Hi, I configured the ntlm cache feature years ago and never looked back.
Today I checked the redis instance that should hold the nt hashes and it is empty:

[root@srvpf ~]# redis-cli -h localhost -p 6383
localhost:6383> keys *
(empty list or set)
localhost:6383>

But I have no errors in the log:

[root@srvpf ~]# grep ntlm /usr/local/pf/logs/packetfence.log | sed 's/user .* /user REDACTED /g' | tail -n 30 Apr 26 10:19:56 srvpf pfqueue: pfqueue(13153) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:20:16 srvpf pfqueue: pfqueue(4995) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:20:22 srvpf pfqueue: pfqueue(10776) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:20:47 srvpf pfqueue: pfqueue(12589) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:21:00 srvpf pfqueue: pfqueue(4675) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:21:03 srvpf pfqueue: pfqueue(10776) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:21:12 srvpf pfqueue: pfqueue(13153) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:21:43 srvpf pfqueue: pfqueue(4995) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:21:53 srvpf pfqueue: pfqueue(8822) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:22:30 srvpf pfqueue: pfqueue(10776) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:23:08 srvpf pfqueue: pfqueue(6490) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:23:43 srvpf pfqueue: pfqueue(10776) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:23:48 srvpf pfqueue: pfqueue(8822) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:23:53 srvpf pfqueue: pfqueue(4995) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:26:39 srvpf pfqueue: pfqueue(6490) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:26:41 srvpf pfqueue: pfqueue(8822) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:26:52 srvpf pfqueue: pfqueue(6490) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:27:03 srvpf pfqueue: pfqueue(16282) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:27:27 srvpf pfqueue: pfqueue(15510) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:27:31 srvpf pfqueue: pfqueue(16282) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:27:45 srvpf pfqueue: pfqueue(12589) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:29:50 srvpf pfqueue: pfqueue(8822) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:30:01 srvpf pfqueue: pfqueue(16282) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:31:01 srvpf pfqueue: pfqueue(17327) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:33:08 srvpf pfqueue: pfqueue(8822) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:33:15 srvpf pfqueue: pfqueue(13153) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:35:43 srvpf pfqueue: pfqueue(12589) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:35:48 srvpf pfqueue: pfqueue(10776) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user) Apr 26 10:35:57 srvpf pfqueue: pfqueue(8180) INFO: [mac:unknown] Cached user REDACTED (pf::domain::ntlm_cache::cache_user)

I noticed that even if i stop redis_ntlm_cache, the logs keeps saying "Cached user ecc."

How is it possible??

Thanks


_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to