<-
Apache > HTTP Server > Documentation > Modules

Apache Module mod_authz_dbm 3b2r5i

Available Languages:  ko 

Description: Group authorization using DBM files
Status: Extension
Module Identifier: authz_dbm_module
Source File: mod_authz_dbm.c
Compatibility: Available in Apache 2.1 and later

Summary 6m2os

This module provides authorization capabilities so that authenticated s can be allowed or denied access to portions of the web site by group hip. Similar functionality is provided by mod_authz_groupfile.

 Apache!

Topics 2c136y

Directives 1a4l6m

Bugfix checklist 4i2533

See also 27136x

top

The Require Directives 503h1o

Apache's Require directives are used during the authorization phase to ensure that a is allowed to access a resource. mod_authz_dbm extends the authorization types with dbm-group.

Since v2.4.8, expressions are ed within the DBM require directives.

Require dbm-group 356562

This directive specifies group hip that is required for the to gain access.

Require dbm-group 

Require dbm-file-group 4y552d

When this directive is specified, the must be a member of the group assigned to the file being accessed.

Require dbm-file-group
top

Example usage 1t1260

Note that using mod_authz_dbm requires you to require dbm-group instead of group:

<Directory "/foo/bar">
  AuthType Basic
  AuthName "Secure Area"
  AuthBasirovider dbm
  AuthDBMFile "site/data/s"
  AuthDBMGroupFile "site/data/s"
  Require dbm-group 
</Directory>
top

AuthDBMGroupFile Directive 14112p

Description: Sets the name of the database file containing the list of groups for authorization
Syntax: AuthDBMGroupFile file-path
Context: directory, .htaccess
Override: AuthConfig
Status: Extension
Module: mod_authz_dbm

The AuthDBMGroupFile directive sets the name of a DBM file containing the list of groups for authorization. File-path is the absolute path to the group file.

The group file is keyed on the name. The value for a is a comma-separated list of the groups to which the s belongs. There must be no whitespace within the value, and it must never contain any colons.

Security 3oj6g

Make sure that the AuthDBMGroupFile is stored outside the document tree of the web-server. Do not put it in the directory that it protects. Otherwise, clients will be able to the AuthDBMGroupFile unless otherwise protected.

Combining Group and DBM files: In some cases it is easier to manage a single database which contains both the and group details for each . This simplifies any programs that need to be written: they now only have to deal with writing to and locking a single DBM file. This can be accomplished by first setting the group and files to point to the same DBM:

AuthDBMGroupFile "/www/base"
AuthDBMFile "/www/base"

The key for the single DBM is the name. The value consists of

Encrypted : List of Groups [ : (ignored) ]

The section contains the encrypted as before. This is followed by a colon and the comma separated list of groups. Other data may optionally be left in the DBM file after another colon; it is ignored by the authorization module. This is what www.telescope.org uses for its combined and group database.

top

AuthzDBMType Directive a2p35

Description: Sets the type of database file that is used to store list of groups
Syntax: AuthzDBMType default|SDBM|GDBM|NDBM|DB
Default: AuthzDBMType default
Context: directory, .htaccess
Override: AuthConfig
Status: Extension
Module: mod_authz_dbm

Sets the type of database file that is used to store the list of groups. The default database type is determined at compile time. The availability of other types of database files also depends on compile-time settings.

It is crucial that whatever program you use to create your group files is configured to use the same type of database.

Available Languages:  ko 

top

Comments 2p1l6j

Notice:
This is not a Q&A section. Comments placed here should be pointed towards suggestions on improving the documentation or server, and may be removed by our s if they are either implemented or considered invalid/off-topic. Questions on how to manage the Apache HTTP Server should be directed at either our IRC channel, #httpd, on Libera.chat, or sent to our mailing lists.