[squid-users] Re: Samba domain and ntlm_auth, seamless auth NOT wanted

From: Marco De Vitis <starless@dont-contact.us>
Date: Mon, 18 Jul 2005 21:13:35 +0200

Il 15/07/2005, alle ore 14:46, Marco De Vitis ha scritto:

> Il 15/07/2005, alle ore 14:20, David ha scritto:
>
>> I think you can just change to using basic authentication.
> [...]
>> auth_param basic program /usr/local/bin/ntlm_auth
>
> Hmmm... interesting idea.
> I'll try when I can, but wouldn't this mean that user/password pairs are
> transmitted in clear text over the LAN?

I answer myself after trying and sniffing the transmission: yes,
user/password are trasmitted in clear text, just like plain basic
authentication.

> Maybe I could try using wb_ntlmauth?
> i.e.:
> auth_param ntlm program /usr/lib/squid/wb_ntlmauth
> (on a Debian Woody with backported squid 2.5)
> Although I've read that wb_ntlmauth does not work with Samba 3.

Indeed, wb_ntlmauth is not even available with Samba 3 packages, so I
didn't even try.

-- 
Ciao,
  Marco.
..."Thrak", King Crimson (1995)
Received on Mon Jul 18 2005 - 13:14:15 MDT

This archive was generated by hypermail pre-2.1.9 : Mon Aug 01 2005 - 12:00:02 MDT