blob: 00ba9a04c6d3eaa20a1d24659ba35005f9b2877b [file] [log] [blame]
<?xml version="1.0" encoding="EUC-KR" ?>
<!DOCTYPE modulesynopsis SYSTEM "../style/modulesynopsis.dtd">
<?xml-stylesheet type="text/xsl" href="../style/manual.ko.xsl"?>
<!-- English Revision: 1.10 -->
<!--
Copyright 2004 The Apache Software Foundation
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<modulesynopsis metafile="mod_authz_host.xml.meta">
<name>mod_authz_host</name>
<description>È£½ºÆ® (À̸§À̳ª IP ÁÖ¼Ò)¸¦ »ç¿ëÇÑ ±×·ì ±ÇÇѺο©</description>
<status>Base</status>
<sourcefile>mod_authz_host.c</sourcefile>
<identifier>authz_host_module</identifier>
<compatibility>¾ÆÆÄÄ¡ 2.1 ÀÌÈĺÎÅÍ</compatibility>
<summary>
<p><directive module="core" type="section">Directory</directive>,
<directive module="core" type="section">Files</directive>,
<directive module="core" type="section">Location</directive>
¼½¼Ç°ú <code><a href="core.html#accessfilename">.htaccess</a></code>
ÆÄÀÏ¿¡¼­ ¼­¹öÀÇ Æ¯Á¤ ºÎºÐÀÇ Á¢±ÙÀ» Á¦¾îÇϱâÀ§ÇØ
<module>mod_authz_host</module>°¡ Á¦°øÇÏ´Â Áö½Ã¾î¸¦ »ç¿ëÇÑ´Ù.
Ŭ¶óÀ̾ðÆ®ÀÇ È£½ºÆ®¸í, IP ÁÖ¼Ò, <a
href="../env.html">ȯ°æº¯¼ö</a>¿¡ ±â·ÏµÈ ¿äûÀÇ Æ¯¼º¿¡ µû¶ó
Á¢±ÙÀ» Á¦¾îÇÑ´Ù. <directive
module="mod_authz_host">Allow</directive>¿Í <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î´Â ¾î¶²
Ŭ¶óÀ̾ðÆ®°¡ ¼­¹ö¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´ÂÁö¸¦ Áö½ÃÇÏ°í, <directive
module="mod_authz_host">Order</directive> Áö½Ã¾î´Â ±âº»ÀûÀ¸·Î
Á¢±ÙÀ» Çã¿ëÇÒÁö °ÅºÎÇÒÁö ¿©ºÎ¿Í ¾î¶»°Ô <directive
module="mod_authz_host">Allow</directive> Áö½Ã¾î¿Í <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î°¡ ¼­·Î ¿µÇâÀ»
¹ÌÄ¡´ÂÁö °áÁ¤ÇÑ´Ù.</p>
<p>È£½ºÆ®±â¹Ý Á¢±ÙÁ¦ÇÑ°ú ¾ÏÈ£±â¹Ý ÀÎÁõÀ» µ¿½Ã¿¡ »ç¿ëÇÒ ¼öµµ
ÀÖ´Ù. ÀÌ °æ¿ì <directive module="core">Satisfy</directive>
Áö½Ã¾î¸¦ »ç¿ëÇÏ¿© ¾î¶»°Ô µÎ Á¦ÇÑÀÌ ¼­·Î ¿µÇâÀ» ¹ÌÄ¡´ÂÁö
°áÁ¤ÇÑ´Ù.</p>
<p>ÀϹÝÀûÀ¸·Î Á¢±ÙÁ¦ÇÑ Áö½Ã¾î´Â (<code>GET</code>,
<code>PUT</code>, <code>POST</code> µî) ¸ðµç ¸Þ¼­µå¿¡ Àû¿ëµÇ¸ç,
ÀÌ ÇൿÀº ´ëºÎºÐÀÇ °æ¿ì ¹Ù¶÷Á÷ÇÏ´Ù. ±×·¯³ª <directive
module="core" type="section">Limit</directive> ¼½¼Ç¾È¿¡
Áö½Ã¾î¸¦ »ç¿ëÇÏ¿© ƯÁ¤ ¸Þ¼­µå¿¡¸¸ Á¦ÇÑÇÒ ¼ö ÀÖ´Ù.</p>
</summary>
<seealso><directive module="core">Satisfy</directive></seealso>
<seealso><directive module="core">Require</directive></seealso>
<directivesynopsis>
<name>Allow</name>
<description>¼­¹öÀÇ ÀϺο¡ Á¢±ÙÇÒ ¼ö Àִ ȣ½ºÆ®¸¦ ÁöÁ¤ÇÑ´Ù</description>
<syntax> Allow from all|<var>host</var>|env=<var>env-variable</var>
[<var>host</var>|env=<var>env-variable</var>] ...</syntax>
<contextlist><context>directory</context><context>.htaccess</context>
</contextlist>
<override>Limit</override>
<usage>
<p><directive>Allow</directive> Áö½Ã¾î´Â ¾î¶² È£½ºÆ®°¡ ¼­¹öÀÇ
ÀϺο¡ Á¢±ÙÇÒ ¼ö ÀÖ´ÂÁö Áö½ÃÇÑ´Ù. È£½ºÆ®¸í, IP ÁÖ¼Ò, IP
ÁÖ¼Ò¿µ¿ª, ȯ°æº¯¼ö¿¡ ±â·ÏµÈ ´Ù¸¥ Ư¼º¿¡ µû¶ó Á¢±ÙÀ» Á¶ÀýÇÒ
¼ö ÀÖ´Ù.</p>
<p>ÀÌ Áö½Ã¾îÀÇ Ã¹¹ø° ¾Æ±Ô¸ÕÆ®´Â Ç×»ó <code>from</code>ÀÌ´Ù.
´ÙÀ½ ¾Æ±Ô¸ÕÆ®¿¡´Â ¼¼°¡Áö Çü½ÄÀÌ ÀÖ´Ù. <code>Allow from all</code>À»
»ç¿ëÇϸé, ¾Æ·¡¿¡¼­ ¼³¸íÇÒ <directive
module="mod_authz_host">Deny</directive>¿Í <directive
module="mod_authz_host">Order</directive> Áö½Ã¾î ¼³Á¤¿¡
µû¶ó ¸ðµç È£½ºÆ®ÀÇ Á¢±ÙÀ» Çã°¡ÇÑ´Ù. ƯÁ¤ È£½ºÆ®¸¸ ¼­¹ö·Î
Á¢±ÙÀ» Çã¿ëÇÏ·Á¸é ´ÙÀ½°ú °°Àº Çü½ÄÀ¸·Î <em>host</em>¸¦ Áö½ÃÇÒ
¼ö ÀÖ´Ù:</p>
<dl>
<dt>È£½ºÆ®¸í (ÀϺÎ)</dt>
<dd>
<example><title>¿¹Á¦:</title>
Allow from apache.org
</example>
<p>È£½ºÆ®¸íÀÌ ÀÌ ¹®ÀÚ¿­°ú °°°Å³ª ÀÌ ¹®ÀÚ¿­·Î ³¡³ª¸é Á¢±ÙÀ»
Çã¿ëÇÑ´Ù. ±×·¡¼­ ÀÌ °æ¿ì <code>foo.apache.org</code>´Â
ÇØ´çµÇ°í, <code>fooapache.org</code>´Â ÇØ´çµÇÁö ¾Ê´Â´Ù.
ÀÌ ¼³Á¤À» »ç¿ëÇÏ¸é ¾ÆÆÄÄ¡´Â <directive
module="core">HostnameLookups</directive> Áö½Ã¾î ¼³Á¤°ú
°ü°è¾øÀÌ Å¬¶óÀ̾ðÆ® IP ÁÖ¼Ò¸¦ °¡Áö°í Áߺ¹-¿ª DNS °Ë»öÀ»
ÇÑ´Ù. Áï, È£½ºÆ®¸íÀ» ã±âÀ§ÇØ IP ÁÖ¼Ò¸¦ ¿ªDNS °Ë»öÀ» ÇÑ
ÈÄ, ´Ù½Ã È£½ºÆ®¸íÀ¸·Î °Ë»öÇÏ¿© ¿ø·¡ IP ÁÖ¼Ò¿Í ÀÏÄ¡ÇÏ´ÂÁö
È®ÀÎÇÑ´Ù. °á°ú°¡ °°°í È£½ºÆ®¸íÀÌ ¼³Á¤°ª¿¡ ÇØ´çÇϸé, Á¢±ÙÀ»
Çã¿ëÇÑ´Ù.</p></dd>
<dt>IP ÁÖ¼Ò Àüü</dt>
<dd>
<example><title>¿¹Á¦:</title>
Allow from 10.1.2.3
</example>
<p>Á¢±ÙÀ» Çã°¡Çϴ ȣ½ºÆ®ÀÇ IP ÁÖ¼Ò</p></dd>
<dt>IP ÁÖ¼Ò ÀϺÎ</dt>
<dd>
<example><title>¿¹Á¦:</title>
Allow from 10.1
</example>
<p>¼­ºê³×Æ®¿öÅ©·Î Á¦ÇÑÇϱâÀ§ÇØ IP ÁÖ¼Ò ¾ÕÀÇ 1¿¡¼­ 3
¹ÙÀÌÆ®.</p></dd>
<dt>³×Æ®¿öÅ©/³Ý¸Å½ºÅ© ½Ö</dt>
<dd>
<example><title>¿¹Á¦:</title>
Allow from 10.1.0.0/255.255.0.0
</example>
<p>³×Æ®¿öÅ© a.b.c.d¿Í ³Ý¸Å½ºÅ© w.x.y.z. ´õ ¼¼¹ÐÇÏ°Ô
¼­ºê³×Æ®¿öÅ©·Î Á¦ÇÑÇÒ¶§ »ç¿ëÇÑ´Ù.</p></dd>
<dt>³×Æ®¿öÅ©/nnn CIDR ±Ô¾à</dt>
<dd>
<example><title>¿¹Á¦:</title>
Allow from 10.1.0.0/16
</example>
<p>¾ÕÀÇ °æ¿ì¿Í °°Áö¸¸, »óÀ§ nnn°³ ºñÆ® °ªÀÌ 1ÀÎ ³Ý¸Å½ºÅ©¸¦
»ç¿ëÇÑ´Ù.</p></dd>
</dl>
<p>¸¶Áö¸· ¼¼°¡Áö ¿¹´Â Á¤È®È÷ µ¿ÀÏÇÑ È£½ºÆ®µéÀ» ÁöĪÇÑ´Ù.</p>
<p>´ÙÀ½°ú °°ÀÌ IPv6 ÁÖ¼Ò¿Í IPv6 ¼­ºê³×Æ®¿öÅ©¸¦ ÁöÁ¤ÇÒ ¼öµµ
ÀÖ´Ù:</p>
<example>
Allow from fe80::a00:20ff:fea7:ccea<br />
Allow from fe80::a00:20ff:fea7:ccea/10
</example>
<p><directive>Allow</directive> Áö½Ã¾î ¾Æ±Ô¸ÕÆ®ÀÇ ¼¼¹ø°
Çü½ÄÀº <a href="../env.html">ȯ°æº¯¼ö</a> À¯¹«¿¡ µû¶ó Á¢±ÙÀ»
Á¦¾îÇÑ´Ù. <code>Allow from env=<var>env-variable</var></code>À»
»ç¿ëÇϸé, <var>env-variable</var> ȯ°æº¯¼ö°¡ Á¤ÀÇµÈ °æ¿ì
Á¢±ÙÀ» Çã°¡ÇÑ´Ù. <module>mod_setenvif</module>°¡ Á¦°øÇÏ´Â
Áö½Ã¾î¸¦ »ç¿ëÇÏ¿© Ŭ¶óÀ̾ðÆ® ¿äûÀÇ Æ¯¼º¿¡ µû¶ó ÀÚÀ¯·Ó°Ô
ȯ°æº¯¼ö¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù. ±×·¯¹Ç·Î ÀÌ Áö½Ã¾î¸¦ »ç¿ëÇÏ¿©
Ŭ¶óÀ̾ðÆ® <code>User-Agent</code> (ºê¶ó¿ìÀú Á¾·ù),
<code>Referer</code>, ´Ù¸¥ HTTP ¿äû Çì´õ¿¡ µû¶ó Á¢±ÙÀ»
Çã°¡ÇÒ ¼ö ÀÖ´Ù.</p>
<example><title>¿¹Á¦:</title>
SetEnvIf User-Agent ^KnockKnock/2\.0 let_me_in<br />
&lt;Directory /docroot&gt;<br />
<indent>
Order Deny,Allow<br />
Deny from all<br />
Allow from env=let_me_in<br />
</indent>
&lt;/Directory&gt;
</example>
<p>ÀÌ °æ¿ì user-agent ¹®ÀÚ¿­ÀÌ <code>KnockKnock/2.0</code>À¸·Î
½ÃÀÛÇÏ´Â ºê¶ó¿ìÀúÀÇ Á¢±ÙÀº Çã¿ëÇÏ°í, ³ª¸ÓÁö´Â ¸ðµÎ °ÅºÎÇÑ´Ù.</p>
</usage>
</directivesynopsis>
<directivesynopsis>
<name>Deny</name>
<description>¼­¹ö Á¢±ÙÀ» °ÅºÎÇÒ È£½ºÆ®¸¦ ÁöÁ¤ÇÑ´Ù</description>
<syntax> Deny from all|<var>host</var>|env=<var>env-variable</var>
[<var>host</var>|env=<var>env-variable</var>] ...</syntax>
<contextlist><context>directory</context><context>.htaccess</context>
</contextlist>
<override>Limit</override>
<usage>
<p>ÀÌ Áö½Ã¾î¸¦ »ç¿ëÇÏ¿© È£½ºÆ®¸í, IP ÁÖ¼Ò, ȯ°æº¯¼ö¿¡ µû¶ó
¼­¹ö Á¢±ÙÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. <directive>Deny</directive>
Áö½Ã¾îÀÇ ¾Æ±Ô¸ÕÆ®´Â <directive
module="mod_authz_host">Allow</directive> Áö½Ã¾î¿Í µ¿ÀÏÇÏ´Ù.</p>
</usage>
</directivesynopsis>
<directivesynopsis>
<name>Order</name>
<description>±âº»ÀûÀ¸·Î Á¢±ÙÀ» Çã¿ëÇÒÁö °ÅºÎÇÒÁö ¿©ºÎ¿Í
<directive>Allow</directive>¿Í <directive>Deny</directive>
󸮼ø¼­¸¦ Á¤ÇÑ´Ù.</description>
<syntax> Order <var>ordering</var></syntax>
<default>Order Deny,Allow</default>
<contextlist><context>directory</context><context>.htaccess</context>
</contextlist>
<override>Limit</override>
<usage>
<p><directive>Order</directive> Áö½Ã¾î´Â ±âº»ÀûÀ¸·Î Á¢±ÙÀ»
Çã¿ëÇÒÁö °ÅºÎÇÒÁö ¿©ºÎ¿Í <directive
module="mod_authz_host">Allow</directive>¿Í <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î 󸮼ø¼­¸¦
Á¤ÇÑ´Ù. <var>ordering</var>Àº ´ÙÀ½ Áß ÇϳªÀÌ´Ù</p>
<dl>
<dt><code>Deny,Allow</code></dt>
<dd><directive module="mod_authz_host">Deny</directive>
Áö½Ã¾î¸¦ <directive module="mod_authz_host">Allow</directive>
Áö½Ã¾î º¸´Ù ¸ÕÀú »ìÆ캻´Ù. ±×¸®°í ±âº»ÀûÀ¸·Î Á¢±ÙÀ» Çã¿ëÇÑ´Ù.
<directive module="mod_authz_host">Deny</directive>³ª
<directive module="mod_authz_host">Allow</directive> Áö½Ã¾î¿¡
ÇØ´çµÇÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢±ÙÀ» Çã¿ëÇÑ´Ù.</dd>
<dt><code>Allow,Deny</code></dt>
<dd><directive module="mod_authz_host">Allow</directive>
Áö½Ã¾î¸¦ <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î º¸´Ù ¸ÕÀú
»ìÆ캻´Ù. ±×¸®°í ±âº»ÀûÀ¸·Î Á¢±ÙÀ» Çã¿ëÇÏÁö ¾Ê´Â´Ù.
<directive module="mod_authz_host">Deny</directive>³ª
<directive module="mod_authz_host">Allow</directive> Áö½Ã¾î¿¡
ÇØ´çµÇÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢±ÙÀ» °ÅºÎÇÑ´Ù.</dd>
<dt><code>Mutual-failure</code></dt>
<dd><directive module="mod_authz_host">Deny</directive>
¸ñ·Ï¿¡´Â ¾È³ª¿À°í <directive
module="mod_authz_host">Allow</directive> ¸ñ·Ï¿¡¸¸ ³ª¿À´Â
È£½ºÆ®¸¸ Á¢±ÙÀ» Çã¿ëÇÑ´Ù. <code>Order Allow,Deny</code>¿Í
°°Àº ÀÏÀ» Çϱ⶧¹®¿¡ »ç¿ëÇÏÁö ¾Ê´Â´Ù.</dd>
</dl>
<p>Å°¿öµå´Â ½°Ç¥·Î¸¸ ±¸ºÐÇÑ´Ù; »çÀÌ¿¡ <em>°ø¹éÀÌ ÀÖÀ¸¸é
¾ÈµÈ´Ù.</em> ¸ðµç °æ¿ì <directive
module="mod_authz_host">Allow</directive>¿Í <directive
module="mod_authz_host">Deny</directive> ¸ðµÎ »ìÆ캽À»
¸í½ÉÇ϶ó.</p>
<p>¾Æ·¡ ¿¹¿¡¼­ apache.org µµ¸ÞÀÎÀÇ ¸ðµç È£½ºÆ®ÀÇ Á¢±ÙÀº
Çã¿ëÇÏÁö¸¸, ´Ù¸¥ È£½ºÆ®´Â ¸ðµÎ °ÅºÎÇÑ´Ù.</p>
<example>
Order Deny,Allow<br />
Deny from all<br />
Allow from apache.org
</example>
<p>¾Æ·¡ ¿¹¿¡¼­ foo.apache.org ÇÏÀ§µµ¸ÞÀο¡ Àִ ȣ½ºÆ®¸¸
°ÅºÎÇÏ°í, apache.org µµ¸ÞÀο¡ Àִ ȣ½ºÆ®´Â ¸ðµÎ Á¢±ÙÀ»
Çã¿ëÇÑ´Ù. ±âº»ÀûÀ¸·Î Á¢±ÙÀ» °ÅºÎÇϱ⶧¹®¿¡ apache.org µµ¸ÞÀο¡
¼ÓÇÏÁö ¾Ê´Â È£½ºÆ®´Â Á¢±ÙÀ» °ÅºÎÇÑ´Ù.</p>
<example>
Order Allow,Deny<br />
Allow from apache.org<br />
Deny from foo.apache.org
</example>
<p>¹Ý´ë·Î À§ÀÇ <directive>Order</directive>¸¦
<code>Deny,Allow</code>·Î º¯°æÇϸé, ¸ðµç È£½ºÆ®ÀÇ Á¢±ÙÀ»
Çã¿ëÇÑ´Ù. ¼³Á¤ÆÄÀÏ¿¡¼­ Áö½Ã¾î°¡ ³ª¿À´Â ¼ø¼­¿Í °ü°è¾øÀÌ
<code>Allow from apache.org</code>¸¦ Á¦ÀÏ ¸¶Áö¸·¿¡ ó¸®ÇÏ¿©
<code>Deny from foo.apache.org</code>ÀÇ È¿°ú¸¦ ¹«½ÃÇϱâ
¶§¹®ÀÌ´Ù. ¶Ç, ±âº»ÀûÀ¸·Î Á¢±ÙÀ» <em>Çã°¡</em>ÇϹǷÎ
<code>apache.org</code> µµ¸ÞÀο¡ ¼ÓÇÏÁö ¾Ê´Â È£½ºÆ®µµ ¸ðµÎ
Á¢±ÙÀ» Çã°¡ÇÑ´Ù.</p>
<p><directive>Order</directive> Áö½Ã¾î´Â ±âº»ÀûÀ¸·Î Á¢±ÙÀ»
Çã¿ëÇÒÁö °ÅºÎÇÒÁö¸¦ Á¤Çϱ⶧¹®¿¡ <directive
module="mod_authz_host">Allow</directive>³ª <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î¸¦ »ç¿ëÇÏÁö
¾Ê¾Æµµ Á¢±Ù°¡´É ¿©ºÎ¿¡ ¿µÇâÀ» ÁØ´Ù. ¿¹¸¦ µé¾î,</p>
<example>
&lt;Directory /www&gt;<br />
<indent>
Order Allow,Deny<br />
</indent>
&lt;/Directory&gt;
</example>
<p>´Â ±âº»ÀûÀ¸·Î Á¢±ÙÀ» <em>°ÅºÎ</em>Çϱ⶧¹®¿¡
<code>/www</code> µð·ºÅ丮¿¡ ´ëÇÑ ¸ðµç Á¢±ÙÀ» °ÅºÎÇÑ´Ù.</p>
<p><directive>Order</directive> Áö½Ã¾î°¡ Á¤ÇÏ´Â Á¢±Ù Áö½Ã¾î
󸮼ø¼­´Â ÇØ´ç ¼­¹ö¼³Á¤ 󸮴ܰ迡¸¸ ¿µÇâÀ» ÁØ´Ù. Áï,
<directive>Order</directive> Áö½Ã¾î ¼³Á¤°ú °ü°è¾øÀÌ <directive
module="core" type="section">Location</directive> ¼½¼Ç ¾È¿¡
ÀÖ´Â <directive module="mod_authz_host">Allow</directive>³ª
<directive module="mod_authz_host">Deny</directive> Áö½Ã¾î´Â
<directive module="core" type="section">Directory</directive>
¼½¼ÇÀ̳ª <code>.htaccess</code> ÆÄÀÏ¿¡ ÀÖ´Â <directive
module="mod_authz_host">Allow</directive>¿Í <directive
module="mod_authz_host">Deny</directive> Áö½Ã¾î¸¦ ¸ðµÎ ó¸®ÇÑ
ÈÄ¿¡ ó¸®ÇÑ´Ù. ¼³Á¤ ¼½¼ÇµéÀÌ °áÇÕÇÏ´Â ¹æ¹ý¿¡ ´ëÇؼ­´Â <a
href="../sections.html">¾î¶»°Ô Directory, Location, Files
¼½¼ÇÀÌ µ¿ÀÛÇϳª</a> ¹®¼­¸¦ Âü°íÇ϶ó.</p>
</usage>
</directivesynopsis>
</modulesynopsis>