Re: Using AD groups from negotiate_kerberos_auth in ssl-bumped connections.
Andrey K <[email protected]> Thu, 5 Mar 2026 16:30:58 +0300
| Newsgroups | gmane.comp.web.squid.general |
|---|---|
| Message-ID | <CADJd0Y3ct=5yNSioZaFbuCk+HruiwyD2NycWMj1iCiPK9p4mWw@mail.gmail.com> |
--===============4512976895275270062==
Content-Type: multipart/alternative; boundary="00000000000012613c064c46f38c"
--00000000000012613c064c46f38c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Amos and Alex, thank you for the information.
Kind regards,
Ankor.
=D1=87=D1=82, 5 =D0=BC=D0=B0=D1=80. 2026=E2=80=AF=D0=B3. =D0=B2 10:23, Amos=
Jeffries <[email protected]>:
> On 04/03/2026 19:33, Andrey K wrote:
> > Hello, Amos,
> >
> > Thanks for the information.
> >
> > Canyou alsotellme:
> > 1. Is it possible to use a macro in the annotate_client ACL to copy HTT=
P
> > request notes to a TCP connection? Something like:
> > acl annotate_groups annotate_client groups=3D%{group}note
> >
>
> That is not supported. Which is what I meant by these having to be
> configured manually. You need an ACL to match the group note, and
> another to set the new note, repeated for each group name you want to
> link between the transactions.
>
>
> > 2. How do you think, should we process the "group" attribute at the
> > connection state level as we do with the "clt_conn_tag"? I think this
> > can be easily implemented in the UpdateRequestNotes() function (src/
> > HttpRequest.cc) by simply copying and pasting a few lines of code:
>
> This is not great since group is not limited to Negotiate and NTLM
> authentication types. Other auth schemes have group only being valid on
> one HTTP transaction.
>
>
> I would suggest having a new access control directive that permits or
> denies annotations to be mapped when the CONNECT is bumped. That would
> allow any existing annotation of the CONNECT transaction to be applied
> as a connection-annotation for the bump'ed request.
>
> HTH
> Amos
>
> _______________________________________________
> squid-users mailing list
> [email protected]
> https://lists.squid-cache.org/listinfo/squid-users
>
--00000000000012613c064c46f38c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr">Amos and Alex, thank you for the information.<div><br></di=
v><div>Kind regards,</div><div>=C2=A0 =C2=A0 Ankor.</div></div><br><div cla=
ss=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_at=
tr">=D1=87=D1=82, 5 =D0=BC=D0=B0=D1=80. 2026=E2=80=AF=D0=B3. =D0=B2 10:23, =
Amos Jeffries <<a href=3D"mailto:[email protected]">[email protected]=
.nz</a>>:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px=
0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On =
04/03/2026 19:33, Andrey K wrote:<br>
> Hello, Amos,<br>
> <br>
> Thanks for the information.<br>
> <br>
> Canyou alsotellme:<br>
> 1. Is it possible to use a macro in the annotate_client ACL to copy HT=
TP <br>
> request notes to a TCP connection? Something like:<br>
> acl annotate_groups annotate_client groups=3D%{group}note<br>
> <br>
<br>
That is not supported. Which is what I meant by these having to be <br>
configured manually. You need an ACL to match the group note, and <br>
another to set the new note, repeated for each group name you want to <br>
link between the transactions.<br>
<br>
<br>
> 2. How do you think,=C2=A0should we process the "group" attr=
ibute at the <br>
> connection state level as we do with the "clt_conn_tag"? I t=
hink this <br>
> can be easily implemented in the UpdateRequestNotes() function (src/ <=
br>
> HttpRequest.cc) by simply copying and pasting a few lines of code:<br>
<br>
This is not great since group is not limited to Negotiate and NTLM <br>
authentication types. Other auth schemes have group only being valid on <br=
>
one HTTP transaction.<br>
<br>
<br>
I would suggest having a new access control directive that permits or <br>
denies annotations to be mapped when the CONNECT is bumped. That would <br>
allow any existing annotation of the CONNECT transaction to be applied <br>
as a connection-annotation for the bump'ed request.<br>
<br>
HTH<br>
Amos<br>
<br>
_______________________________________________<br>
squid-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">squi=
[email protected]</a><br>
<a href=3D"https://lists.squid-cache.org/listinfo/squid-users" rel=3D"noref=
errer" target=3D"_blank">https://lists.squid-cache.org/listinfo/squid-users=
</a><br>
</blockquote></div>
--00000000000012613c064c46f38c--
--===============4512976895275270062==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users
--===============4512976895275270062==--