RE: AW: AW: AW: [squid-users] squid_ldap_group authentication aga inst Act ive Directory

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Sat, 20 Dec 2003 23:50:37 +0100 (CET)

On Sat, 20 Dec 2003, Keppner, Christoph wrote:

> when i search with ldapsearch and filter (objectClass=groupOfNames), nothing

Then search for a group by CN and look what the objectClass in the AD is.

> external_acl_type ldap_group %LOGIN /usr/lib/squid/squid_ldap_group -b
> dc=dhc-gmbh,dc=com -D keppner@dhc-gmbh.com -w SeCrEt -f
> "(&(cn=%g)(member=%u)(objectClass=groupOfNames))" -F "(sAMAccountName=%s)"

The -D should be a DN, not a email address. But the helper should warn you
loudly if this is your problem.

Regards
Henrik
Received on Sat Dec 20 2003 - 15:50:47 MST

This archive was generated by hypermail pre-2.1.9 : Thu Jan 01 2004 - 12:00:18 MST