Re: [squid-users] Authentification via samba 3.0 to an active directory server

From: Markus Meissner <mm645380@dont-contact.us>
Date: Fri, 15 Aug 2003 10:39:09 +0200

On Thursday 14 August 2003 17:07, Henrik Nordstrom wrote:
> On Thu, 14 Aug 2003, Markus Meissner wrote:
> > Hm, sounds good, but... I don't know how to find it. lsof gives me many
> > files, doing a grep on squid has still a lot of files, none of them looks
> > like a named pipe. I have some "pipes" in the output, but they don't have
> > a filename. What should I do?
>
> What you need to look for is what files the ntlm_auth and winbind
> processes have open. It is not relevant what files Squid has open.

OK, I understand. There is a pipe open at /tmp/.winbindd/pipe. The directory
is accessable for the squid-user (ntlm_auth runs as squid user) and the pipe
itself is srwxrwxrwx. So this should work. There is another pipe at
/var/cache/samba/winbindd_privileged which is only accessable by root, but I
_think_ that this is OK. To stay on the safe side I have made it accessable
by everyone but it doesn't help.

I will emphasize that everything on the smb-side works, I can even call
ntlm_auth with parameters (--domain, --username etc) and it works (->
NT_STATUS_OK: Success (0x0))! My conclusion is that it can only be the
communication beteween squid and ntlm_auth, but I know far to less from squid
and ntlm_auth.

-- 
Beste Gruesse / Best regards Markus Meissner
Received on Fri Aug 15 2003 - 02:39:22 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:18:55 MST