[squid-users] Re: Re[squid-users] verse proxy to Sharepoint

From: afstcklnd <andrew.stickland_at_spirititconsulting.com>
Date: Mon, 23 Jun 2008 15:31:00 -0700 (PDT)

Hi,

OK, have built a new Squid 2.7 Stable 2 version and it's up and running.
wbinfo reports authentication OK, but I get the following when the users try
and authenticate....

authenticateNTLMHandleReply: Error validating user via NTLM. Error returned
'BH NT_STATUS_ACCESS_DENIED'

This would suggest a Samba problem but in isolation, Samba seems fine. Any
ideas???

All the best
Andrew

Chris Robertson-2 wrote:
>
> afstcklnd wrote:
>> We have a working infrastructure using Windows 2003, AD & Sharepoint for
>> Project Web Access. In order to allow branch office access, we wanted to
>> put
>> in place a reverse proxy solution and looked at Squid. After a lot of
>> reading, it became clear the Squid 2.6 or above was the best option in
>> order
>> to get working NTLM authentication. So....
>>
>> We've installed a Fedora Core 9 box with Squid 3.0, attached it to the
>> domain and set up all the kerberos, ldap authentication etc. However,
>> it's
>> not quite behaving correctly.
>>
>
> Last I saw,
> (http://www.squid-cache.org/mail-archive/squid-users/200803/0523.html)
> you'll need to use 2.6 or 2.7 to proxy NTLM authentication. The
> connection pinning required to support it has not been added to the
> released Squid 3 code base.
>
>> Testing kerberos, ldap etc. seems all OK and the ntlm helpers are running
>> OK. Connect to the proxy with IE of Firefox and the request for a
>> password
>> is presented but regardless of what is entered authentication.
>>
>> Obviously I need to provide more information but can you guide me as to
>> where and what I need to provide?
>>
>> Thanks
>>
>
> Chris
>
>
>

-- 
View this message in context: http://www.nabble.com/Reverse-proxy-to-Sharepoint-tp17909397p18079891.html
Sent from the Squid - Users mailing list archive at Nabble.com.
Received on Mon Jun 23 2008 - 22:31:03 MDT

This archive was generated by hypermail 2.2.0 : Fri Jun 27 2008 - 12:00:05 MDT