[squid-users] RE: proxyauth for certain active directory users

From: Joseph L. Casale <JCasale_at_activenetwerx.com>
Date: Wed, 29 Jul 2009 19:07:10 +0000

>I have everything setup as documented but its not working. The
>proxy is joined to the domain, wbinfo -g/-u gives results. Without
>the --require-membership-of switch If I supply a valid domain users
>credentials it works. This is running latest build of 2.7.

>NTLM Authentiation
>auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp --require-membership-of="domain\somegroup"

I only have a production rig setup and I can't interrupt it,
but off the top of my head I would assume your winbind separator is
a "\" but if I recall the needed syntax when using the slash as a
separator, you need to escape the slash:)

Try a \\ and see if that works, or set winbind to use the default
domain possibly and just put the group name in?

Anyway, sorry for not being more precise, but that should help.
You can run ntlm_auth manually to view the output for debug purposes.
That should yield any config errors clearly.

jlc
Received on Wed Jul 29 2009 - 19:07:24 MDT

This archive was generated by hypermail 2.2.0 : Thu Jul 30 2009 - 12:00:05 MDT