5183f0
diff --git a/modules/proxy/mod_proxy.c b/modules/proxy/mod_proxy.c
5183f0
index d13c249..f383996 100644
5183f0
--- a/modules/proxy/mod_proxy.c
5183f0
+++ b/modules/proxy/mod_proxy.c
5183f0
@@ -1200,11 +1200,20 @@ static int proxy_handler(request_rec *r)
5183f0
                     /* handle the scheme */
5183f0
                     ap_log_rerror(APLOG_MARK, APLOG_DEBUG, 0, r, APLOGNO(01142)
5183f0
                                   "Trying to run scheme_handler against proxy");
5183f0
+
5183f0
+                    if (ents[i].creds) {
5183f0
+                        apr_table_set(r->notes, "proxy-basic-creds", ents[i].creds);
5183f0
+                        ap_log_rerror(APLOG_MARK, APLOG_TRACE1, 0, r,
5183f0
+                                      "Using proxy auth creds %s", ents[i].creds);
5183f0
+                    }
5183f0
+
5183f0
                     access_status = proxy_run_scheme_handler(r, worker,
5183f0
                                                              conf, url,
5183f0
                                                              ents[i].hostname,
5183f0
                                                              ents[i].port);
5183f0
 
5183f0
+                    if (ents[i].creds) apr_table_unset(r->notes, "proxy-basic-creds");
5183f0
+
5183f0
                     /* Did the scheme handler process the request? */
5183f0
                     if (access_status != DECLINED) {
5183f0
                         const char *cl_a;
5183f0
@@ -1621,8 +1630,8 @@ static void *merge_proxy_dir_config(apr_pool_t *p, void *basev, void *addv)
5183f0
     return new;
5183f0
 }
5183f0
 
5183f0
-static const char *
5183f0
-    add_proxy(cmd_parms *cmd, void *dummy, const char *f1, const char *r1, int regex)
5183f0
+static const char *add_proxy(cmd_parms *cmd, void *dummy, const char *f1,
5183f0
+                             const char *r1, const char *creds, int regex)
5183f0
 {
5183f0
     server_rec *s = cmd->server;
5183f0
     proxy_server_conf *conf =
5183f0
@@ -1680,19 +1689,24 @@ static const char *
5183f0
     new->port = port;
5183f0
     new->regexp = reg;
5183f0
     new->use_regex = regex;
5183f0
+    if (creds) {
5183f0
+        new->creds = apr_pstrcat(cmd->pool, "Basic ",
5183f0
+                                 ap_pbase64encode(cmd->pool, (char *)creds),
5183f0
+                                 NULL);
5183f0
+    }
5183f0
     return NULL;
5183f0
 }
5183f0
 
5183f0
-static const char *
5183f0
-    add_proxy_noregex(cmd_parms *cmd, void *dummy, const char *f1, const char *r1)
5183f0
+static const char *add_proxy_noregex(cmd_parms *cmd, void *dummy, const char *f1,
5183f0
+                                     const char *r1, const char *creds)
5183f0
 {
5183f0
-    return add_proxy(cmd, dummy, f1, r1, 0);
5183f0
+    return add_proxy(cmd, dummy, f1, r1, creds, 0);
5183f0
 }
5183f0
 
5183f0
-static const char *
5183f0
-    add_proxy_regex(cmd_parms *cmd, void *dummy, const char *f1, const char *r1)
5183f0
+static const char *add_proxy_regex(cmd_parms *cmd, void *dummy, const char *f1,
5183f0
+                                   const char *r1, const char *creds)
5183f0
 {
5183f0
-    return add_proxy(cmd, dummy, f1, r1, 1);
5183f0
+    return add_proxy(cmd, dummy, f1, r1, creds, 1);
5183f0
 }
5183f0
 
5183f0
 PROXY_DECLARE(const char *) ap_proxy_de_socketfy(apr_pool_t *p, const char *url)
5183f0
@@ -2638,9 +2652,9 @@ static const command_rec proxy_cmds[] =
5183f0
     "location, in regular expression syntax"),
5183f0
     AP_INIT_FLAG("ProxyRequests", set_proxy_req, NULL, RSRC_CONF,
5183f0
      "on if the true proxy requests should be accepted"),
5183f0
-    AP_INIT_TAKE2("ProxyRemote", add_proxy_noregex, NULL, RSRC_CONF,
5183f0
+    AP_INIT_TAKE23("ProxyRemote", add_proxy_noregex, NULL, RSRC_CONF,
5183f0
      "a scheme, partial URL or '*' and a proxy server"),
5183f0
-    AP_INIT_TAKE2("ProxyRemoteMatch", add_proxy_regex, NULL, RSRC_CONF,
5183f0
+    AP_INIT_TAKE23("ProxyRemoteMatch", add_proxy_regex, NULL, RSRC_CONF,
5183f0
      "a regex pattern and a proxy server"),
5183f0
     AP_INIT_FLAG("ProxyPassInterpolateEnv", ap_set_flag_slot_char,
5183f0
         (void*)APR_OFFSETOF(proxy_dir_conf, interpolate_env),
5183f0
diff --git a/modules/proxy/mod_proxy.h b/modules/proxy/mod_proxy.h
5183f0
index 288c5d4..57cc92f 100644
5183f0
--- a/modules/proxy/mod_proxy.h
5183f0
+++ b/modules/proxy/mod_proxy.h
5183f0
@@ -116,6 +116,7 @@ struct proxy_remote {
5183f0
     const char *protocol;   /* the scheme used to talk to this proxy */
5183f0
     const char *hostname;   /* the hostname of this proxy */
5183f0
     ap_regex_t *regexp;     /* compiled regex (if any) for the remote */
5183f0
+    const char *creds;      /* auth credentials (if any) for the proxy */
5183f0
     int use_regex;          /* simple boolean. True if we have a regex pattern */
5183f0
     apr_port_t  port;       /* the port for this proxy */
5183f0
 };
5183f0
diff --git a/modules/proxy/proxy_util.c b/modules/proxy/proxy_util.c
5183f0
index 0759dac..2bfc8f0 100644
5183f0
--- a/modules/proxy/proxy_util.c
5183f0
+++ b/modules/proxy/proxy_util.c
5183f0
@@ -2446,11 +2446,14 @@ ap_proxy_determine_connection(apr_pool_t *p, request_rec *r,
5183f0
                      * So let's make it configurable by env.
5183f0
                      * The logic here is the same used in mod_proxy_http.
5183f0
                      */
5183f0
-                    proxy_auth = apr_table_get(r->headers_in, "Proxy-Authorization");
5183f0
+                    proxy_auth = apr_table_get(r->notes, "proxy-basic-creds");
5183f0
+                    if (proxy_auth == NULL)
5183f0
+                        proxy_auth = apr_table_get(r->headers_in, "Proxy-Authorization");
5183f0
+
5183f0
                     if (proxy_auth != NULL &&
5183f0
                         proxy_auth[0] != '\0' &&
5183f0
-                        r->user == NULL && /* we haven't yet authenticated */
5183f0
-                        apr_table_get(r->subprocess_env, "Proxy-Chain-Auth")) {
5183f0
+                        (r->user == NULL  /* we haven't yet authenticated */
5183f0
+                         || apr_table_get(r->subprocess_env, "Proxy-Chain-Auth"))) {
5183f0
                         forward->proxy_auth = apr_pstrdup(conn->pool, proxy_auth);
5183f0
                     }
5183f0
                 }
5183f0
@@ -2672,7 +2675,8 @@ static apr_status_t send_http_connect(proxy_conn_rec *backend,
5183f0
     nbytes = apr_snprintf(buffer, sizeof(buffer),
5183f0
                           "CONNECT %s:%d HTTP/1.0" CRLF,
5183f0
                           forward->target_host, forward->target_port);
5183f0
-    /* Add proxy authorization from the initial request if necessary */
5183f0
+    /* Add proxy authorization from the configuration, or initial
5183f0
+     * request if necessary */
5183f0
     if (forward->proxy_auth != NULL) {
5183f0
         nbytes += apr_snprintf(buffer + nbytes, sizeof(buffer) - nbytes,
5183f0
                                "Proxy-Authorization: %s" CRLF,
5183f0
@@ -3567,6 +3571,7 @@ PROXY_DECLARE(int) ap_proxy_create_hdrbrgd(apr_pool_t *p,
5183f0
     apr_bucket *e;
5183f0
     int do_100_continue;
5183f0
     conn_rec *origin = p_conn->connection;
5183f0
+    const char *creds;
5183f0
     proxy_dir_conf *dconf = ap_get_module_config(r->per_dir_config, &proxy_module);
5183f0
 
5183f0
     /*
5183f0
@@ -3743,6 +3748,11 @@ PROXY_DECLARE(int) ap_proxy_create_hdrbrgd(apr_pool_t *p,
5183f0
         return HTTP_BAD_REQUEST;
5183f0
     }
5183f0
 
5183f0
+    creds = apr_table_get(r->notes, "proxy-basic-creds");
5183f0
+    if (creds) {
5183f0
+        apr_table_mergen(r->headers_in, "Proxy-Authorization", creds);
5183f0
+    }
5183f0
+
5183f0
     /* send request headers */
5183f0
     headers_in_array = apr_table_elts(r->headers_in);
5183f0
     headers_in = (const apr_table_entry_t *) headers_in_array->elts;