Morning, I want to use mod_auth for apache2 to restrict access to a directory on a website. I also want to use mod_rewrite to force such authentication to be over https. I have the following in dir/.htaccess: RewriteEngine On RewriteCond %{HTTPS} !^on$ RewriteRule ^(.*)$ https://%{HTTP_HOST}/dir/$1 AuthType Basic AuthName "private thingum" require user username However, what happens is that i'm prompted for the username and password before i'm redirected to ssl, which is useless. Is there any way i can get the rewrite to happen before the auth? Thanks, Steve --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx