Re: [squid-users] NTLM Authentication

From: Kinkie <kinkie-squid@dont-contact.us>
Date: Fri, 13 Aug 2004 16:22:55 +0200

Merton Campbell Crockett <mcc@CATO.GD-AIS.COM> writes:

> (1) When a web server uses NTLM authentication, will a login screen
> be presented when the web site is accessed via a Squid proxy?

Accessing an NTLM-protected site via a proxy won't work. NTLM is broken
beyond repair, and this is one of the effects.

> (My recollection from years ago was that the login screen was
> only displayed when basic authentication was enabled?)

Not really. If you access the NTLM-protected site directly, whether or not
authentication is requested depends on the zone security settings in
MS Internet Exporer (and of course what zone the server is in).

> (2) The web server was recently switched from a WindowsNT to an
> Active Directory domain. What is the syntax for a user login
> ID when basic authentication is used?

Always the same: domain\user

> (3) Is there a convenient way of specifying to the user that they
> should bypass the proxy for a subset of the web content?

A proxy autoconfiguration file.

-- 
	kinkie (kinkie-squid [at] kinkie [dot] it)
	Random fortune, unrelated to the message:
Observe yon plumed biped fine.
To activate its captivation,
Deposit on its termination,
A quantity of particles saline.
Received on Fri Aug 13 2004 - 08:22:57 MDT

This archive was generated by hypermail pre-2.1.9 : Wed Sep 01 2004 - 12:00:02 MDT