Search squid archive

Re: Cache_peer login password encryption

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 28/08/18 11:52 PM, Hariharan Sethuraman wrote:
> Thanks Amos, let me explain my understanding. Please correct if wrong.
> The parent proxy (that is configured in cache_peer) does a basic
> authentication with the squid which will be transferred in plain text
> even if communication with cache_peer is going to be https based. Correct?
> 

You mean the connection to the peer uses TLS ?
 In that case the encryption is taken care of by the TLS layer. The
proxy and its peer are still talking regular HTTP over that connection.

The Basic auth password still needs to be unencrypted for Squid to
generate the correct HTTP message headers for the peer.

If you need secure passwords use Kerberos (Negotiate auth) between the
peers.

Amos
_______________________________________________
squid-users mailing list
squid-users@xxxxxxxxxxxxxxxxxxxxx
http://lists.squid-cache.org/listinfo/squid-users




[Index of Archives]     [Linux Audio Users]     [Samba]     [Big List of Linux Books]     [Linux USB]     [Yosemite News]

  Powered by Linux