Re: [squid-users] squid and ntlm: looking for SSO enabling tools

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Thu, 05 Mar 2009 22:19:05 +1300

robert rottermann wrote:
> Hi there,
>
> I want to run an intranet using an applicationserver (zope/plone) running behind
> a squid http accelerator. I want to provide NTLM based SSO such that a user that
> logged into his/her workstation is automaticely logged into the intranet.
>
> what I am looking for is an autentication helper tool, that provides
> authentication within squid and allows passing along the username for which the
> authentication was accepted.

Squid bundles with several such helpers.
Depending on the squid version you have access to domainless LanMan
sign-on, full NTLM support (requires samba ntlm_auth) or kerberos
support (Vista etc).

Squid 2.7, and 3.1 provide NTLM pass-thru for IIS etc to do
www-authenticate with NTLM credentials. Other Squid can only terminate
NTLM and pass Basic-auth credentials to www backends.

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE6 or 3.0.STABLE13
   Current Beta Squid 3.1.0.6
Received on Thu Mar 05 2009 - 09:18:41 MST

This archive was generated by hypermail 2.2.0 : Thu Mar 05 2009 - 12:00:02 MST