Shibboleth and Squid Proxy
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 1 10:03:33 EDT 2013
> I've buried a significant amount of time on that quest, the "normal" web
> proxy behaviour, that is. My present conclusion: it is not possible as
> things are ATM. I'm looking for alternative ways. The HTTP proxy
> protocol does not mix well with SAML redirections. There seem to be
> other options, but I've not yet had the time to investigate them. Maybe
> others in this list can provide you with different opinions.
There is absolutely no way to do anything reasonable with the standard forward proxy model in HTTP, that's limited to authentication methods that are supported directly in HTTP. The closest you'll get to a "real" method would be SPNEGO or client TLS (and that would depend on client and Squid support).
I know nothing about Squid, so couldn't say what's possible in a reverse proxy mode.
-- Scott
More information about the users
mailing list