Re: [squid-users] Only attempt ntlm auth for domain machines

From: Kinkie <gkinkie_at_gmail.com>
Date: Wed, 13 Jan 2010 07:55:02 +0100

On Wed, Jan 13, 2010 at 12:14 AM, Matt Richards <matt_at_mattstone.net> wrote:
> Hello,
>
> I currently have a squid proxy setup and running with AD authentication and SSO.
>
> My question is ... is it possiable to have squid only attempt to authenticate via kerberos for machines that are a
> member of the AD domain?
>
> If needed I can write a script that queries the AD LDAP database for the machine object.

No.
Your best option is to have a dual-squid setup, and use different
client configurations for machines in/not in the domain (or something
like transparent-for-non-domain and
explicitly-configured-for-domain-members).

-- 
    /kinkie
Received on Wed Jan 13 2010 - 06:55:06 MST

This archive was generated by hypermail 2.2.0 : Wed Jan 13 2010 - 12:00:03 MST