[squid-users] Re: Simple Kerberos/Squid configuration "received type 1 NTLM token"

From: Markus Moeller <huaraz_at_moeller.plus.com>
Date: Mon, 27 Sep 2010 21:36:39 +0100

"Markus Moeller" <huaraz_at_moeller.plus.com> wrote in message
news:i7qqri$kuv$2_at_dough.gmane.org...
>
> "barbarossa" <bDmanLIB_at_hotmail.com> wrote in message
> news:1285596015113-2715437.post_at_n4.nabble.com...
>>
>> I want to say that in IE 8 (the only version I used for the proxy), I get
>> a
>> login prompt.
>>
>>> Are the XP users defined in the Kerberos server ?
>>>
>>> Markus
>>
>> No. I just want to authenticate using the ticket I created. Is this not
>> possible?
>>
>>>Did you configure Firefox to use the MIT gss library using about:config
>>>and
>>>setting network.negotiate-auth.gsslib,
>>>network.negotiate-auth.using-native-gsslib ? If not does NIM push the
>>>credential cache into the MS credential cache ( I don't recall if NIM can
>> do
>>>that now-a-days) ?
>>
>> Now I tried it with the following values:
>> *setting network.negotiate-auth.gsslib: C:\Program
>> Files\MIT\Kerberos\bin\gssapi32.dll
>> *network.negotiate-auth.using-native-gsslib: false
>>
>> Is this correct?
>
> Yes this should work.

Correction. You also have to set:

network.auth.use-sspi false

Markus
>
>> --
>> View this message in context:
>> http://squid-web-proxy-cache.1019090.n4.nabble.com/Simple-Kerberos-Squid-configuration-received-type-1-NTLM-token-tp2553379p2715437.html
>> Sent from the Squid - Users mailing list archive at Nabble.com.
>>
>
>
>
Received on Mon Sep 27 2010 - 20:36:58 MDT

This archive was generated by hypermail 2.2.0 : Tue Sep 28 2010 - 12:00:05 MDT