Re: [squid-users] NTLM not working for squid in windows server

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Wed, 25 Aug 2010 00:22:59 +0000

On Tue, 24 Aug 2010 17:22:09 +0100, José Carlos Correia
<jcorreia_at_tintadigital.com> wrote:
> Dear all,
>
> I have installed Squid in Windows 2008 with NTLM authentication but the
> browser still prompts for login.
>
> I read in the forums that NTLM won't work if:
> "- the client is not joined to a domain
> - the client is configured not to attempt automatica authentication to
> the proxy
> - the clients is not MSIE or Firefox (not sure about other browsers)"

That last point is false. WMP and Java apps are known to do NTLM.
There is no reason other browsers on windows can't do it too.

Add to that list:
 - if the server closes the connection all the time behind HTTP/1.0
proxies (ie Squid).

>
> In this case, Squid is replacing an ISA Server. NTLM was working with
> the ISA server but without any changes to the clients (just replacing
> the ISA Server by Squid) NTLM doesn't work.
>
> The only situation where the browser doesn't prompt for authentication
> is when the server is added to the Trusted Zone and IE is configured
> with Automatic login. But this won't necessary with the ISA Server.
>
> What am I missing?
>
> Thanks,
> José Carlos Correia

There has been a lot of testing and checking of NTLM and persistent
connections recently in exactly this area. Squid-3.1.7 contains a number of
fixes.

Amos
Received on Wed Aug 25 2010 - 00:23:03 MDT

This archive was generated by hypermail 2.2.0 : Wed Aug 25 2010 - 12:00:02 MDT