On Fri, Sep 09, 2011 at 03:42:21PM +0100, Markus Moeller wrote: > You need to create one AD entry for proxy.domain.tld and copy the > same keytab to both squid servers and use the -s GSS_C_NO_NAME > option for squid_kerb_auth or negotiate_kerberos_auth. > at a first glance, it seems to works like a charm, many thanks :)