[squid-users] multiple authenticate_program clauses, and customer claimed squid asked both

From: Marc Haber <squid-users.ircache.net@dont-contact.us>
Date: Mon, 01 Oct 2001 19:05:13 +0200

Hi,

one customer of ours is running squid2.3.STABLE4 on FreeBSD
4.1-RELEASE, of which I don't have a clue. The squid conf has _two_
authenticate_program clauses, saying

authenticate_program smb_auth -W domain1 -U DC1
authenticate_program smb_auth -W domain2 -U DC2.

Customer claims that users from both domains were able to use the
proxy until yesterday. Right now, squid denies all requests
originating from domain2 users, and only the first smb_auth process
children (5 processes) authenticating against domain1 is currently
running. When I restart squid, only smb_auth domain1 children are
started.

All relevant docs I skimmed only mention _the_ authenticate_progam
which makes me believe that configuring two authenticate_program
clauses never worked as intended. But this is contrary to my
customer's claims, whom I tend to believe. Unfortunately, there are no
logs to verify.

Can anyone enlighten me about what's going on here? Is it possible
that both domain controllers were engaged in a trust relationship so
that DC1 forwarded all authentication requests for domain2 users to
DC2 without squid noticing?

Any hints will be appreciated.

Greetings
Marc

-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber          |   " Questions are the         | Mailadresse im Header
Karlsruhe, Germany  |     Beginning of Wisdom "     | Fon: *49 721 966 32 15
Nordisch by Nature  | Lt. Worf, TNG "Rightful Heir" | Fax: *49 721 966 31 29
Received on Mon Oct 01 2001 - 11:05:16 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:02:34 MST