Apache http auth
-
We have a staging linux server which is managed with cPanel and hosts around 30-60 accounts per month based on our projects. All sites are protected with http auth and using a common password. On a regular basis, 2-3 months or so, we change the password inform the team and they notify the clients as well.
Looking for an alternate method by which this can get automated, best if each site could have individual http auth which keeps it more secure than a blanket all site password. I am checking for option by which the team can use something like google authenticator from their mobile devices to get the new credentials, but couldn't figure out if this is possible and the admin control which devices can get access with Google Authenticator or such
-
This looks interesting https://github.com/archiecobbs/mod-authn-otp
Need to test and see how this works and how does it give the users option to see the OTP