Information Services Talk
Information Services Talk
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Apache FakeBasicAuth problem

 
Post new topic   Reply to topic    Information Services Talk Forum Index -> Information Services Talk
View previous topic :: View next topic  
Author Message
Guest






PostPosted: Thu Sep 27, 2007 8:49 pm    Post subject: Apache FakeBasicAuth problem Reply with quote

I was used to use FakeBasicAuth in Apache 2.0.59, and I have a problem
to use it in 2.2.4, with the same config (see bottom of message).

I always get now 'user /...: authentication failure for "/path/":
Password Mismatch'.

In the debug log, I can find:
Faking HTTP Basic Auth header: "Authorization: Basic {DN:passwordn
base64}"


Thanks

Nick

SSLVerifyClient require
<Location "/">
SSLRequireSSL
SSLOptions +FakeBasicAuth
Authname "MyApp"
AuthType Basic
AuthUserFile conf/users.auth
Require valid-user
</Location>

user.auth (DN coming from OpenSSL):
/...:xxj31ZMTZzkVA
Back to top
  Ads
Advertising
Sponsor


Guest






PostPosted: Fri Sep 28, 2007 11:00 am    Post subject: Re: Apache FakeBasicAuth problem Reply with quote

Additional info: I also tried without FakeBasicAuth, to have the
interactive password box, and with another user 'frank' and the
password 'sinatra'.
Depending on my password file, I get the following errors:
- frank:mlVo7KaArYZhg
-> dialog box -> frank/sinatra
-> user frank: authentication failure: Password Mismatch
- frank:$apr1$9U1.....$C.5OJhZ4UxxM9SIzv4XAY0
-> no dialog box
-> configuration error: couldn't check access. No groups file?
- frank:{SHA}7DUut/wAuxmp4mKiKKNr9eEUeG0=
-> no dialog box
-> configuration error: couldn't check access. No groups file?
So, MD5 & SHA-1 are not supported.

With FakeBasicAuth, I get exactly the same password error:
user /C=BE/ST=Belgium/...: authentication failure: Password Mismatch

It seems that the CRYPT algorithm that is used is not compatible with
the previous versions !?!
When I try 'htpasswd.exe -nbd', it responds 'Automatically using MD5
format'.
I use Windows with OpenSSL 0.9.8e.

Quote:
SSLVerifyClient require
Location "/"
SSLRequireSSL
SSLOptions +FakeBasicAuth
Authname "MyApp"
AuthType Basic
AuthUserFile conf/users.auth
Require valid-user
/Location
Back to top
  Ads
Advertising
Sponsor


Guest






PostPosted: Fri Sep 28, 2007 11:01 am    Post subject: Re: Apache FakeBasicAuth problem Reply with quote

And I have the same on Linux (2.2.6) :-(

Quote:
I get the following errors:
- frank:mlVo7KaArYZhg
-> dialog box -> frank/sinatra
-> user frank: authentication failure: Password Mismatch

Location "/"
Authname "MyApp"
AuthType Basic
AuthUserFile conf/users.auth
Require valid-user
/Location
Back to top
  Ads
Advertising
Sponsor


Display posts from previous:   
Post new topic   Reply to topic    Information Services Talk Forum Index -> Information Services Talk All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Board Security

80 Attacks blocked

Powered by phpBB © 2001, 2005 phpBB Group