Re: [squid-users] Squid 2.7 Chained Proxies and NTLM Pass-thru

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sat, 17 Jan 2009 00:22:07 +1300

vincent.blondel_at_ing.be wrote:
> hello all,
>
> my clients should access an IIS website requesting ntlm authentication
> 'WWW-Authentication'. they all use ie6 and proxied through a chain of
> two proxies.
>
> the first one hosted in internal network making the whole job of
> logging, validating ntlm authentication coming from all the ie's with
> our internal active directories, allow/deny websites mime-types and all
> kind of stuffs.
>
> the other one hosted in dmz as making simply the job of gateway to the
> internet.
>
> Both of them are running 2.7.4
>
> simple question .. Is that possible or not to make this surfing working
> .. if yes what do I have to configure ??
> Do I have to activate things like squid ntlm_auth binary,
> connection-auth=on, login=PASS ??

Only connection-auth=on. Not login=PASS.
auth_* should not be needed unless Proxy-Authentication is required.

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE5 or 3.0.STABLE11
   Current Beta Squid 3.1.0.3
Received on Fri Jan 16 2009 - 11:22:15 MST

This archive was generated by hypermail 2.2.0 : Fri Jan 16 2009 - 12:00:03 MST