Re: [squid-users] squid and windows authentication

From: Guido Serassio <serassio@dont-contact.us>
Date: Thu, 19 Sep 2002 09:51:19 +0200

Hi,

Il 09.15 19/09/2002 Ilker Gokhan ha scritto:
>Bjarni ?ór Haraldsson wrote:
> I want to install linux with proxy on the network, can squid query the
> windows users database???
>>and how is that implemented?
>>I would like to block some users or even some groups to access the
>>internet through my cache can I do that with squid?
>>Is there such a thing as a quota manager on squid, that is can I block
>>sudden amount og data transferred through my cache based on users.
>>NOTE the user database lies on the windows 2000 server (Active Directory)
>
>AFAIK, NTLM authentication exists.So, if your Win2000 works like PDC. You
>can. But active directory authentication has not been implemented (at
>least yet..). See:
>
>http://www.serassio.it/SquidNT/squidnt25.htm
>
>Please correct me If i'm wrong..
>
>Best regards,
>Ilker G.

Authentication against a Windows Domain (AD or NT 4) doesn't need the use
of Squid on Windows. Both Unix and Windows 2.5 version can do this.

There are two options:

- Basic LDAP authentication against native AD
- NTLM authentication against the NT 4 domain emulation of AD (this NOT
mixed mode)

With first option, the browser always prompts for username and password,
with second, when using Internet Explorer the logged in credential are used
without prompting the user.

Both method can do AD groups membership check.

At this time the Unix version is more robust and stable, so is recommended.

Regards

Guido

-
=======================================================
Serassio Guido
Via Albenga, 11/4 10134 - Torino - ITALY
E-mail: guido.serassio@serassio.it
WWW: http://www.serassio.it
Received on Thu Sep 19 2002 - 01:52:05 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:10:21 MST