From: "Половников Денис" <itech@avtoprognoz.ru> To: ALT Linux Community general discussions <community@lists.altlinux.org> Subject: [Comm] Squid+Ad проблема Date: Thu, 14 Aug 2008 17:27:25 +0400 Message-ID: <1285600986.20080814172725@avtoprognoz.ru> (raw) Здравствуйте, ALT. Подскажите в чем может быть трабла с ntlm_auth авторизацией в домене win2003. Сквид работает в режиме траспоренд прокси. В общем много страного и непонятного творится с этим сквидом. Берем юзверя и пихаем его в группу Internet в AD в аклах написано что ему доступ разрешон. В итоге при конекте получаем акцес денайт от сквида. Из командной строки хелпер проходит авторизацию отлично. Ниже приведен конфиг. ПОмогите а то уже голова пухнет перечитал кучу сайтов в инете везде написано что все должно быть ок. auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp auth_param ntlm children 10 auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic auth_param basic children 5 auth_param basic realm Squid proxy-caching web server auth_param basic credentialsttl 2 hours auth_param basic casesensitive off acl all src 0.0.0.0/0.0.0.0 acl manager proto cache_object acl localhost src 127.0.0.1/255.255.255.255 acl to_localhost dst 127.0.0.0/8 acl SSL_ports port 443 # https acl SSL_ports port 563 # snews acl Rsync_ports port 873 acl Jabber_ports port 5222 5223 acl ICQ_ports port 5190 # ICQ acl Safe_ports port 80 # http acl Safe_ports port 21 # ftp acl Safe_ports port 443 # https acl Safe_ports port 70 # gopher acl Safe_ports port 210 # wais acl Safe_ports port 1025-65535 # unregistered ports acl Safe_ports port 280 # http-mgmt acl Safe_ports port 488 # gss-http acl Safe_ports port 563 # snews acl Safe_ports port 591 # filemaker acl Safe_ports port 777 # multiling http acl Safe_ports port 631 # cups acl Safe_ports port 873 # rsync acl Safe_ports port 901 # SWAT acl CONNECT method CONNECT external_acl_type nt_group %LOGIN /usr/lib/squid/wbinfo_group.pl # only ICQ acl inet_icq external nt_group icqinternet # full inet acl inet_full external nt_group internet # Avtorizaciya acl MYDOMAIN proxy_auth REQUIRED acl bad_url url_regex "/etc/squid/db/deny_url" acl deny_domains dstdomain "/etc/squid/db/deny_domains" acl bad_networks dst "/etc/squid/db/bad_networks" http_access deny manager http_access deny !Safe_ports http_access deny CONNECT !SSL_ports !Jabber_ports !Rsync_ports http_access allow MYDOMAIN http_access deny bad_url http_access allow inet_icq ICQ_ports http_access deny bad_networks http_access deny deny_domains http_access allow localhost http_access allow inet_full http_access deny all -- С уважением, Половников Денис mailto:itech@avtoprognoz.ru
next reply other threads:[~2008-08-14 13:27 UTC|newest] Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top 2008-08-14 13:27 Половников Денис [this message] 2008-08-14 13:43 ` Roman V. Tutov 2008-08-14 14:00 ` Алексей Шенцев 2008-08-14 14:00 ` Половников Денис 2008-08-14 14:02 ` Алексей Шенцев 2008-08-14 14:06 ` Alexey I. Froloff 2008-08-15 6:44 ` Половников Денис 2008-08-15 8:18 ` Alexey I. Froloff
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=1285600986.20080814172725@avtoprognoz.ru \ --to=itech@avtoprognoz.ru \ --cc=community@lists.altlinux.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
ALT Linux Community general discussions This inbox may be cloned and mirrored by anyone: git clone --mirror http://lore.altlinux.org/community/0 community/git/0.git # If you have public-inbox 1.1+ installed, you may # initialize and index your mirror using the following commands: public-inbox-init -V2 community community/ http://lore.altlinux.org/community \ mandrake-russian@linuxteam.iplabs.ru community@lists.altlinux.org community@lists.altlinux.ru community@lists.altlinux.com public-inbox-index community Example config snippet for mirrors. Newsgroup available over NNTP: nntp://lore.altlinux.org/org.altlinux.lists.community AGPL code for this site: git clone https://public-inbox.org/public-inbox.git