Re: [squid-users] Ntlm authentication down to groups

From: Henrik Nordstrom <hno@dont-contact.us>
Date: 25 Jun 2003 12:36:38 +0200

ons 2003-06-25 klockan 11.35 skrev Mueller, Thomas:
> Dear Henrik, list,
>
> i think that i have read for a few days that is possible to authenticate
> users from
> a NT Domain down to groups in Squid 2.5.

Yes.

> 1)
> The authentication for users from my NT Domain is working fine, but i'm
> wondering why I get this
> Error message in the message file:
>
> Jun 25 10:59:10 proxy2 msnt_auth[14106]: AddServer: Ignoring host 'my_PDC'.
> Cannot resolve its address.

As it says. Your server does not know how to find the host "my_PDC" in
your network.

> Jun 25 10:59:10 proxy2 msnt_auth[14106]: OpenConfigFile: No servers set in
> /etc/squid/msntauth.conf. At least one is needed.

Then authentication should not work at all..

> "nslookup" is working for my pdc and bdc on this server, i also added them
> in the "hosts" file.....so what's wrong?

Check your spelling.

> 2)Is it possible to exclude Domain Users by entering the WinNT DomainUser
> name in the "msntauth.denyusers"?

Yes.

> 3) Can I tell squid only to authenticate users from my NT Domain which are
> in the group "internet" for example?

Not with this helper.

I would recommend using the winbind helpers. See the Squid FAQ for
installation instructions.

Regards
Henrik

-- 
Donations welcome if you consider my Free Squid support helpful.
https://www.paypal.com/xclick/business=hno%40squid-cache.org
Please consult the Squid FAQ and other available documentation before
asking Squid questions, and use the squid-users mailing-list when no
answer can be found. Private support questions is only answered
for a fee or as part of a commercial Squid support contract.
If you need commercial Squid support or cost effective Squid and
firewall appliances please refer to MARA Systems AB, Sweden
http://www.marasystems.com/, info@marasystems.com
Received on Wed Jun 25 2003 - 04:36:45 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:17:38 MST