Re: [squid-users] Deploying squid with NTLM authentication (forw)

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Tue, 25 Jun 2002 00:29:18 +0200

Joerg Mayer wrote:

> 1) Is there a recommended version (looks like I need 2.5 or 2.6) or
> specific versions to avoid? If not, I intend to use squid-2.5.PRE7.

Go for the latest 2.5 snapshot, and then upgrade to 2.5.STABLE when it
becomes available. Hopefully 2.5.STABLE will be available before you go
production.

You should not be using DEVEL version in production unless you have a
strong reason to why.

> 2) Is the NTLM code ready for use in a 2000-3000 user environment (one NT4
> domain)? Are there drawbacks?

using the winbind helper should be ok I think. The SMB helper has quite
many quirks.. but this is still relatively new code so it is hard to
tell how well it operates before a few have put it into large scale
production.

> 3) Is the squid version I picked ready for use?

The 2.5 version is almost ready.

> 4) Is there a way for me to check whether these users are members of
> a specific NT group (like "internet" or such)? If not, what is
> missing in the way of infrastructure?

Coming. The needed internal infrastructure is there now, but it remains
to write the helpers for integrating with NT domain groups..

> 5) Any recommended reading besides the FAQ and the documentation found at
> (or directly linked to from) squid.sf.net/ntlm/ ?

devel.squid-cache.org/ntlm/ is probably the best source for NTLM related
information in Squid at the moment. In some time there will be FAQ
sections also. If you want to help with the documentation then please
take notes when doing your installation.

Regards
Henrik
Received on Mon Jun 24 2002 - 16:55:24 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:08:48 MST