Re: [squid-users] Problems with ntlm authentification ? what change from 2.6 to 3.0 ?

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Tue, 14 Oct 2008 22:10:06 +1300

Phibee Network Operation Center wrote:
> Amos Jeffries a écrit :
>>> Amos Jeffries a écrit :
>>>
>>>> Phibee Network Operation Center wrote:
>>>>
>>>>> Hi
>>>>>
>>>>> i use Squid with NTLM authentification on 2.6 version ...
>>>>>
>>>>> I have a new server and want run on Squid 3.0 but when i start the
>>>>> process,
>>>>> he shutdown and put into cache.log:
>>>>>
>>>>> 2008/10/13 06:39:33| Starting Squid Cache version 3.0.STABLE2 for
>>>>> i386-redhat-linux-gnu...
>>>>>
>>>> STABLE2 was severely broken with all authentication. Please do not use
>>>> under any circumstances.
>>>>
>>>> If possible please use the latest release (currently STABLE9) or if
>>>> not possible at least STABLE7+.
>>>>
>>>> Amos
>>>>
>>> Hi
>>>
>>> thanks for your answer, but no change with stable7 ;=)
>>>
>>
>> Same message about "Starting ... 3.0.STABLE2" ?
>>
>> The 10 or so lines lines above it should indicate why the shutdown took
>> place to begin with.
>>
>> Amos
>>
>>
>>
>>
> Hi
>
> i have deleted my old conf file and start a new with the default
> configuration and now the auth start correctly (i don't understand why
> bu it's good ..)
>
> but now a new problems:
>
>
> 2008/10/14 06:07:39| Starting Squid Cache version 3.0.STABLE7 for
> i386-redhat-linux-gnu...
> 2008/10/14 06:07:39| Process ID 26104
> 2008/10/14 06:07:39| With 1024 file descriptors available
> 2008/10/14 06:07:39| DNS Socket created at 0.0.0.0, port 53027, FD 7
> 2008/10/14 06:07:39| Adding domain srv1-v2.sodiaal.ophelys.org from
> /etc/resolv.conf
> 2008/10/14 06:07:39| Adding nameserver 127.0.0.1 from /etc/resolv.conf
> 2008/10/14 06:07:39| helperStatefulOpenServers: Starting 15 'ntlm_auth'
> processes
> 2008/10/14 06:07:39| helperOpenServers: Starting 15 'ntlm_auth' processes
> 2008/10/14 06:07:39| helperOpenServers: Starting 5 'wbinfo_group.pl'
> processes
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
> 2008/10/14 06:07:39| User-Agent logging is disabled.
> 2008/10/14 06:07:39| Referer logging is disabled.
> 2008/10/14 06:07:39| Unlinkd pipe opened on FD 42
> 2008/10/14 06:07:39| Local cache digest enabled; rebuild/rewrite every
> 3600/3600 sec
> 2008/10/14 06:07:39| Swap maxSize 5120000 KB, estimated 393846 objects
> 2008/10/14 06:07:39| Target number of buckets: 19692
> 2008/10/14 06:07:39| Using 32768 Store buckets
> 2008/10/14 06:07:39| Max Mem size: 16384 KB
> 2008/10/14 06:07:39| Max Swap size: 5120000 KB
> 2008/10/14 06:07:39| Version 1 of swap file with LFS support detected...
> 2008/10/14 06:07:39| Rebuilding storage in /var/spool/squid (CLEAN)
> 2008/10/14 06:07:39| Using Least Load store dir selection
> 2008/10/14 06:07:39| Current Directory is /etc
> 2008/10/14 06:07:39| Loaded Icons.
> 2008/10/14 06:07:39| Accepting HTTP connections at 0.0.0.0, port 8080,
> FD 44.
> 2008/10/14 06:07:39| Accepting ICP messages at 0.0.0.0, port 3130, FD 45.
> 2008/10/14 06:07:39| HTCP Disabled.
> 2008/10/14 06:07:39| Ready to serve requests.
> 2008/10/14 06:07:39| Done reading /var/spool/squid swaplog (1 entries)
> 2008/10/14 06:07:39| Finished rebuilding storage from disk.
> 2008/10/14 06:07:39| 1 Entries scanned
> 2008/10/14 06:07:39| 0 Invalid entries.
> 2008/10/14 06:07:39| 0 With invalid flags.
> 2008/10/14 06:07:39| 1 Objects loaded.
> 2008/10/14 06:07:39| 0 Objects expired.
> 2008/10/14 06:07:39| 0 Objects cancelled.
> 2008/10/14 06:07:39| 0 Duplicate URLs purged.
> 2008/10/14 06:07:39| 0 Swapfile clashes avoided.
> 2008/10/14 06:07:39| Took 0.02 seconds ( 48.57 objects/sec).
> 2008/10/14 06:07:39| Beginning Validation Procedure
> 2008/10/14 06:07:39| Completed Validation Procedure
> 2008/10/14 06:07:39| Validated 27 Entries
> 2008/10/14 06:07:39| store_swap_size = 12
> 2008/10/14 06:07:40| storeLateRelease: released 0 objects
> 2008/10/14 06:08:05| externalAclLookup: 'AD_Group' queue overload
> (ch=0xb9b05bd0)
> 2008/10/14 06:08:05| externalAclLookup: 'AD_Group' queue overload
> (ch=0xb9b05bd0)
>
> and now we have a:
>
> 2008/10/14 06:07:39| WARNING: Cannot run
> '/usr/lib/squid/wbinfo_group.pl' process.
>
> if i run it manually wbinfo_group.pl, it's good ... i run on Fedora 9
> and my conf are:
>
> external_acl_type AD_Group %LOGIN /usr/lib/squid/wbinfo_group.pl
>
>
> same, i don't know why ;=)
>

Squid runs as a non-privileged user.
You need that user to have execute access to the wbinfo_group.pl helper.

Amos

-- 
Please use Squid 2.7.STABLE4 or 3.0.STABLE9
Received on Tue Oct 14 2008 - 09:10:13 MDT

This archive was generated by hypermail 2.2.0 : Tue Oct 14 2008 - 12:00:03 MDT