[squid-users] Re: squid + winbind weird behavior

From: Adam Aube <aaube01@dont-contact.us>
Date: Fri, 18 Feb 2005 20:17:06 -0500

Please don't top post (which is replying above the original message) - it
makes the thread hard to follow.

Paulo Pires wrote:
> Qui, 2005-02-17 ās 00:40 +0100, Henrik Nordstrom escreveu:
>> On Wed, 16 Feb 2005, Paulo Pires wrote:
>>
>> > chown nobody /usr/local/samba-3.0.10/var/locks/winbindd_privileged
>> >
>> > This solved the thing. We can't change the perms cause it's a socket,
>> > so it's better to change the owner to the user which runs squid.
>>
>> You should change the group, not the owner..
>>
>> http://www.squid-cache.org/Doc/FAQ/FAQ-23.html#ss23.5
>> http://us4.samba.org/samba/docs/man/winbindd.8.html
>>
>> Changing the owner will make Samba quite upset about the security.

> chgrp squid /path/to/winbind_privileged

> I've added squid group, added user nobody into it and put it in my
> squid.conf. But as you can see below, there's only read perms for squid
> group, so the error is still there.
>
> 4 drwxr-s--- 2 root squid 4096 2005-02-17 14:15 winbindd_privileged
>
> I don't know how the hell this worked for others, since other users from
> squid will only have read access to the dir, when they should have
> execute permissions too.

They do have execute permissions - the "s" in that position means the
directory is group executable and SetGID.

Adam
Received on Fri Feb 18 2005 - 18:17:26 MST

This archive was generated by hypermail pre-2.1.9 : Tue Mar 01 2005 - 12:00:02 MST