Re: Needing state in NTLMSSP

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 17 Jan 2003 09:57:47 +0100

Robert Collins wrote:

> You are reading the code incorrectly. We *don't* need thousands of
> helper children, and we don't block the helper based on the client.
>
> We multiplex requests from multiple NTLM authentications to each NTLM
> helper. You can run with only one helper, if your helper is reasonable
> fast in it's responses.

Maybe. However I don't see how you can do this in a reliable manner if
you add into the mix

 * Negotiate packets for correct NTLMSSP implementation
 * NTLMv2

And even less if we later want to expand into supporting SPNEGO.

Btw, SPNEGO is identital to NTLMSSP when it comes to requirements for
Squid. Only differs in the helper.

Regards
Henrik
Received on Fri Jan 17 2003 - 01:59:10 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:19:07 MST