RE: [squid-users] LDAP groups with a redirector

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 20 Aug 2004 13:44:44 +0200 (CEST)

On Fri, 20 Aug 2004, Dave Raven wrote:

> NTLM authentication passes domain and user information to
> squidGuard, I think in the format domain/username or visa versa.

NTLM authentication passes the users login name which includes the domain.

The NT Domain thing is very different from groups. NT Domains declare
where the user is defined, not his permissions (groups).

> Would it be possible/worthwhile (with group_ldap - and perhaps some code
> changes from us) to pass username/group to the redirector, at which
> stage we'll handle splitting it etc?

No.

This information is not available in the login name.

It is the same issue if you want a NT Group to be sent.

Regards
Henrik
Received on Fri Aug 20 2004 - 05:44:48 MDT

This archive was generated by hypermail pre-2.1.9 : Wed Sep 01 2004 - 12:00:02 MDT