User Proxy Settings

Is there any way of forcing the proxy username and password to be the login name and password. The problem I have is students not clicking the save to keychain clickbox, then using other peoples proxy login and password as it may have different permissions.

On windows this comes from the active directory, is there a similar setting I can set on the Mac?

Many Thanks

PowerBook G4 867Mhz, Mac OS X (10.4.3), PowerMac G5 2x2Ghz

Posted on Aug 24, 2010 5:37 AM

Reply
8 replies

Aug 24, 2010 6:30 AM in response to MrHoffman

Macs are bound to Active Directory and Snow Leopard Server. User policies are set by the Apple servers, directory authentication by the windows 2003 servers.

Problem is I need to be able to set the proxy user name and password from the directory somehow. We enforce internet settings on the active directory user rather than by machine address as some users require different settings.

Aug 24, 2010 6:47 AM in response to MrHoffman

Every student has an account, there is no session sharing, the security hole is that Mac OS X requires the user to save their proxy server settings in the keychain. If they choose not to click this then they can use other peoples logins as authentication for the proxy server.

The Web Proxy is a Microsoft ISA server, authenticated against active directory.

I'm looking for a way of telling the system to use the login name and password and not ask the user to input it.

Message was edited by: Mark Cain

Aug 24, 2010 7:33 AM in response to Mark Cain

Microsoft ISA can authenticate via various means including your mentioned AD, Kerberos and various LDAP schemes, which implies there's a problematic authentication means here or there's a misconfiguration of some sort. This particularly if the users are re-using previous credentials; that's (badness) occurring out at the ISA box.

I'm not an ISA expert, and I'm not at all current on Microsoft technologies. You might want to check in a more Microsoft-focused forum, and particularly search for discussions of operating ISA with Linux (yes, Linux), Unix, or Mac OS X clients; with non-Microsoft platforms.

Based on some digging, it looks like MCX might be your path forward if you want to get Mac OS X hard-wired with these and not go near the ISA box configuration; the 10.6 Proxies set-up does provide for proxy credentials, and the path into that storage (if you're auto-configuring) is usually via the user's input or via MCX.

This possibly in conjunction with the [WPAD proxy autoconfiguration|http://tips4macosx.blogspot.com/2009/07/use-web-proxy-auto-di scovery-in-safari.html] setting. (And there's an interesting thread [here|http://forums.isaserver.org/m 2002033963/mpage_1/key/tm.htm#2002033963] related to proxy authentication)

Check with the Microsoft ISA folks and forums, too. This can't be the first time they've encountered Linux (and I'd start there, with this question; most any "foreign" system OS will do for the purposes of the initial question) or Mac OS X boxes.

Sep 9, 2010 1:08 AM in response to MrHoffman

There is no problem with the ISA server. We have the same issue. The problem is that OSX server does not seem to allow you to add authentication settings when adding a Web Proxy to either users or machines.

We have introdued an XServe into our windows network recently and are having the same problem. The windows machines have a group policy to enforce the web-proxy authentication comes from their domain logon which they use to login into the machine.

Though our OD is bound to the AD and the users use their AD domain logons for the macs also, I can't find a way to auto-authenticate the users to the web-proxy. When they open a browser, because their machine or accounts are set to connect to WAN through the proxy, they get a request to authenticate.

Anyone know how to solve this problem?

Oct 5, 2010 6:20 AM in response to jimiknight

Jimi,

We are currently facing the same dilemma. Macs authenticate via AD and are managed with the OD. I would be really curious if you have found a way around this. I tried to use WGM to set a Login option, using an item which was essentially the PAC file URL. WGM has an option to "Authenticate a selected share-point with the user's login name and password". This has worked in the past for mounting shares but not with auto authenticating a proxy. If you have any ideas I would greatly appreciate hearing them.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

User Proxy Settings

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.