Re: New authenticator module for native Win32 port

From: Robert Collins <robert.collins@dont-contact.us>
Date: Tue, 13 Feb 2001 08:16:00 +1100

----- Original Message -----
From: "Igor V. Nechaev" <igor@iface.ru>
To: <squid-dev@squid-cache.org>
Sent: Tuesday, February 13, 2001 12:19 AM
Subject: New authenticator module for native Win32 port

> Hi all!
>

Hi!

> I am in the process of developing authenticator plugin for Win32
> port of Squid (Romeo Angelache+Guido Serassio). This plugin is
> supposed to authenticate users against WindowsNT user's database.

Excellent.

> It uses native Windoze SSPI interface, wich gives it power to work
> under ordinary user account. Current nt_auth module (native Windows
> NT Authenticator working as DLL) works only if Squid is run under
> 'System' account. It somehow discredits 'cache_effective_user/
> cache_effective_group' idea.

I don't think Romeo/Guido have implemented that concept under MSVC..

> Moreover, using SSPI interface one can authenticate against, say,
> Kerberos server.

Yes, but you can do that already given that squid has the users credentials in cleartext.

> If you, people, think that this one worth your attention I'd be glad
> to share it with the community.

It would be good to have in squid. Even better, if you've got the patience would be for you to build and test it under the cygwin
squid as well (perhaps with a #define to switch from .DLL to .exe in your makefile). That way the authenticator will have the widest
possible use.

Rob
Received on Mon Feb 12 2001 - 14:14:21 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:13:30 MST