On Nov 8, 2007 6:38 PM, Grant Peel <gpeel@xxxxxxxxxxxxx> wrote: > Hi all, > > I have a security company hounding me to turn of HTDigest. > > Any idea how? If they think it is so important, why not ask them? Or are they just following some set of inflexible rules that even they don't really understand? Anyway, htdigest is a simple support utility that comes with apache. As long as it isn't suid or called directly from the web, it poses absolutely no security hazard. But if you want to "turn it off", find it on your hard disk and remove it. Joshua. --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx