Friday, June 13, 2008

Apache Security

When hosting an Apache web server for very concerned customers, authentication, authorization, and access control can all flood in the way. Some may even ask for host-based methods. Just keep in mind that Apache has its own way for them all, including where to write logs. Don't go mess with usual files like /etc/hosts, /etc/hosts.allow, /etc/hosts.deny, or /var/log/messages. Unless, of course, your boss told you to.

1 comment:

Unknown said...

You boss should have told you to use iptables.