Apache Authentication - ApacheCon 2005
Digest
  • Username/Password never sent to the server

  • MD5 hash of name, password, realm

  • MD5 is a one-way hashing algorithm

  • Password never stored anywhere in a readable format, and never passed across the network at all.

Index
Back to Caveats
Forward to Configuration

ApacheCon 2005 : Apache Authentication - Slide #21 of 45