You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@httpd.apache.org by Jean-Pierre Bergamin <ja...@ractive.ch> on 2011/01/27 14:34:49 UTC

[users@httpd] Reverse proxy with digest auth to a webapp with basic auth

Hello everyone

We are using apache's mod_proxy (reverse proxy) to make two internal 
webapps available over the internet. It works fine so far.

We now tried to use digest authentication on the proxy to secure the 
access to the proxy itself. One webapp has no problem with that 
approach. You first have to enter the username and passwort of the 
digest auth of the proxy and then you can access the webapp and login 
there as usual.

The other application though is using basic auth - which does not work. 
You first have to enter the username and passwort of the proxy - good. 
Then you have to enter the username and password of the app. Now the 
browser falls into an infinte loop, where it sends always just the 
authentication of the proxy digest auth and gets back a 401 from the 
webapp behind the proxy, because this one does not expect the digest 
auth, but the basic auth.

Is there any "pattern" how digest and/or basic auth can be used for the 
reverse proxy itself and for the proxied webapp?


Best regards,
James


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org