On Thu, Aug 20, 2009 at 11:35 AM, Melanie Pfefer<melanie_pfefer@xxxxxxxxxxx> wrote: > Do you think this is caused Location directive used for a location and a sublocation? > > I tested on a fresh apache. The <directory> directive works as expected (i.e. only user1, user2 and user3 can access bbb/) (But still I am prompted for password even if I do not access bbb/): You still get prompted under aaa/ because "valid-user" means any user who has authenticated is authorized -- it does not skip the authentication phase. -- Eric Covener covener@xxxxxxxxx --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx