Re: Username Header [PATCH]

From: Robert Collins <robert.collins@dont-contact.us>
Date: Fri, 4 Jan 2002 14:53:33 +1100

----- Original Message -----
From: "Henrik Nordstrom" <hno@squid-cache.org>

> Quick question: What is wrong with using basic authentication for
forwarding
> the username to the application(s)?

This is one of the things needed IMO in the long term for managing
forwarded pinned NTLM or Digest connections. Particularly in cache
hierarchies, although this scenario is similar.

> Such basic authentication can easily added to the request by
redirectors or
> and by per server cache_peer lines using the login= option.
>
> Using basic authentication adds slightly more security, as the user do
not
> need to know the password.

But can sniff it :].

I think I outlined a very similar proposal in this list about a year
ago.

Rob
Received on Thu Jan 03 2002 - 20:53:26 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:14:44 MST