[squid-users] Authentication to Active Directory

From: Johan de Vries <johan.devries@dont-contact.us>
Date: Tue, 27 Apr 2004 11:45:50 +0200

Hi all,

I am a little bit confused about the setup of Squid with authentication to Active Directory
I am using: RedHat 9 Squid 2.5 Samba 3.0.2 Windows Server 2000

In the Squid manual is the line:
Squid writes cleartext usernames and passwords when talking to the external authentication processes
In our AD setup is the use of plaintext passwords not allowed
Still I want Squid to authenticate to the AD domain
How can this be set up ?
What do I really need ?

The Squid manual is talking about a:
NTLM challenge/response authentication against an NT domain controller

In my opinion I don't need the NTLM stuff when I use the AD system
Is this correct ?

Questions about the winbindd daemon:
I compiled Samba with: --with-ads --with-acl-support --with-winbind --with-winbind-auth-challenge
When I start the winbindd and do a: net ads join
then commands like: wbinfo -u will work
Still there are errors in the log like:
SPENGO login failed: Logon failure
Kinit failed: Preauthentication failed

These errors are gone when I do a: net rpc join
Can these errors be ignored, or do I really need to join the rpc domain ?

Regards,
Johan
Received on Tue Apr 27 2004 - 03:45:52 MDT

This archive was generated by hypermail pre-2.1.9 : Fri Apr 30 2004 - 12:00:02 MDT