Re: [squid-users] Sending on Group names after Kerb LDAP look-up

2010-03-29 Thread Nick Cairncross
Hi, I just wanted to give this a bump; Is it possible to manipulate the (Kerberos-authenticated) username that gets sent to my ICAP server and strip off the @domain? E.g. jsm...@myaddomain becomes jsmith Relevant squid lines just FYI: icap_send_client_username on

Re: [squid-users] Sending on Group names after Kerb LDAP look-up

2010-03-25 Thread Nick Cairncross
Amos, Thanks for your help - you are right in that the connector has the ability to receive and manipulate ICAP, and using an NTLM authenticated user allows me to do the thing I need. All was nearly lost. However, if I change to Kerberos authentication on my Squid then the connector breaks

Re: [squid-users] Sending on Group names after Kerb LDAP look-up

2010-03-23 Thread Amos Jeffries
Nick Cairncross wrote: Hi All, Things seem to be going well with my Squid project so far; a combined Mac/Windows AD environment using Kerberos authentication with fall back of NTLM. I (hopefully) seem to be getting the hang of it! I've been trying out the Kerberos LDAP look up tool and have a

[squid-users] Sending on Group names after Kerb LDAP look-up

2010-03-22 Thread Nick Cairncross
Hi All, Things seem to be going well with my Squid project so far; a combined Mac/Windows AD environment using Kerberos authentication with fall back of NTLM. I (hopefully) seem to be getting the hang of it! I've been trying out the Kerberos LDAP look up tool and have a couple of questions (I