Re: [tlug] apache mod_auth_digest

2) Is it a security problem to put the .htdigest file in the same
private directory? The httpd.conf contains the following lines, but I
don't know if that's enough:

I generally keep all such files outside of the URI space of the web
server. The last thing you want is web server to be serving up the

You could as you have mentioned tweak your config to "disallow" this.
However, I find keeping it out of the way in the first place easier.

Regards, Keith

