We run apache 2.0.52 on Fedora Core 3. After log out, the userid and password are stored in $PHP_AUTH_USER and $PHP_AUTH_PW, unless close the browser completely. It can be automatically relogin if click the login bottun again. So we have to set up login in twice to prevent illegal login. So how to unset $PHP_AUTH_USER and $PHP_AUTH_PW when logout, so user doesn't need to close the browser? Thanks, Max __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx