s/key authentication for Apache on FreeBSD?

Brett Glass brett at lariat.org
Sat Dec 13 18:36:14 PST 2003


At 03:15 AM 12/11/2003, bruce at nikkel.com wrote:
  
>If the basic auth string was not included in an http request, the
>webserver would generate a error 401 (Unauthorized). Check out RFC 2617
>(HTTP Authentication: Basic and Digest Access Authentication).

True. But does it authenticate again? Or merely recognize that you're
the same person you were before and let you through?

--Brett



More information about the freebsd-security mailing list