> It's all documented in Apache Doc. You need to use the following line in > you're .htaccess file so that passwords distinct from the system > database work: > > AuthPAM_Enabled Off > > > Otherwise regular system accounts are used. Does Apache2 switch back to uid 0 to read /etc/shadow ?? Just wondering. Igmar