[squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-20 Thread nairb rotsak
Hello all, I have squid 2.5STABLE12 running on an Ubuntu 6.06 box. I have it joined to an AD domain and it works great. I want to add a group in AD that allows Inet use. If they aren't in that group, they can't get out. I would like it to stay seamless.. no login box. This is not a trans

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-20 Thread Henrik Nordstrom
On ons, 2008-08-20 at 08:39 -0700, nairb rotsak wrote: > The 2nd one is what I pretty much used to get this far... > > I just don't know how to tie it all together.. and I have looked at the > wbinfo_group.pl.. but not sure if I need to go that far?? far? wbinfo_group.pl is the easiest way to

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-21 Thread nairb rotsak
inal Message From: Henrik Nordstrom <[EMAIL PROTECTED]> To: nairb rotsak <[EMAIL PROTECTED]> Cc: squid-users@squid-cache.org Sent: Wednesday, August 20, 2008 5:44:48 PM Subject: Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups On ons, 2008

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-21 Thread chris brain
Hi From my experience with NTLM and AD this is the best way we found to implement group membership : ntlm_auth already has a mechanism to provide this its just that the doco is difficult to follow. squid.conf : auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic --r

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-21 Thread nairb rotsak
posted somewhere.. please tell me where to go... AD groups Hi From my experience with NTLM and AD this is the best way we found to implement group membership : ntlm_auth already has a mechanism to provide this its just that the doco is difficult to follow. squid.conf : auth_param basic program /u

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-24 Thread nairb rotsak
roxyusers_group".. because my winbind line is 'winbind separator = +' Works great Chris, thanks again! - Original Message From: chris brain <[EMAIL PROTECTED]> To: squid-users@squid-cache.org Sent: Thursday, August 21, 2008 10:26:15 PM Subject: Re: [squid-users] if th

Re: [squid-users] if this is posted somewhere.. please tell me where to go... AD groups

2008-08-25 Thread Henrik Nordstrom
On tor, 2008-08-21 at 07:24 -0700, nairb rotsak wrote: > Just to clarify, to use wbinfo_group.pl, I need to: > 1. Add Domain Local group to Active Directory called Internet-Allowed (name > not important) Yes, unless you already have a suidable group. > 2. Add 'external_acl_type ADS %LOGIN /us