note 43322 added to features.http-auth
| From: | chris at schaake dot nu | Date: | Thu, 17 Jun 2004 13:42:26 +0000 |
| Subject: | note 43322 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-71227@lists.php.net to get a copy of this message | ||
A simple script for SSL Client Certificate authentication with a basic authentication fall-back. I
use this on my site using LDAP server to check username/passwords and client certificate to user
mapping.
<?
// Check if and how we are authenticated
if ($_SERVER['SSL_CLIENT_VERIFY'] != "SUCCESS") { // Not using a client
certificate
if ((!$_SERVER['PHP_AUTH_USER']) && (!$_SERVER['PHP_AUTH_PW'])) { //
Not logged in using basic authentication
authenticate(); // Send basic authentication headers
}
}
if ($_SERVER['SSL_CLIENT_S_DN_CN'] != "chris") { // Check CN name of cert
if (!(($_SERVER['PHP_AUTH_USER'] == "test") &&
($_SERVER['PHP_AUTH_PW'] == "123"))) { // Check username and password
authenticate(); // Send basic authentication headers because username and/or password didnot match
}
}
phpinfo();
// Call authentication display
function authenticate() {
Header("WWW-Authenticate: Basic realm=Website");
Header("HTTP/1.0 401 Unauthorized");
error401();
exit;
}
?>
See my website (http://www.schaake.nu/index.php?page=/manuals/sslmanual.xml) for more details on
client certificate with Apache and PHP.
----
Manual Page -- http://www.php.net/manual/en/features.http-auth.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43322
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43322&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43322&report=yes
Search -- http://master.php.net/manage/user-notes.php