RE: [squid-users] problem accessing a certain website using 2.5.STABLEx

From: Tay Teck Wee <wolfpacks01@dont-contact.us>
Date: Fri, 19 Aug 2005 19:11:08 +0800 (CST)

Thanks Henrik for your informative reply.

Just last 2 questions below.

--- Henrik Nordstrom <hno@squid-cache.org> wrote:

> On Fri, 12 Aug 2005, Tay Teck Wee wrote:
>
> > 1) But it would be most strange that squid on
> version
> > 2.4 could serve up the pop-up auth box while
> version
> > 2.5 cannot.
>
> Not at all.
>
> 2.4 does not know about the HTTP breakage introduced
> by Microsoft in their
> NTLM & Negotiate authentication schemes, and will
> happily forward the
> messages as seen resulting in total caos after a
> while (including major
> security issues on the server).

What kind of chaos can we expect?

>
> 2.5 knows both NTLM and Negotiate violates HTTP and
> can not be proxied in
> a good manner.
>
> Also newer versions of MSIE and IIS also knows this
> and will automatically
> disable the use of NTLM and Negotiate when a proxy
> is detected.
>

How does one auth then?

Send instant messages to your online friends http://asia.messenger.yahoo.com
Received on Fri Aug 19 2005 - 05:11:11 MDT

This archive was generated by hypermail pre-2.1.9 : Thu Sep 01 2005 - 12:00:02 MDT