[squid-users] Kerberos-authentication and ntlm-fallback with AD-group-membership-checking

From: Tom Tux <tomtux80_at_gmail.com>
Date: Wed, 7 Jul 2010 07:23:49 +0200

Hi

I'm searching a way to authenticate IE6-clients with ntlm based on
group-membership and all other clients (IE7, IE8) with kerberos (also
group-membership-based).

I'm able to authenticate with kerberos AND group-membership
(squid_kerb_ldap), but the IE6-clients will then prompt for the
squid_kerb_ldap-authentication. If I leave the squid_kerb_ldap-helper
away, then all users are able to authenticate without checking the
group-membership.

How can I achieve to have a proper single-sign-on
kerberos-authentication (with squid_kerb_ldap) and a
fallback-ntlm-authentication for the IE6-browser (also with checking
group-membership) without prompting for username/password?

Thank you.
Regards
Tom
Received on Wed Jul 07 2010 - 05:23:56 MDT

This archive was generated by hypermail 2.2.0 : Thu Jul 08 2010 - 12:00:03 MDT