Information Resources & Technology (IRT)

Securing Content With Basic Authentication

Important

Before adding or requesting password protection for your Web content, make sure you have read and understood the difference between access security and transaction security in our introduction to Password Protection for Your Site.

Basic Authentication creates a simple login-password pair for access to a secured Web directory. The advantage is that you can allow access by anyone you choose, with or without a SUNet ID. The disadvantage is that, in practice, this is usually a low-security method, only as good as the security of the method you use to share the login and password. Anything sent by email is not secure, for example.

You can improve your security when using this method by using a secure process to share the login and password (by phone, for example), and always using https:// when linking to and within the secured area.

You cannot install this kind of security yourself. To request BasicAuth, contact Web Help.

Specify:

Basic Authentication can be combined with Securing Content by Machine IP Address. If your users have SUNet IDs, Securing Content by SUNet ID is usually better.

Stanford Medicine Resources:

Footer Links: