Hi I followed http://wiki.squid-cache.org/ConfigExamples/Authenticate/WindowsActiveDirectory I can see the cache.log the the client is authenticating with a Kerberos ticket however for every connection get a TCP/DENIED 407 and then the connection is made. Is this not what NTLM does? I thought that with Kerberos this does not happen? I have a very strange issue we are using Zimbra Desktop client and with the proxy settings the Zimbra Desktop client fails to connect.. TCP_DENIED/407 2173 CONNECT cluster01.zimbra.com:443 - NONE/- text/html but all the other browsers (IE,FF,Chrome) everything works but the log is full of TCP/DENIED 407. Any help should be appreciated SQUID3 Stable19