Hello everyone!
Is there any way of squid logs show what browser the clients
are using? I need this to know the reach of a GPO in all my domain. I hope
anyone can help me out.
Regards,
Wladner
Hi to all,
I'm using squid with kerberos authentication. It was working just
fine. For some unknown reason now it isn't. Look what it is in
cache.log:
squid_kerb_auth: ERROR: gss_acquire_cred() failed: Unspecified GSS
failure. Minor code may provide more information. Permission denied
2012/05/
Amos,
what could be causing this? When I desable NTLM authentication or when
I use Kerberos all access go just fine, but when only NTLM is able I
can't get access to https pages and I get in the logs TCP_DENIED/407.
How can I debug it?
regards
2012/4/20 Amos Jeffries :
> On 21/04/2012 1:15 a.m.,
Hello,
I'm using NTLM scheme like this:
auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 30 startup=5 idle=5
auth_param ntlm keep_alive on
And it is working fine except for https pages. Here is my basic squid.conf:
acl to_localhost dst 12
inbindd_privileged??
regards,
Wladner
2012/4/18 Simon Dwyer :
> HI Wladner,
>
> I get that second message when i forget to start the winbind service.
>
> on Centos : service start winbind
>
> Simon
>
> On Wed, 2012-04-18 at 16:05 -0300, Wladner Klimach wrote:
>>
Hi everyone,
I'm trying to implement NTLM scheme in my squid box. I've already
configured samba and winbind so that I can check with wbinfo and even
run /usr/bin/ntlm_auth at the shell and it works. But for some hidden
problem squid is not having the same result. Look what is poping up at
the cach
On 11/04/2012 21:15, Wladner Klimach wrote:
>
> That's the options I pointed for authetincation:
>
> '--enable-auth=basic,digest,ntlm,negotiate'
> '--enable-basic-auth-helpers=LDAP,MSNT,NCSA,PAM,SMB,YP,getpwnam,multi-domain-NTLM,SASL,DB,POP3,squid_radius_auth
t Active
Looks like ntlm is not an option to squid. Could it be the lack of the
compilation option --with-winbind-auth-challenge??
2012/4/11 Harry Mills :
> On 11/04/2012 17:56, Wladner Klimach wrote:
>>
>> Hi people,
>>
>> I'm having some problem to implement NTLM
Hi people,
I'm having some problem to implement NTLM at my squid box. I've
followed the documentation guides but for some unknown reason isn't
still working. Here is my squid.conf ( authentication portion only):
auth_param negotiate program
/squid-3.2.0.16/helpers/negotiate_auth/wrapper/negotiat
Squid users,
when I try to get this url www.tcu.gov.br it takes too long when it
even does. Look at my set up configs in squid.conf:
cache_store_log none
maximum_object_size 16384 KB
minimum_object_size 0 KB
maximum_object_size_in_memory 50 KB
cache_swap_low 95
cache_swap_high 98
ipcache_size
Hi people,
I only need to know if it's possible to build http_access joinning
more than 2 ACLs. Like this, if I want to use a src ACL + proxy_auth
ACL + dstdomain ACL all in the same http_access comand, would be
possible?
Regards,
Wladner
Hello,
I'm trying to use ext_user type of ACL but for some reason it isn't
matching. Look at my cache.log message with debug_options set up:
ACL::ChecklistMatches: result for 'restrictedDomains' is 1
2012/02/08 16:24:40.553| ACLList::matches: result is true
2012/02/08 16:24:40.553| ACLList::matc
Hi everyone!
I need my squid to deal with some users in a different way. I'm
running kerberos authetication scheme, so only authenticated users can
access the cache. How could I make an ACL to group some authenticated
users in order to deny or allow some urls especific to them? But
notice this, I'
Hello,
I can't download this page
https://clientes.smiles.com.br/eloyalty_ptb/start.swe?SWECmd=Login&SWECM=S&SWEHo=clientes.smiles.com.br
. Looks like some sort of problem is causing timeout. Any clue of what
might be happening?
Regards,
Wladner
s above these.
refresh_pattern ^ftp: 144020% 10080
refresh_pattern ^gopher:14400% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
Regards,
Wladner
2011/12/20 Amos Jeffries :
> On 21/12/2011 3:03 a.m.,
mara.gov.br:squid->cainf-269642.redecamara.camara.gov.br:4230
(ESTABLISHED)
squid 20367 squid 156u IPv6 2472223 0t0 TCP *:squid (LISTEN)
Is only has IPV6 conection types. Is this a problem or point a
possible bottleneck ?
2011/12/19 Wladner Klimach :
> Amos,
>
> how can
nly I using it.
Regards,
Wladner
2011/12/14 Amos Jeffries :
> On Wed, 14 Dec 2011 13:22:38 -0200, Wladner Klimach wrote:
>>
>> Hello,
>>
>> i'm running squid with kerberos authentication. The problem is that
>> it's runing too slow. Looks like squid is
Hello,
i'm running squid with kerberos authentication. The problem is that
it's runing too slow. Looks like squid is negotiating with AD every
URL it tries to get. Anyone could point me a way out?
Best regards,
Wladner
Hey people,
i'm runing squid-3.1 with negotiate with squid_kerb_auth program. The
only problem is that it's generating slowlyness for browsing sites.
Could anyone point some article of tunning squid with kerberos?
regards,
Wladner
19 matches
Mail list logo