Re: [squid-users] auth. user against AD group

From: Guido Serassio <serassio@dont-contact.us>
Date: Sat, 08 Feb 2003 09:22:35 +0100

Hi Henrik,

At 01.51 08/02/2003, Henrik Nordstrom wrote:
>Guido Serassio wrote:
> >
> > Hi,
> >
> > Il 10.04 07/02/2003 KaiserM@Gendorf.de ha scritto:
> > >Hello List,
> > >
> > >my problem ist to get user authenticated against a AD.
> > >
> > >
> > > external_acl_type NT_global_group %LOGIN
> > > /usr/lib/squid/wb_group
> > > acl ieuser external NT_global_group Datkom
> > > acl proxy_auth REQUIRED
> > > http access allow ieuser
> >
> > Wrong squid.conf settings:
> >
> > Try using;
> >
> > acl password proxy_auth REQUIRED
> >
> > http access allow password ieuser
>
>You do not actually need to use a proxy_auth acl if your are using a
>external_acl_type with %LOGIN, they both do the same thing (trigger
>authentication).

Hmm, I think that the following from
http://devel.squid-cache.org/external_acl/ is very unclear:

"auth lookups
The use of %LOGIN requires that the user is already successfully
authenticated. The external acl cannot yet cause a challenge to be sent to
the browser. "

Regards

Guido

>Regards
>Henrik

-
=======================================================
Serassio Guido
Via Albenga, 11/4 10134 - Torino - ITALY
E-mail: guido.serassio@serassio.it
WWW: http://www.serassio.it
Received on Sat Feb 08 2003 - 01:23:53 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:13:17 MST