Re: [squid-users] RE: wbinfo_group.pl receives user and domain in wrong format?

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sat, 05 Jan 2013 20:03:27 +1300

On 4/01/2013 10:01 p.m., Laurikainen, Tuukka wrote:
> Hi,
>
> Update: If I change "winbind use default domain = no" the wbinfo_group.pl receives the correct username.
>
> This OK, just that the basic auth users now need to include the domain with their username.
>
> I still would like to know why wbinfo_group.pl receives the username in form of USER_at_MY.DOMAIN and not as DOMAIN\USER or just USER as I understand it should.

Your understanding of the user name format is wrong.

* NTLM auth protocol format is domain\user

* Kerberos auth protocol format is user_at_domain.

Both are correct formats for Negotiate authentication user name labels,
since Negotiate is a wrapper layer around both auth protocols.

Amos
Received on Sat Jan 05 2013 - 07:03:35 MST

This archive was generated by hypermail 2.2.0 : Sat Jan 05 2013 - 12:00:05 MST