You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在IIS 10(Windows Server 2019)+PHP7.3环境下htpasswd无法使用的问题

IIS 10 中.htpasswd不生效的原因及本地用户基础认证方案

Great question! Let's break this down clearly since IIS and Apache have fundamentally different authentication systems, even if URL Rewrite makes .htaccess work for rewrites.

为什么.htaccess正常但.htpasswd不生效?

The core issue here is that IIS doesn't natively recognize .htpasswd files—that's an Apache-specific standard. The URL Rewrite module you're using lets IIS parse rewrite rules from .htaccess, but it only handles rewrite-related directives (like RewriteRule or RewriteCond). It has no support for Apache's authentication directives like AuthUserFile or AuthType, which is why your .htpasswd settings are being ignored entirely.

To put it simply: .htaccess support in IIS is limited to rewrite logic, not the full suite of Apache configuration directives.

如何用本地Windows用户实现基础认证?

Yes, you absolutely can use local Server 2019 users to set up basic authentication in IIS. Here's a step-by-step guide:

1. Enable the Basic Authentication module

  • Open IIS Manager, navigate to your target site.
  • In the Features View, double-click the Authentication icon.
  • Right-click Basic Authentication and select Enable.

    Important: Basic Authentication sends credentials in plaintext, so always pair this with HTTPS to secure the connection.

2. Configure folder/site permissions for local users

  • Right-click your site (or the specific directory you want to protect) and select Edit Permissions.
  • Go to the Security tab, click Edit → Add.
  • Type in the name of your local Windows user (e.g., .\LocalUser1 where . represents the local machine) and click Check Names to confirm it exists.
  • Grant the user appropriate permissions (usually Read is sufficient for web content).
  • Remove any unnecessary groups/users (like Everyone) to lock down access.

3. Target specific directories with web.config (optional)

If you want to protect only a subdirectory (instead of the entire site), you can use a web.config file to override settings for that path—this is IIS's equivalent to directory-specific .htaccess rules:

<location path="path/to/protected/folder">
  <system.webServer>
    <security>
      <authentication>
        <anonymousAuthentication enabled="false" />
        <basicAuthentication enabled="true" />
      </authentication>
    </security>
  </system.webServer>
</location>

Save this in your site's root web.config, and IIS will enforce basic authentication only for the specified folder.

4. Test the setup

Restart your IIS site, then try accessing the protected content. You'll see a browser login prompt—enter the local user's username and password, and you should gain access if everything is configured correctly.

内容的提问来源于stack exchange,提问作者Michael Mittermair

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:01:54