Re: Fwd: RE: [squid-users] ntlm authentication

From: dhana krishnan <dhanseker@dont-contact.us>
Date: Thu, 30 May 2002 07:04:09 +0100 (BST)

Hello Henrik,

        Thansk for your reply. I can able to ping.
I've already added netbios anme in /etc/hosts file.
But in squid.conf, when i added ip(domain
controller)as
auth_param ntlm program
/usr/local/squid/libexec/ntlm_auth
domainame/172.16.1.3

ntlm_auth won't works...same error in both log files
as in previous mail.

once when i added domaincontrollername instead of IP,
ntlm_auth works fine(able to access pages) with
following error in cache.log file.

auth_param ntlm program
/usr/local/squid/libexec/ntlm_auth
domainame/domaincontroller name

cache.log shows..
Reviving DC
ntlm-auth[772](ntlm_auth.c:244): attempting challenge
retrieval
ntlm-auth[772](libntlmssp.c:119): Connecting to server
172.16.1.3 domain DOMAIN
ntlm-auth[772](libntlmssp.c:126): Couldn't connect to
SMB Server. Error:The attempt to call the remote
server failed. See protocol error info.
        RFCNBE_CallRejCNNP: Call rejected. Called name
not present.
ntlm-auth[772](ntlm_auth.c:246): make_challenge
retuned (nil)
ntlm-auth[772](ntlm_auth.c:252): Marking DC as DEAD
ntlm-auth[772](ntlm_auth.c:255): moving on to next
controller
ntlm-auth[823](ntlm_auth.c:232): obtain_challenge:
selecting DOMAIN\172.16.1.3 (attempt #1)
......

what may be wrong?

Thansk and Regards,
-dhana

 --- Henrik Nordstrom <hno@squid-cache.org> wrote: >
Your Squid server does not seem to know the address
> of your selected NT
> login servers.. It needs to know these by name.
>
> Can you ping the servers by their netbios name? If
> not, add them to your
> /etc/hosts file...
>
>
> dhana krishnan wrote:
> >
> > Hello Henrik,
> >
> > I'm using ntlm_auth on WINNT4.0 domain controller
> not
> > winbind. while trying to browse, only error
> results.
> > I'm getting following messages(errors) in
> cache.log.
> >
> > ntlm-auth[672](ntlm_auth.c:277): managing request
> > ntlm-auth[672](ntlm_auth.c:283): ntlm
> authenticator.
> > Got 'YR' from Squid
> > ntlm-auth[672](ntlm_auth.c:232): obtain_challenge:
> > selecting DOMAIN\172.16.1.3 (attempt #1)
> > ntlm-auth[672](ntlm_auth.c:244): attempting
> challenge
> > retrieval
> > ntlm-auth[672](libntlmssp.c:119): Connecting to
> server
> > 172.16.1.3 domain DOMAIN
> > ntlm-auth[672](libntlmssp.c:126): Couldn't connect
> to
> > SMB Server. Error:The attempt to call the remote
> > server failed. See protocol error info.
> > RFCNBE_CallRejCNNP: Call rejected. Called
> name
> > not present.
> > ntlm-auth[672](ntlm_auth.c:246): make_challenge
> > retuned (nil)
> > ntlm-auth[672](ntlm_auth.c:252): Marking DC as
> DEAD
> > ntlm-auth[672](ntlm_auth.c:255): moving on to next
> > controller
> >
> > and in access.log ,i'm getting TCP_DENIED/407.
> > Don't know what may be the problem.
> >
> > Thansk...
> > -dhana
> >
> > --- Henrik Nordstrom <hno@marasystems.com> wrote:
> >
> > dhana krishnan wrote:
> > > > Does squid NTLM works with WINNT4.0 domain
> > > controller?
> > >
> > > Yes, NTLM needs a NT domain controller or server
> > > where to you want to
> > > authenticate..
> > >
> > > > if so, howto configure winnt domain controller
> to
> > > use ntlm?
> > >
> > > Nothing special needs to be configured on the NT
> > > side of things when using
> > > the SMB helper (ntlm_auth). If using winbind
> then
> > > you need to set up a
> > > workstation/server account for your winbind
> server..
> > > (see the Samba winbind
> > > installation instructions).
> > >
> > > Regards
> > > Henrik
> >
> >
>
________________________________________________________________________
> > Everything you always wanted to know about cars
> and bikes,now
> > at:
http://in.autos.yahoo.com/cricket/tracker.html

________________________________________________________________________
Everything you always wanted to know about cars and bikes,now
 at: http://in.autos.yahoo.com/cricket/tracker.html
Received on Thu May 30 2002 - 00:04:13 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:08:16 MST