>Number:         3248
>Category:       mod_proxy
>Synopsis:       Can't logon to a Microsoft Proxy 2.0 via proxy-authentication 
>with ProxyRemote
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    apache
>State:          open
>Class:          sw-bug
>Submitter-Id:   apache
>Arrival-Date:   Mon Oct 19 14:50:01 PDT 1998
>Last-Modified:
>Originator:     [EMAIL PROTECTED]
>Organization:
apache
>Release:        1.3.3
>Environment:
Linux 2.0.34 #6 Fri Jul 10 12:45:12 CEST 1998 i586 unknown
gcc
>Description:
For security reasons, we are running two separate proxies. One is a MS Proxy
2.0 and the other is Apache 1.3.3 
Clients must get thru the Apache proxy first (bypassing the filtering)
in order to get to the second proxy (MS Proxy).
We use ProxyRemote for redirecting the clients to the MS Proxy which
has Basic-Authentication turned on for authorizing the usernames and passwords
our users have for Internet access.
And here comes the prob. When a client tries to connect to any of the sites
we are doing ProxyRemote for, he gets almost instantly prompted for his
username/password but the authentication always fails returning with Error Code 
407 

The anomaly leaves the following line in the access-log:
192.168.74.44 - - [19/Oct/1998:09:40:42 +0200] "GET http://www.blabla.com/ 
HTTP/1.0" 407 0

Clients aproved to fail: Netscape Communicator 4.5, MSIE 4.0 and lynx 2.8
>How-To-Repeat:
Get an MS Proxy 2.0 (Basic-Authentication and a user with granted access to 
WWW) 
Set up Apapche 1.3.3 with
ProxyRemote http://www.anysite.com http://www.msproxy.com:80
And try to reach http://www.anysite.com
>Fix:
Absolutely no idea. I haven't found even the slightest trace of a useful
solution on the Web for days.
>Audit-Trail:
>Unformatted:
[In order for any reply to be added to the PR database, ]
[you need to include <[EMAIL PROTECTED]> in the Cc line ]
[and leave the subject line UNCHANGED.  This is not done]
[automatically because of the potential for mail loops. ]
[If you do not include this Cc, your reply may be ig-   ]
[nored unless you are responding to an explicit request ]
[from a developer.                                      ]
[Reply only with text; DO NOT SEND ATTACHMENTS!         ]



Reply via email to