Re: [Fwd: Re: [squid-users] is really impossible?]

From: Matus UHLAR - fantomas <[email protected]>
Date: Fri, 1 Apr 2005 10:46:36 +0200

> >On 30.03 16:01, Jonis Maurin Cear� wrote:
> >>It's really impossible to run squid as transparent proxy (NAT) +
> >>authentication? :(

> Matus UHLAR - fantomas escreveu:
> >no. it is possible, but not with interception.

> >>Anyone know any other solution?

> >configure clients to use the proxy.

On 31.03 09:31, Jonis Maurin Cear� wrote:
> I can't....it must be easy for end user :(

easy?
1. set up proxy autoconfiguration file and configure DHCP to support it.
   (you can find this info in archives or google)
2. transparently redirect all users not using proxy to a page that tells
   them how to configure a proxy

> any other idea instead of squid ?

It is not possible. I repeat: IT IS NOT POSSIBLE.

No HTTP client will send its proxy authorization to end server, and the
client can not know that you redirected end server to proxy. Senting proxy
authorization data would be security bug. And therefore no browser authors
will code such feature to their browsers, unless you ask any to do it.

-- 
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
"To Boot or not to Boot, that's the question." [WD1270 Caviar]
Received on Fri Apr 01 2005 - 01:46:39 MST

This archive was generated by hypermail pre-2.1.9 : Sun May 01 2005 - 12:00:03 MDT