Don't really like what I'm seeing, so far. The authentication built into Apache sends the password unencrypted. We don't have really sensitive data, like credit cards. But I'd still prefer it didn't do that.
Also, the password file has to be maintained by hand. I guess I could write a PHP script to do that