Re: [squid-users] Re: help squid_kerb_auth

2010-07-16 Thread Nicola Gentile
Now it works! I have not changed anything. Thanks for the help Nicola Gentile 2010/7/16 Markus Moeller hua...@moeller.plus.com: Hi Nicola,  Can you run strace against squid_kerb_auth ? You can do this by selecting just on child (e.g. auth_param negotiate children 1) and then do trace -f  -F

RE: [squid-users] swapfile header too small

2010-07-16 Thread GIGO .
Amos, Thank you. I will do as per your advice. regards, Bilal Date: Fri, 16 Jul 2010 13:43:17 +1200 From: squ...@treenet.co.nz To: squid-users@squid-cache.org Subject: Re: [squid-users] swapfile header too small GIGO . wrote: Dear All, I

[squid-users] external_acl_type + ldap-auth

2010-07-16 Thread Riaan Nolan
Hallo Squid users, I'm having a problem, that I cannot solve :/ I am authenticating users against Active Directory via squid_ldap_auth (Which Works GREAT!) auth_param basic program /usr/lib/squid/squid_ldap_auth -R -b dc=domain,dc=co,dc=za -D cn=ldap,cn=Users,dc=domain,dc=co,dc=za -w ** -f

[squid-users] Re: Re: help squid_kerb_auth

2010-07-16 Thread Markus Moeller
Maybe there was still an old ticket on the client which has now expired. This could be checked with kerbtray. Markus Nicola Gentile nikko...@gmail.com wrote in message news:aanlktil4o5sipa1mz9ibdo7xuu6i_knk4a9u17rfe...@mail.gmail.com... Now it works! I have not changed anything. Thanks for

[squid-users] Kerberos: HTTP/host and not HTTP/host.fqdn@FQDN

2010-07-16 Thread Nick Cairncross
Hi list, I think I have a problem with one of my SPNs/keytab - wondered if someone could confirm this: 3 x squid boxes on different sites, squid1, squid2 and squid3 are their hostnames. I have one AD account with the SPNs of all on it. Using fqdn for the proxy address to 2 of them results in

RES: [squid-users] ntlm locking user accounts in 2003 AD

2010-07-16 Thread Stacker Hush
Thanks for the answer. To enable HTTP/1.1 is in my case the right way is changing the lines below: http_port 127.0.0.1:3128 transparent http11 http_port 8080 http11 cache_peer 127.0.0.1 parent 8081 0 no-query login=*:nopassword http11 including the http11 parameter? Thanks, Stacker From:

Re: RES: [squid-users] ntlm locking user accounts in 2003 AD

2010-07-16 Thread Amos Jeffries
Stacker Hush wrote: Thanks for the answer. To enable HTTP/1.1 is in my case the right way is changing the lines below: http_port 127.0.0.1:3128 transparent http11 NTLM (or any authentication) on the transparent interception port will not work anyway. As Henrik said the client-facing