Hi there!
Would it possible to verify that authentication headers that prompt the username/password/domain dialog come from the Cassini, and not from the proxy? The reson we ask is to our knowledge UltiDev Cassini does not add any authentication headers on its own, so in effect it's always configured for anonymous access only. We are not sure what logging capabilities Apache has, but the idea is to intercept requests and responses traveling between first, client and proxy, and then between proxy and Cassini - to see who's adding authentication headers to the response. Also, just in case, is it possible that your web service application itself is adding authentication headers to the response?
Best regards,
UltiDev Team.
Please donate at
http://www.ultidev.com/products/Donate.aspx to help us improve our products.