On Wed, Jan 13, 2010 at 12:14 AM, Matt Richards <matt@xxxxxxxxxxxxx> wrote: > Hello, > > I currently have a squid proxy setup and running with AD authentication and SSO. > > My question is ... is it possiable to have squid only attempt to authenticate via kerberos for machines that are a > member of the AD domain? > > If needed I can write a script that queries the AD LDAP database for the machine object. No. Your best option is to have a dual-squid setup, and use different client configurations for machines in/not in the domain (or something like transparent-for-non-domain and explicitly-configured-for-domain-members). -- /kinkie