br>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<Strong>Override:</strong> AuthConfig<br>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<strong>Status:</strong> Extension<br>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<strong>Module:</strong> mod_auth_dbm<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeThe AuthDBMUserFile directive sets the name of a DBM file containing the list
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeof users and passwords for user authentication. <em>Filename</em> is the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeabsolute path to the user file.<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeThe user file is keyed on the username. The value for a user is the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyecrypt() encrypted password, optionally followed by a colon and
9ae950ef93f87449f6f6129445701ba24b4d337fKnut Anders Hatlenarbitrary data. The colon and the data following it will be ignored
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeby the server.<p>
9ae950ef93f87449f6f6129445701ba24b4d337fKnut Anders Hatlen
9ae950ef93f87449f6f6129445701ba24b4d337fKnut Anders HatlenSecurity: make sure that the AuthDBMUserFile is stored outside the
9ae950ef93f87449f6f6129445701ba24b4d337fKnut Anders Hatlendocument tree of the webserver; do <em>not</em> put it in the directory that
9ae950ef93f87449f6f6129445701ba24b4d337fKnut Anders Hatlenit protects. Otherwise, clients will be able to download the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeAuthDBMUserFile.<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeImportant compatibility note: The implementation of "dbmopen" in the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeapache modules reads the string length of the hashed values from the
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeDBM data structures, rather than relying upon the string being
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeNULL-appended. Some applications, such as the Netscape web server,
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyerely upon the string being NULL-appended, so if you are having trouble
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyeusing DBM files interchangeably between applications this may be a
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbyepart of the problem. <p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond NorbyeSee also <A HREF="core.html#authname">AuthName</A>,
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<A HREF="core.html#authtype">AuthType</A> and
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<A HREF="#authdbmgroupfile">AuthDBMGroupFile</A>.<p>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye<!--#include virtual="footer.html" -->
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</BODY>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye</HTML>
9be8460a4d4915ca1a46021adc07b75568cb47eaTrond Norbye
92e4fc35a05a3edc22484cf4f5f32de3efde4703Trond Norbye