Hi

Can you try

auth_param negotiate program /usr/lib/squid/squid_kerb_auth -d -i -s GSS_C_NO_NAME

instead of

auth_param negotiate program /usr/lib/squid/squid_kerb_auth -d -i -s HTTP/[email protected]

I wonder if the kerberos library get confused having hostname proxy01 and keytab proxy02. It shouldn't.

You could also try to remove the invalid KVNO entries from the keytab using ktutils (I assume you use MIT Kerberos).

Markus


"flypast"  wrote in message news:[email protected]...

thx for your confirmation(i did the right. thing ). let us go back to my
issue. cld you pls help ?



--
View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-proxy-kerberos-authentication-failure-Help-tp4663964p4663976.html Sent from the Squid - Users mailing list archive at Nabble.com.

Reply via email to