RE: [squid-users] Squid authentication to a Samba domain controller

From: Lux <squid@dont-contact.us>
Date: Sat, 17 Mar 2007 13:32:20 +0100

> From: Kinkie [mailto:kinkie-squid@kinkie.it]
> Sent: Saturday, March 17, 2007 9:11 AM

> On Sat, 2007-03-17 at 07:56 +0100, Lux wrote:
> > Hi all
> >
> > I'd like Squid to authenticate, possibly transparently with
> ntlm, to a Samba
> > Domain Controller.
> > I found, and used in other cases, plenty of documentation about
> doing this
> > but with a Windows domain, via winbindd and ntlm_auth. But this approach
> > seems not to be usable when the Squid box is also a Samba
> domain controller.
> > Any ideas? Pointers to docs are appreciated.
>
> It should work just the same.
> In what ways is your attempt failing?

You're right. I simply forgot to join the Samba machine to the domain with
net rpc join, so ntlm_auth was failing.
I noticed that the command "wbinfo -u" gives "Error looking up domain users"
on a Samba DC, whereas it returns the list of usernames when it is issued on
a member server. I tried this on different Samba domain controllers too.
This led me to think that the Samba domain controller setup was going to be
different at all.
Now I joined the machine to the domain, and ntlm_auth --username
xxx --password xxx is working good. Unfortunately I'm not able to try the
whole squid functionality with a real browser at the moment, but I think
it's likely to be ok now.

Thank you.
Luigi
Received on Sat Mar 17 2007 - 06:31:26 MDT

This archive was generated by hypermail pre-2.1.9 : Sat Mar 31 2007 - 13:00:02 MDT