<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: proxy server authenticating w/LDAP?</title>
	<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP/</link>
	<description>Comments on Ask MetaFilter post proxy server authenticating w/LDAP?</description>
	<pubDate>Tue, 02 Aug 2005 18:30:51 -0800</pubDate>
	<lastBuildDate>Tue, 02 Aug 2005 18:30:51 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: proxy server authenticating w/LDAP?</title>
		<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP</link>	
		<description>Anybody ever set up a proxy server that authenticates using an external LDAP server - so that (for example) off-campus university students can access third-party web services that are restricted to campus IP addresses?
 &lt;br /&gt;&lt;br /&gt; &lt;small&gt;&lt;small&gt;Well, it is worth a shot!&lt;/small&gt;&lt;/small&gt;&lt;br&gt;
&lt;br&gt;
I&apos;m guessing that I would be using Squid, but the configuration is intimidating the heck out of me. RTFM? Or do you have any pointers? I&apos;m not interested in caching - just authenticating and presenting a campus IP number to the third party services.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2005:site.22081</guid>
		<pubDate>Tue, 02 Aug 2005 17:56:46 -0800</pubDate>
		<dc:creator>spock</dc:creator>
		
			<category>LDAP</category>
		
			<category>proxy</category>
		
			<category>Squid</category>
		
			<category>authentication</category>
		
	</item> <item>
		<title>By: 445supermag</title>
		<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP#354890</link>	
		<description>Some schools already have this service, you may want to check before you go to too much trouble. I&apos;d call the library.  I have also used remote login on an XP computer on the school network (this assumes you have a login on an xp computer somewhere).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.22081-354890</guid>
		<pubDate>Tue, 02 Aug 2005 18:30:51 -0800</pubDate>
		<dc:creator>445supermag</dc:creator>
	</item><item>
		<title>By: roue</title>
		<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP#354930</link>	
		<description>EZproxy from useful utilities does this. Also check out libProxy. Same deal, harder setup (depends on apache 1.3 and mod_perl. &lt;br&gt;
 &lt;br&gt;
I&apos;m in the midst of setting this very thing up for the school I work at.  We chose EZProxy. It authenticated against ldap with about 4 lines of config code. Very easy.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.22081-354930</guid>
		<pubDate>Tue, 02 Aug 2005 19:47:02 -0800</pubDate>
		<dc:creator>roue</dc:creator>
	</item><item>
		<title>By: devilsbrigade</title>
		<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP#354952</link>	
		<description>A proxy should NEVER be used for this. You want a VPN. &lt;br&gt;
&lt;br&gt;
Oregon State University lets you use Cisco VPN as a client, which I assume means using Cisco routing, but I&apos;m sure there are other VPN solutions out there. &lt;br&gt;
&lt;br&gt;
Proxies have way, way too much risk. VPNs restrict the use to a certain set of domains/ips, plus can give access to network shares.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.22081-354952</guid>
		<pubDate>Tue, 02 Aug 2005 20:33:16 -0800</pubDate>
		<dc:creator>devilsbrigade</dc:creator>
	</item><item>
		<title>By: spock</title>
		<link>http://ask.metafilter.com/22081/proxy-server-authenticating-wLDAP#355017</link>	
		<description>I can&apos;t restrict to a certain set of domains/ips, devilsbrigade, because legitimate off-campus students could be connecting from anywhere. What risks are there for a student authenticating (via https) to get a proxy connection to a web server?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.22081-355017</guid>
		<pubDate>Tue, 02 Aug 2005 23:37:13 -0800</pubDate>
		<dc:creator>spock</dc:creator>
	</item>
	</channel>
</rss>
