[squid-users] ntlm_auth problems

From: Terry <td3201_at_gmail.com>
Date: Mon, 24 May 2010 10:52:39 -0500


I am trying to get ntlm_auth to work in my squid-2.6.STABLE21-6.el5
installation on RHEL 5.4. Samba is samba-common-3.0.33-3.15.el5_4.
Here's my relevant config:

auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 5
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 5 hours
acl all src
acl manager proto cache_object
acl localhost src
acl to_localhost dst
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl NTLMUsers proxy_auth REQUIRED
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow NTLMUsers
http_access deny all

Using IE or Firefox, I am presented with an authentication dialog box.
 I attempt to authenticate and it fails. In the logs, I see only

1274715773.285 1 TCP_DENIED/407 1813 GET
http://google.com/ - NONE/- text/html

I am able to authenticate fine manually:
[root_at_omajelut01 ~]# ntlm_auth --username=john --domain=DOMAIN1
NT_STATUS_OK: Success (0x0)

Where am I going wrong here?
