[squid-users] Re: ntlm_auth problems

From: Terry <td3201_at_gmail.com>
Date: Mon, 24 May 2010 11:18:08 -0500

On Mon, May 24, 2010 at 10:52 AM, Terry <td3201_at_gmail.com> wrote:
> Hello,
>
> I am trying to get ntlm_auth to work in my squid-2.6.STABLE21-6.el5
> installation on RHEL 5.4.  Samba is samba-common-3.0.33-3.15.el5_4.
> Here's my relevant config:
>
>
> auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
> auth_param ntlm children 5
> auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
> auth_param basic children 5
> auth_param basic realm Squid proxy-caching web server
> auth_param basic credentialsttl 5 hours
> acl all src 0.0.0.0/0.0.0.0
> acl manager proto cache_object
> acl localhost src 127.0.0.1/255.255.255.255
> acl to_localhost dst 127.0.0.0/8
> acl SSL_ports port 443
> acl Safe_ports port 80          # http
> acl Safe_ports port 21          # ftp
> acl Safe_ports port 443         # https
> acl Safe_ports port 70          # gopher
> acl Safe_ports port 210         # wais
> acl Safe_ports port 1025-65535  # unregistered ports
> acl Safe_ports port 280         # http-mgmt
> acl Safe_ports port 488         # gss-http
> acl Safe_ports port 591         # filemaker
> acl Safe_ports port 777         # multiling http
> acl NTLMUsers proxy_auth REQUIRED
> http_access allow manager localhost
> http_access deny manager
> http_access deny !Safe_ports
> http_access deny CONNECT !SSL_ports
> http_access allow NTLMUsers
> http_access deny all
>
>
> Using IE or Firefox, I am presented with an authentication dialog box.
>  I attempt to authenticate and it fails.  In the logs, I see only
> this:
>
> 1274715773.285      1 10.98.1.122 TCP_DENIED/407 1813 GET
> http://google.com/ - NONE/- text/html
>
>
> I am able to authenticate fine manually:
> [root_at_omajelut01 ~]# ntlm_auth --username=john --domain=DOMAIN1
> password:
> NT_STATUS_OK: Success (0x0)
>
> Where am I going wrong here?
>

Sorry to reply to my own post but I wanted to get this out there. Is
this related to samba 3.0? I see this related post:
http://marc.info/?l=squid-users&m=127331202712656&w=2

Thanks!
Received on Mon May 24 2010 - 16:18:16 MDT

This archive was generated by hypermail 2.2.0 : Tue May 25 2010 - 12:00:06 MDT