[squid-users] Squid - LDAP

From: Franco, Battista <Battista.Franco@dont-contact.us>
Date: Mon, 13 Feb 2006 14:41:39 +0100

Hello
I use squid 2.5stable9 on fedora core 4.
I want use squid with ldap (Windows 2003) authentications.
Client doesn't work and access.log file is:
1139839762.746 0 10.239.57.19 TCP_DENIED/407 1784 GET
http://www.microsoft.com/isapi/redir.dll? - NONE/- text/html

My squid.conf is:
.....
auth_param basic program /usr/lib/squid/squid_ldap_auth -R -b
"dc=xx,dc=yyy,dc=uuuu,dc=rrrr" -f sAMAccountName=%s -h 10.239.56.2
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
.....
acl password proxy_auth REQUIRED
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563 407
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 407
acl CONNECT method CONNECT
http_access allow manager localhost
http_access allow password
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access deny all
....
cache_peer another-proxy.xxxx.com parent 8080 0 proxy-only default
#

Which is the problem?
 
Received on Mon Feb 13 2006 - 06:41:47 MST

This archive was generated by hypermail pre-2.1.9 : Wed Mar 01 2006 - 12:00:03 MST