I don't know, the docs on apache say:
That would lead one to believe it should have worked...Make sure that the AuthUserFile is stored outside the document tree of the web-server; do not put it in the directory that it protects. Otherwise, clients may be able to download the AuthUserFile.