http://httpd.apache.org/docs/trunk/mod/mod_authn_core.html#authtype talks about "AuthType None", and has an awesome example of exactly what I need to do - unfortunately, it appears to be new to 2.3/2.4. Is there any equivalent feature in 2.2?
The authentication type None disables authentication. When authentication is enabled, it is normally inherited by each subsequent configuration section, unless a different authentication type is specified. If no authentication is desired for a subsection of an authenticated section, the authentication type None may be used; in the following example, clients may access the /www/docs/public directory without authenticating:
<Directory /www/docs> AuthType Basic AuthName Documents AuthBasicProvider file AuthUserFile /usr/local/apache/passwd/passwords Require valid-user </Directory> <Directory /www/docs/public> AuthType None Require all granted </Directory>
I think you are right: it is not supported in apache 2.2.
I would try the ugly workaround at https://issues.apache.org/bugzilla/show_bug.cgi?id=10932
Something like:
or
Something like below works for me with apache 2.2. I took it from http://httpd.apache.org/docs/2.2/mod/core.html#require
This worked for me on apache2.2:
You just need to set Allow from all and Satisfy Any
This worked for me:
Just wanted to add this bit of info:
On Apache 2.2.22 you need to have the order correct for it to work:
This did not work for me for location "/foo/sub":
I.e the authentication from the location "/foo" defined prior to "/foo/sub" still was applied.
This does work for location "/foo/sub":
I.e. the authentication from the location "/foo" defined prior to "/foo/sub" was annulled.
This will work