[squid-users] Re: Re: ext_kerberos_ldap_group_acl vs ext_ldap_group_acl

From: Markus Moeller <huaraz_at_moeller.plus.com>
Date: Wed, 4 Sep 2013 06:01:29 +0100

"Eugene M. Zheganin" <eugene_at_zhegan.in> wrote in message
news:5226B394.90103_at_zhegan.in...
> Hi.
>
> On 04.09.2013 01:42, Markus Moeller wrote:
>>
>> Do you work in a Windows environemnt with AD as kdc ? I have a new
>> method in my squid 3.4 patch (see squid dev list) which uses the Group
>> Information MS is putting in the ticket. This would eliminate the ldap
>> lookup completely.
>>
> I do. This is awesome ! Thanks a lot.
>

It "just" needs the helper protocol enhancement to forward group information
from the auth helper to an acl helper which I still have to write.

> Are you still interested in tcpdump captures you mentioned in previous
> letter ?
>

Yes I would still like to see it.

> P.S. I found this message. Will the new helper protocol recognize nested
> groups ?
>

Yes it does.

> Eugene.
>

Regards
Markus
Received on Wed Sep 04 2013 - 05:01:53 MDT

This archive was generated by hypermail 2.2.0 : Wed Sep 04 2013 - 12:00:05 MDT