note 40445 added to features.http-auth
| From: | rob at theblip dot com | Date: | Thu, 04 Mar 2004 01:47:25 +0000 |
| Subject: | note 40445 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-66216@lists.php.net to get a copy of this message | ||
Regarding HTTP authentication in IIS with the php cgi 4.3.4, there's one more step. I searched
mightily and didn't find this information anywhere else, so here goes. When using HTTP auth
with the php CGI, you need to do the following things:
1. In your php.ini file, set "cgi.rfc2616_headers = 0"
2. In Web Site Properties -> File/Directory Security -> Anonymous Access dialog box, check the
"Anonymous access" checkbox and uncheck any other checkboxes (i.e. uncheck "Basic
authentication," "Integrated Windows authentication," and "Digest" if
it's enabled.) Click OK.
3. In "Custom Errors", select the range of "401;1" through "401;5" and
click the "Set to Default" button.
It's this last step that is crucial, yet not documented anywhere. If you don't, instead of
the headers asking for credentials, IIS will return its own fancy but useless 'you are not
authenticated' page. But if you do, then the browser will properly ask for credentials, and
supply them in the $_SERVER['PHP_AUTH_*'] elements.
----
Manual Page -- http://www.php.net/manual/en/features.http-auth.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40445
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40445&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40445&report=yes
Search -- http://master.php.net/manage/user-notes.php