Re: [squid-users] Remote access acls

From: Henrik Nordstrom <henrik_at_henriknordstrom.net>
Date: Sat, 14 Jun 2008 00:22:15 +0200

I would recommend you use digest instead of basic. That way the password
is not transmitted in plain text.

almost the same setup as basic, except for the auth_param settings.

auth_param digest program /usr/local/squid/libexec/digest_pw_auth /usr/local/squid/etc/registered.htdigest

and change the rest of the basic auth_param to digest instead..

the password file is most easily maintained using Apache htdigest, instead of Apache htpasswd..

Regards
Henrik

On fre, 2008-06-13 at 21:42 +0700, docdiz wrote:
> I use simple NCSA. Then add small password file to NCSA directory.
> This password file is changed EVERY day, at 08:00am and 17:00pm. User
> have to call in to get the username/password of that day before
> they're able to use this office's squid (another way to audit who's
> working or not :-D)
>
> # heh! this line is extract from the very old 2.0 conf
> authenticate_program /usr/local/squid/bin/ncsa /usr/local/squid/etc/registered
>
> # this two lines never change eventhough it's now 2.6
> acl MEMBER proxy_auth REQUIRED
> http_access deny !MEMBER

Received on Fri Jun 13 2008 - 22:22:20 MDT

This archive was generated by hypermail 2.2.0 : Sat Jun 14 2008 - 12:00:03 MDT