[squid-users] squidnt 2.7Stable8 - NTLM/negotiate user authproblems with 2008R2/Win7

From: franzo318 <franzo318_at_gmail.com>
Date: Tue, 8 Nov 2011 07:41:57 -0800 (PST)

hi guys,

installation: squidnt 2.7-8 on Win2008R2(domainmember srv)
clients: win7/other 2008R2 Server
configuration: with user authentication ->
auth_param ntlm program c:/squid/libexec/mswin_ntlm_auth.exe

result: proxy ist not able to authenticate the client request because it can
not handle the default win7/2008 R2 security setting "LAN
Manager-Authenticaton-level"
it would only work, if this setting would be changed from default to "ntlm
only" -> but this change would result in an securityhole!!!

the same problem occurs while using the negotiate scheme and
auth_param negotiate program c:/squid/libexec/mswin_negotiate_auth.exe

my fazit:
user authentication with squidnt 2.7 in an 2008r2/win7 environment, is not
possible without security impact.

is this right? or can anbody provide an workaround to the described problem?

thanks in advance?
f

--
View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squidnt-2-7Stable8-NTLM-negotiate-user-authproblems-with-2008R2-Win7-tp4016437p4016437.html
Sent from the Squid - Users mailing list archive at Nabble.com.
Received on Tue Nov 08 2011 - 15:42:00 MST

This archive was generated by hypermail 2.2.0 : Wed Nov 09 2011 - 12:00:03 MST