Re: [squid-users] SSO for Win2k and Linux Clients using LDAP

From: Henrik Nordstrom <henrik@dont-contact.us>
Date: Wed, 16 Aug 2006 23:14:57 +0200

ons 2006-08-16 klockan 22:53 +0200 skrev Alexander Schaber:

> Which other OS could be used with SSO?

Today it's basically Microsoft Windows having this..

> Isn't Kerberos supposed to integrate SSO? I've read that it will be
> integrated with Squid 3?

Kerberos have the potential to provide this, but still a lot is missing
to reach the goal.. There is no real standard for how to use Kerberos
for authentication in web (the closest is Microsoft SPNEGO over HTTP),
and support in all components involved is therefore pretty slim..

SPNEGO might actually work, and is supported by Squid if you find the
correct helper for it to verify the authentication exchanges.. Samba is
working on extending ntlm_auth to also support SPNEGO, but apparently
there is no stable release yet..

As this is pretty much uncharted areas I suspect the client support in
common browsers outside the Windows platform also still leave much to
ask.

Regards
Henrik

Received on Wed Aug 16 2006 - 15:15:01 MDT

This archive was generated by hypermail pre-2.1.9 : Fri Sep 01 2006 - 12:00:02 MDT