RE: [squid-users] Having trouble with win32_check_group (SquidNT )

From: Serassio Guido <guido.serassio@dont-contact.us>
Date: Fri, 24 Dec 2004 12:11:26 +0100

Hi,

At 11.26 24/12/2004, Holton, Euan wrote:

>When running Squid in a domain user context (either from a command prompt
>or setting the "log in as" properties for the service), it works fine.

OK, so it's a permissions problem on Your Active Directory: the local
SYSTEM account of your Squid machine cannot lookup for the users group
membership.
Now we need to understand why it works with the domain administrator account.

By default, the domain administrator account is placed in the Users Container.
Where are placed the other user accounts ?

A work around that I don't like much, if your Squid machine IS NOT a Domain
Controller, could be to add a standard user account to your AD domain,
place this user in local administrators group of the Squid machine and set
into its "Log On To ..." properties the Squid machine name.

>Yes, the account is a member of the "Pre-Windows 2000 Compatible Access"
>group, and the group does have various read permissions; however, whether
>they are correct I currently don't know (I am going to have a look into it
>now).

Just to be sure, please check if this applies to you:

http://support.microsoft.com/default.aspx?scid=kb;en-us;325363

Regards

Guido

-
========================================================
Guido Serassio
Acme Consulting S.r.l. - Microsoft Certified Partner
Via Gorizia, 69 10136 - Torino - ITALY
Tel. : +39.011.3249426 Fax. : +39.011.3293665
Email: guido.serassio@acmeconsulting.it
WWW: http://www.acmeconsulting.it/
Received on Fri Dec 24 2004 - 04:11:31 MST

This archive was generated by hypermail pre-2.1.9 : Sat Jan 01 2005 - 12:00:03 MST