This wont get you into any trouble imo, you need to ask your site hoster for the location of the htpasswd file (to generate the password files)
Apache uses some default locations which you try first though.
the passwords are/can be encrypted by 3 differend standards

so sniff ahead
btw, I succeeded in protecting my cgi-bin this way, the control panel suplied me only with a way to httaccess my httpdocs and httpsdocs directories.