Thanks for the reply. So even if I get this ACL working they would have to authenticate whenever a new browser window is launched? If that's the case I'll have to go back to NTLM, which I didn't want to do since it's being phased out. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-ldap-auth-tp2126169p2130862.html Sent from the Squid - Users mailing list archive at Nabble.com.