Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread heimarbeit123 . 99
sadly I can not copy my log here, because the mail get rejected again and again because of this.   But here are the two errors, which I can see inside the cache.log.   Connected OK group filter '(&(sAMAccountName=ldaptest)(memberOf=CN=Test1,OU=Groups,DC=my.domain,DC=com))', searchbase 'dc=my.dom

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread Amos Jeffries
On 22/02/21 11:41 pm, heimarbeit123.99 wrote: You were right! I realy don't know how I was able to miss this.. I removed "-R" and don't get the error anymore. I did read the documentation again and -K and -S should be fine. -d of course too. But now I get the error "WARNING: LDAP search error 'O

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread heimarbeit123 . 99
You were right! I realy don't know how I was able to miss this.. I removed "-R" and don't get the error anymore. I did read the documentation again and -K and -S should be fine. -d of course too.   But now I get the error "WARNING: LDAP search error 'Operations error'". I found out that many peo

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread Amos Jeffries
On 22/02/21 10:42 pm, heimarbeit123.99 wrote: of course I did read the documentation. Otherwise I would not have asked here. I would not ask for your time if the solution would be available for myself. I am asking right here -after some weeks- because I do not know what is finally wrong. You

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread heimarbeit123 . 99
of course I did read the documentation. Otherwise I would not have asked here. I would not ask for your time if the solution would be available for myself. I am asking right here -after some weeks- because I do not know what is finally wrong. I can't even figure out what the error means. Even goo

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread Amos Jeffries
On 22/02/21 9:26 pm, heimarbeit123.99 wrote: So I finally tried it on my Squid Proxy. I edited the squid like this: external_acl_type ad_group_member_check ttl=120 %LOGIN /usr/lib/squid/ext_ldap_group_acl -d -R -K -S -b "dc=domain,dc=com" -D proxyu...@domain.com -W /etc/squid/ldappass.txt -f "

Re: [squid-users] Squid doesn't notice AD group changes

2021-02-22 Thread heimarbeit123 . 99
So I finally tried it on my Squid Proxy.   I edited the squid like this:   external_acl_type ad_group_member_check ttl=120 %LOGIN /usr/lib/squid/ext_ldap_group_acl -d -R -K -S -b "dc=domain,dc=com" -D proxyu...@domain.com -W /etc/squid/ldappass.txt -f "(&(sAMAccountName=%u)(memberOf=CN=%g,OU=G