<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Lighttpd setup a password protected directory (directories)</title> <atom:link href="http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: michiel</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-176684</link> <dc:creator>michiel</dc:creator> <pubDate>Thu, 08 Dec 2011 12:40:33 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-176684</guid> <description>Hi,
I got plain authorization working, but it seems there is a very long timeout before you have to enter login&amp;password again. Is there a way to set it to about 30 minutes or so?</description> <content:encoded><![CDATA[<p>Hi,</p><p>I got plain authorization working, but it seems there is a very long timeout before you have to enter login&amp;password again. Is there a way to set it to about 30 minutes or so?</p> ]]></content:encoded> </item> <item><title>By: przemek</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-171964</link> <dc:creator>przemek</dc:creator> <pubDate>Thu, 16 Jun 2011 07:22:55 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-171964</guid> <description>what is domain name? i got index.php as my website in ww folder and how i do domain name?</description> <content:encoded><![CDATA[<p>what is domain name? i got index.php as my website in ww folder and how i do domain name?</p> ]]></content:encoded> </item> <item><title>By: kurt krueckeberg</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-170475</link> <dc:creator>kurt krueckeberg</dc:creator> <pubDate>Tue, 05 Apr 2011 14:20:52 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-170475</guid> <description>Great article. The most helpful one I&#039;ve found.</description> <content:encoded><![CDATA[<p>Great article. The most helpful one I&#8217;ve found.</p> ]]></content:encoded> </item> <item><title>By: Chalai</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-155468</link> <dc:creator>Chalai</dc:creator> <pubDate>Fri, 30 Apr 2010 01:10:22 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-155468</guid> <description>Hi!
How to restrict access to a folder/subfolder only?
Using Apache I can restrict user access to a folder/subfolder only by setting a value for open_basedir and include_path, how do I do that with Lighttpd?</description> <content:encoded><![CDATA[<p>Hi!<br
/> How to restrict access to a folder/subfolder only?<br
/> Using Apache I can restrict user access to a folder/subfolder only by setting a value for open_basedir and include_path, how do I do that with Lighttpd?</p> ]]></content:encoded> </item> <item><title>By: mahal24</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-155036</link> <dc:creator>mahal24</dc:creator> <pubDate>Thu, 15 Apr 2010 06:02:54 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-155036</guid> <description>Can somebody please tell me if Lighttpd supports &quot;GROUP&quot; authentication and if it does  how do you configure it?  Thanks in advance!</description> <content:encoded><![CDATA[<p>Can somebody please tell me if Lighttpd supports &#8220;GROUP&#8221; authentication and if it does  how do you configure it?  Thanks in advance!</p> ]]></content:encoded> </item> <item><title>By: Tapas Mallick</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154582</link> <dc:creator>Tapas Mallick</dc:creator> <pubDate>Mon, 29 Mar 2010 09:53:22 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154582</guid> <description>I believe there should have a post on &quot;Access restriction based on IP/Subnet Address&quot; (like: order allow, deny; allow from 192.168.1.0/24; deny from all; directives normally used in apache)</description> <content:encoded><![CDATA[<p>I believe there should have a post on &#8220;Access restriction based on IP/Subnet Address&#8221; (like: order allow, deny; allow from 192.168.1.0/24; deny from all; directives normally used in apache)</p> ]]></content:encoded> </item> <item><title>By: lopes</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154024</link> <dc:creator>lopes</dc:creator> <pubDate>Mon, 01 Mar 2010 22:44:56 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154024</guid> <description>Hi!
How I can use the same password and user for two folder? How I can setup this?
Many thanks</description> <content:encoded><![CDATA[<p>Hi!</p><p>How I can use the same password and user for two folder? How I can setup this?</p><p>Many thanks</p> ]]></content:encoded> </item> <item><title>By: Lopes</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154023</link> <dc:creator>Lopes</dc:creator> <pubDate>Mon, 01 Mar 2010 22:33:08 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-154023</guid> <description>Thanks Vivek!
Just a question how can I protect two folders? Using same user and password?</description> <content:encoded><![CDATA[<p>Thanks Vivek!</p><p>Just a question how can I protect two folders? Using same user and password?</p> ]]></content:encoded> </item> <item><title>By: Charlie</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152749</link> <dc:creator>Charlie</dc:creator> <pubDate>Wed, 06 Jan 2010 17:38:18 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152749</guid> <description>Thanks, Vivek.
I looked the error.log file. The message are password mismatch. I figured out that the problem is with password file &quot;.pwd_Yuemeng&quot;.  One user without line feed at the end of line will make it work. However, for two users &quot;user=TEST&#124;user=TEST2&quot;, The password file have two lines, the first line with line feed, the second line without line feed. The first user cannot login, but second folder can login. Do you have any idea to deal with the line feed issue? Can some other symbol to put at the end of line to make it works?</description> <content:encoded><![CDATA[<p>Thanks, Vivek.<br
/> I looked the error.log file. The message are password mismatch. I figured out that the problem is with password file &#8220;.pwd_Yuemeng&#8221;.  One user without line feed at the end of line will make it work. However, for two users &#8220;user=TEST|user=TEST2&#8243;, The password file have two lines, the first line with line feed, the second line without line feed. The first user cannot login, but second folder can login. Do you have any idea to deal with the line feed issue? Can some other symbol to put at the end of line to make it works?</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152741</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Wed, 06 Jan 2010 07:59:34 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152741</guid> <description>Check error log and the following debug options and restart lighttpd:
auth.debug  = 2
Take a look at your error.log for detailed info.</description> <content:encoded><![CDATA[<p>Check error log and the following debug options and restart lighttpd:<br
/> auth.debug  = 2<br
/> Take a look at your error.log for detailed info.</p> ]]></content:encoded> </item> <item><title>By: Charlie</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152737</link> <dc:creator>Charlie</dc:creator> <pubDate>Wed, 06 Jan 2010 01:05:37 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-152737</guid> <description>Hi,
My web server is DNS-323 with fun_plug 0,5 and lighttpd
I have changed the lighttpd.conf to include the following:
&lt;pre&gt;server.modules              = (
&quot;mod_access&quot;,
&quot;mod_auth&quot;,
&quot;mod_fastcgi&quot;,
&quot;mod_accesslog&quot; )
server.document-root        = &quot;/mnt/HD_a2/www/pages/&quot;
$HTTP[&quot;url&quot;] =~ &quot;^/Yuemeng/&quot; {
auth.debug = 2
auth.backend = &quot;plain&quot;
auth.backend.plain.userfile = &quot;/mnt/HD_a2/www/pwd/.pwd_Yuemeng&quot;
auth.require = ( &quot;/Yuemeng/&quot; =&gt;
(
&quot;method&quot; =&gt; &quot;basic&quot;,
&quot;realm&quot; =&gt; &quot;Password protected area&quot;,
&quot;require&quot; =&gt; &quot;user=TEST&quot;
)
)
},&lt;/pre&gt;
Only one line in the file /mnt/HD_a2/www/pwd/.pwd_Yuemeng
TEST:xxyyzz
The &quot;Yuemeng&quot; is sub directory of  &quot;/mnt/HD_a2/www/pages/&quot;
after restart lighttpd, I do got popup window asking for username and password,
but entering the usename and passwod will not let me to got in the Yuemeng directory. after trying three times,  It give me &quot;401 - Unauthorized&quot;
I could not figure out what is wrong.
I do not know my server has SSL support or not, Do I need SSL to make it wroks?
Thanks.</description> <content:encoded><![CDATA[<p>Hi,<br
/> My web server is DNS-323 with fun_plug 0,5 and lighttpd<br
/> I have changed the lighttpd.conf to include the following:</p><pre>server.modules              = (
                                "mod_access",
                                "mod_auth",
                                "mod_fastcgi",
                                "mod_accesslog" )
server.document-root        = "/mnt/HD_a2/www/pages/"
$HTTP["url"] =~ "^/Yuemeng/" {
auth.debug = 2
auth.backend = "plain"
auth.backend.plain.userfile = "/mnt/HD_a2/www/pwd/.pwd_Yuemeng"
auth.require = ( "/Yuemeng/" =&gt;
 	(
	"method" =&gt; "basic",
	"realm" =&gt; "Password protected area",
	"require" =&gt; "user=TEST"
	)
   )
},</pre><p>Only one line in the file /mnt/HD_a2/www/pwd/.pwd_Yuemeng<br
/> TEST:xxyyzz</p><p>The &#8220;Yuemeng&#8221; is sub directory of  &#8220;/mnt/HD_a2/www/pages/&#8221;</p><p>after restart lighttpd, I do got popup window asking for username and password,<br
/> but entering the usename and passwod will not let me to got in the Yuemeng directory. after trying three times,  It give me &#8220;401 &#8211; Unauthorized&#8221;</p><p>I could not figure out what is wrong.</p><p>I do not know my server has SSL support or not, Do I need SSL to make it wroks?</p><p>Thanks.</p> ]]></content:encoded> </item> <item><title>By: Pep</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-150533</link> <dc:creator>Pep</dc:creator> <pubDate>Sat, 05 Sep 2009 09:15:16 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-150533</guid> <description>Hi,
I followed this how-to. I get it to state, when it says no errors. But authentification still doesn`t work. I would like to describe it more in detail but all I can say is: no errors; web works as before setting authentification; but webpage doesn`t require any username and password. I`ve restarted OpenWRT, which maked no difference.
Thank you for help.</description> <content:encoded><![CDATA[<p>Hi,<br
/> I followed this how-to. I get it to state, when it says no errors. But authentification still doesn`t work. I would like to describe it more in detail but all I can say is: no errors; web works as before setting authentification; but webpage doesn`t require any username and password. I`ve restarted OpenWRT, which maked no difference.<br
/> Thank you for help.</p> ]]></content:encoded> </item> <item><title>By: Clive</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148924</link> <dc:creator>Clive</dc:creator> <pubDate>Thu, 11 Jun 2009 22:59:05 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148924</guid> <description>yeah thats the second time that has been suggested to me, I should really have said I&#039;ve already looked at mod_secure_download. The php app has to be written to make use of it so it&#039;s not an option. I was hoping for a solution by the webserver only, something to put in the lighttpd.conf file to achieve this but its looking like it isnt possible :(</description> <content:encoded><![CDATA[<p>yeah thats the second time that has been suggested to me, I should really have said I&#8217;ve already looked at mod_secure_download. The php app has to be written to make use of it so it&#8217;s not an option. I was hoping for a solution by the webserver only, something to put in the lighttpd.conf file to achieve this but its looking like it isnt possible :(</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148921</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Thu, 11 Jun 2009 19:53:18 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148921</guid> <description>Try &lt;a href=&quot;http://www.cyberciti.biz/tips/lighttpd-mod_secdownload-configuration.html&quot; rel=&quot;nofollow&quot;&gt;mod_secdownload&lt;/a&gt;.</description> <content:encoded><![CDATA[<p>Try <a
href="http://www.cyberciti.biz/tips/lighttpd-mod_secdownload-configuration.html" rel="nofollow">mod_secdownload</a>.</p> ]]></content:encoded> </item> <item><title>By: Clive</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148920</link> <dc:creator>Clive</dc:creator> <pubDate>Thu, 11 Jun 2009 19:51:21 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-148920</guid> <description>Hi,
I&#039;m just wondering if password protection is the answer to my problem. I want to only allow files to be downloaded via pages on my website and nowhere else, I can stop hotlinking from other sites with the following:
$HTTP[&quot;referer&quot;] !~ &quot;^($&#124;http://www\.mydomain\.com)&quot; {
url.access-deny = ( &quot;.mp3&quot;, &quot;.zip&quot; )
}
But that doesnt prevent people from typing the url of a file directly into the browser, they can still download it that way. Is there any other way to prevent this? I&#039;d prefer to just have a 403 forbidden to appear if a file is accessed directly or from another site, but I cant find a solution anywhere so I may consider using a password protected directory.</description> <content:encoded><![CDATA[<p>Hi,</p><p>I&#8217;m just wondering if password protection is the answer to my problem. I want to only allow files to be downloaded via pages on my website and nowhere else, I can stop hotlinking from other sites with the following:</p><p>$HTTP["referer"] !~ &#8220;^($|http://www\.mydomain\.com)&#8221; {<br
/> url.access-deny = ( &#8220;.mp3&#8243;, &#8220;.zip&#8221; )<br
/> }</p><p>But that doesnt prevent people from typing the url of a file directly into the browser, they can still download it that way. Is there any other way to prevent this? I&#8217;d prefer to just have a 403 forbidden to appear if a file is accessed directly or from another site, but I cant find a solution anywhere so I may consider using a password protected directory.</p> ]]></content:encoded> </item> <item><title>By: Marcus</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-147824</link> <dc:creator>Marcus</dc:creator> <pubDate>Tue, 24 Mar 2009 15:28:13 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-147824</guid> <description>Along the lines of what Paul posted, I&#039;m trying to password protect a directory for multiple users.  You posted that you should simply append a new user to the end of the /etc/lighttpd/lighttpd.conf file, but I&#039;m confused about the formatting.  Should it look like:
&lt;code&gt;
auth.require = ( &quot;/media/&quot; =&gt;
(
&quot;method&quot; =&gt; &quot;basic&quot;,
&quot;realm&quot; =&gt; &quot;Media&quot;,
&quot;require&quot; =&gt; &quot;user=user1&quot;
&quot;require&quot; =&gt; &quot;user=user2&quot;
)
&lt;/code&gt;
Or should it look like:
&lt;code&gt;
auth.require = ( &quot;/media/&quot; =&gt;
(
&quot;method&quot; =&gt; &quot;basic&quot;,
&quot;realm&quot; =&gt; &quot;Media&quot;,
&quot;require&quot; =&gt; &quot;user=user1&#124;user=user2&quot;
)
&lt;/code&gt;
?
Also, what should the password file look like in order to do this?  Thanks!</description> <content:encoded><![CDATA[<p>Along the lines of what Paul posted, I&#8217;m trying to password protect a directory for multiple users.  You posted that you should simply append a new user to the end of the /etc/lighttpd/lighttpd.conf file, but I&#8217;m confused about the formatting.  Should it look like:</p><p><code><br
/> auth.require = ( "/media/" =&gt;<br
/> (<br
/> "method" =&gt; "basic",<br
/> "realm" =&gt; "Media",<br
/> "require" =&gt; "user=user1"<br
/> "require" =&gt; "user=user2"<br
/> )<br
/> </code><br
/> Or should it look like:<br
/> <code><br
/> auth.require = ( "/media/" =&gt;<br
/> (<br
/> "method" =&gt; "basic",<br
/> "realm" =&gt; "Media",<br
/> "require" =&gt; "user=user1|user=user2"<br
/> )<br
/> </code><br
/> ?</p><p>Also, what should the password file look like in order to do this?  Thanks!</p> ]]></content:encoded> </item> <item><title>By: yannick coulombe</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-147520</link> <dc:creator>yannick coulombe</dc:creator> <pubDate>Tue, 03 Mar 2009 15:51:08 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-147520</guid> <description>Thanks,
without having to do some more google searches !!</description> <content:encoded><![CDATA[<p>Thanks,</p><p>without having to do some more google searches !!</p> ]]></content:encoded> </item> <item><title>By: dikshie</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-146868</link> <dc:creator>dikshie</dc:creator> <pubDate>Sat, 24 Jan 2009 15:07:06 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-146868</guid> <description>hi,
i just migrate apache to lighttpd. i found i can not find easy and straightforward way
to enable auth for every users since all my users has .htpassword in public_html
any straightforward way to enable auth for every /home/$user/public_html/ ?
thanks!</description> <content:encoded><![CDATA[<p>hi,<br
/> i just migrate apache to lighttpd. i found i can not find easy and straightforward way<br
/> to enable auth for every users since all my users has .htpassword in public_html<br
/> any straightforward way to enable auth for every /home/$user/public_html/ ?</p><p>thanks!</p> ]]></content:encoded> </item> <item><title>By: mad</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-146359</link> <dc:creator>mad</dc:creator> <pubDate>Sat, 20 Dec 2008 20:28:13 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-146359</guid> <description>Hi,
how can I password protect main folder (server.document-root=/usr/local/www)
Thanks.</description> <content:encoded><![CDATA[<p>Hi,</p><p>how can I password protect main folder (server.document-root=/usr/local/www)</p><p>Thanks.</p> ]]></content:encoded> </item> <item><title>By: DanielS</title><link>http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-145021</link> <dc:creator>DanielS</dc:creator> <pubDate>Wed, 17 Sep 2008 05:32:14 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/lighttpd-setup-a-password-protected-directory-directories.html#comment-145021</guid> <description>Just a quick note as far as step one, a simple command would be &lt;code&gt;lighty-enable-mod auth&lt;/code&gt;
Otherwise Great Post! Thanks!</description> <content:encoded><![CDATA[<p>Just a quick note as far as step one, a simple command would be <code>lighty-enable-mod auth</code><br
/> Otherwise Great Post! Thanks!</p> ]]></content:encoded> </item> </channel> </rss>
