Secure Transfer of proxy_auth passwords

From: <sdmatott+squid@dont-contact.us>
Date: Mon, 24 Jan 2000 13:33:42 -0600

Hey all,
        I assume that by default squid sends proxy_auth passwords
as plain text across the web.
        In other words, when it prompts users for a u-name and passwd
it then beams these two back to itself as plain-text to be handed over to the
proxy_auth program, (eg. ncsa_auth or whatever)
        Is this true?
        If so does anyone know of a way around this, ie a way to make squid
encrypt passwd's as it sends them across the web, or maybe a way to use
a challenge/response type system with squid?
        It would be nice it our users did not have to send their passwords
as plain text for all the internet to see.

        Well any ideas?
Thanks,
        Scott Matott sXe
        
Received on Mon Jan 24 2000 - 12:42:31 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:50:40 MST