sön 2006-02-26 klockan 08:39 +0530 skrev updatemyself .:
i was trying to setup a squid proxy server with the wb_group authentication.
in my windows 2003 ADS i am having a group called internet
i need to give internet access for the ppl belongs to that group
can anyone help me.. how i can
On 2/26/06, updatemyself . [EMAIL PROTECTED] wrote:
Hai All,
i was trying to setup a squid proxy server with the wb_group authentication.
in my windows 2003 ADS i am having a group called internet
i need to give internet access for the ppl belongs to that group
in my corrent configuration
Begin forwarded Message from Roman Rathler,
Thu, 29 Apr 2004 11:06:01 +0200 (METDST):
Hi,
in the meanwhile i got it running using the wbinfo_group.pl helper.
There is a bug in the perl script that comes with the fedora package
squid-2.5.STABLE3-1.fc1 when it tries converting groupSID to
On Thu, 29 Apr 2004, Roman Rathler wrote:
in the meanwhile i got it running using the wbinfo_group.pl helper. There is a bug
in the perl script that comes with the fedora package
squid-2.5.STABLE3-1.fc1 when it tries converting groupSID to groupGID...
As far as I know this is fixed in
Hi,
for sure I am not the only one having this problem and maybe it a rtfm-thing, but i
wasn't able to find it and I searched a lot.
I have a squid up and running with samba-3 using the fedora packages
(squid-2.5.STABLE3-1.fc1). authentication against the ads works fine from squid for
basic
-- Mensaje original --
From: Roman Rathler [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Date: Wed, 28 Apr 2004 10:11:59 +0200 (METDST)
Subject: [squid-users] wb_group issues
Hi,
for sure I am not the only one having this problem and maybe it a rtfm-thing,
but i wasn't able to find it and I searched
On Wed, 28 Apr 2004, Roman Rathler wrote:
I have a squid up and running with samba-3 using the fedora packages
(squid-2.5.STABLE3-1.fc1). authentication against the ads works fine from squid for
basic and ntlm authentication. now i want to build some acls using groups from the
active
DOES ANYBODY HAVE AN IDEA ABOUT THIS???
-Original Message-
From: Mark Pelkoski
Sent: Wednesday, November 26, 2003 10:27 AM
To: [EMAIL PROTECTED]
Subject: [squid-users] Wb_group error message in cache.log
List,
I keep seeing this error in my cache.log a couple of times a day
: Wednesday, November 26, 2003 10:27 AM
To: [EMAIL PROTECTED]
Subject: [squid-users] Wb_group error message in cache.log
List,
I keep seeing this error in my cache.log a couple of times a day. Is
this normal or do I have a problem? I require my users to belong to a
certain NT group in order to use
PROTECTED]
Subject: RE: [squid-users] Wb_group error message in cache.log
Not really..
Does it happen for all users or just some?
Is there any log messages from Samba in the Samba or messages log files?
Regards
Henrik
On Tue, 2 Dec 2003, Mark Pelkoski wrote:
DOES ANYBODY HAVE AN IDEA ABOUT
On Tue, 2 Dec 2003, Mark Pelkoski wrote:
Nothing in the smbd.log file.
winbind is logging to the log.winbindd log file, not smbd.log.
This message shows up randomly giving no notice to any particular user.
Just curious if this is any issue or not.
If you do not have any complaints from
List,
I keep seeing this error in my cache.log a couple of times a day. Is
this normal or do I have a problem? I require my users to belong to a
certain NT group in order to use Squid. I wasn't seeing it when I tested
it with 70 users. Now I have 800+ users.
I need wb_group to work under samba 3.
Compiling it with the samba 3 libraries give this error_
[EMAIL PROTECTED] winbind_group]# make
source='wb_common.c' object='wb_common.o' libtool=no \
depfile='.deps/wb_common.Po' tmpdepfile='.deps/wb_common.TPo' \
depmode=gcc3 /bin/sh
On Fri, 31 Oct 2003, Lombardo Federico wrote:
I need wb_group to work under samba 3.
Won't work. wb_group is a Samba-2.X helper.
For Samba-3 you can use the wbinfo_group helper which is Samba version
neutral.
Regards
Henrik
Subject: Re: [squid-users] wb_group and samba 3
On Fri, 31 Oct 2003, Lombardo Federico wrote:
I need wb_group to work under samba 3.
Won't work. wb_group is a Samba-2.X helper.
For Samba-3 you can use the wbinfo_group helper which is Samba version
neutral.
Regards
Henrik
On Fri, 31 Oct 2003, Lombardo Federico wrote:
but wbinfo_group is a perl script, I've a lot of users... I'm afraid that
will slow down authentication process, isn't it ?
Not really. The speed difference is marginal, and in both cases the
results are aggressively cached by Squid.
wb_group is
I'm having issues using wb_group from Stable3, both the version
compile from source and the SRPM. I have an earlier version of
wb_group that works perfectly from Stable1, here is my results
Interesting - I got:
$ ./wb_group -d -c
/wb_group[25429](wb_check_group.c:321): External ACL winbindd
I'm having issues using wb_group from Stable3, both the version compile
from source and the SRPM. I have an earlier version of wb_group that
works perfectly from Stable1, here is my results
/usr/lib/squid/wb_group -d -c
/wb_group[22948](wb_check_group.c:321): External ACL winbindd group
I had a similar problem if I had Squid running. I would halt squid and test
wb_group and all would work right then.
-Original Message-
From: Alex Short [mailto:[EMAIL PROTECTED]
Sent: Friday, August 29, 2003 4:26 PM
To: [EMAIL PROTECTED]
Subject: [squid-users] wb_group strangeness
Henrik,
Thanks so much that worked.
Later.
On Wed, 2003-08-20 at 17:23, Henrik Nordstrom wrote:
On Wednesday 20 August 2003 23.24, Edward Mann wrote:
I am running squid 2.5.STABLE3, samba 2.2.8a with wb_group.
wb_group is working fine, but what i want to know is if there is a
way that
I am running squid 2.5.STABLE3, samba 2.2.8a with wb_group. wb_group is
working fine, but what i want to know is if there is a way that i can
setup the configuration so that if the user is not in the group the
wb_group helper will put them back to basic and IE will give them the
login box? They
On Wednesday 20 August 2003 23.24, Edward Mann wrote:
I am running squid 2.5.STABLE3, samba 2.2.8a with wb_group.
wb_group is working fine, but what i want to know is if there is a
way that i can setup the configuration so that if the user is not
in the group the wb_group helper will put them
]
Sent: Tuesday, August 19, 2003 12:30 AM
Subject: Re: Res: Re: Res: Re: [squid-users] -- wb_group cache time
On Monday 18 August 2003 20.02, Alex Carlos Braga Antão wrote:
Where do I find the wb_group helpers to squid work with Samba 3.0?
The wbinfo based helper should work I think
(helpers
Hello again,
I have wb_group configured here, but I´m still getting some strange
problems.
I can browse with a user in the group Internet, but if I remove this
user from the group, the user still can browse.
I configure ttl=60 (1 minute) to test, but nothing happens. It only
works if
On Monday 18 August 2003 15.31, Alex Carlos Braga Antão wrote:
What really means the negative_ttl on the external_acl
How long to remember negative lookups, i.e. a user not being member of
a group in case of group lookups.
Regards
Henrik
--
Donations welcome if you consider my Free
On Monday 18 August 2003 15.06, Alex Carlos Braga Antão wrote:
I configure ttl=60 (1 minute) to test, but nothing happens. It
only works if I restart SAMBA.
Then the problem is somewhere in Samba. Most likely winbind has cached
the group memberships, not querying the domain again.
How
, 18 de agosto de 2003 13:23:16
Para: Alex Carlos Braga Antão; [EMAIL PROTECTED]
Assunto: Re: Res: Re: [squid-users] -- wb_group cache time
On Monday 18 August 2003 15.06, Alex Carlos Braga Antão wrote:
I configure ttl=60 (1 minute) to test, but nothing happens. It
only works if I restart SAMBA
On Monday 18 August 2003 20.02, Alex Carlos Braga Antão wrote:
Where do I find the wb_group helpers to squid work with Samba 3.0?
The wbinfo based helper should work I think
(helpers/external/wbinfo_group).
The wb_auth and wb_ntlm_auth are both replaced by the Samba ntlm_auth
helper in
, August 13, 2003 6:18 PM
Subject: Re: [squid-users] wb_group problem
On Wed, 13 Aug 2003, [koi8-r] áÌÅËÓÁÎÄÒ ýÅÒÂÁËÏ× wrote:
I try to run wb_group -d...
I give 'mydomain\user group' - fail with (wb_check_group.c:231) -
Waring:
Can't enum user groups.
I give 'mydomain\\user group' - fail
:52 PM
Subject: Re: [squid-users] wb_group problem
On Wed, 13 Aug 2003, Aleksandr Shcherbakov wrote:
wbinfo says:
wbinfo -r username
Could not get groups for user username
wbinfo -r domain\username
Could not get groups for user domain\username
Then I think there is a problem
, August 13, 2003 6:18 PM
Subject: Re: [squid-users] wb_group problem
On Wed, 13 Aug 2003, [koi8-r] aIAEOAIAO yAOAAEI? wrote:
I try to run wb_group -d...
I give 'mydomain\user group' - fail with (wb_check_group.c:231) -
Waring:
Can't enum user groups.
I give 'mydomain\\user group' - fail
On Wed, 13 Aug 2003, Aleksandr Shcherbakov wrote:
wbinfo says:
wbinfo -r username
Could not get groups for user username
wbinfo -r domain\username
Could not get groups for user domain\username
Then I think there is a problem with your winbind installation somewhere.
Maybe it is not fully
The only good way I can see to do this is to match against
the authenticated username. Use a script to calculate which
users in access.log are over their limit, then dump those
to a file that you match on using a proxy_auth acl.
acl overused proxy_auth /path/to/file
Were already doing this.
Hi!
I want to use winbind authentication and control access via group (I have
w2k domain - Active Directory).
I configured smb (2-2-8a) and squid (2.5.STABLE3, compiled with samba
sources) using http://www.squid-cache.org/Doc/FAQ/FAQ-23.html#ss23.5.
I have added to smb.conf:
winbind enum users =
On Wed, 13 Aug 2003, [koi8-r] áÌÅËÓÁÎÄÒ ýÅÒÂÁËÏ× wrote:
I try to run wb_group -d...
I give 'mydomain\user group' - fail with (wb_check_group.c:231) - Waring:
Can't enum user groups.
I give 'mydomain\\user group' - fail with same message.
'user group' - the same.
What does wbinfo say about
using external acl works fine.
Thanks.
Regards
Aleskandr.
- Original Message -
From: Henrik Nordstrom [EMAIL PROTECTED]
To: Aleksandr Shcherbakov [EMAIL PROTECTED]
Cc: Henrik Nordstrom [EMAIL PROTECTED]; [EMAIL PROTECTED]
Sent: Wednesday, August 13, 2003 8:52 PM
Subject: Re: [squid-users
I finally remembered to check the cache log for details
:-( arg. OK so the groups are being read correctly now.
Good.
This particular configuration leads to everyone at full
speed, which is a better default option!
For the 'overused' acl, should i be using external_auth or
RFC391 User
On Monday 04 August 2003 05.20, Simon Bryan wrote:
Yes it works from the command line OK with that syntax. Does Squid
do that automatically? If not how do you configure the acl? I have
the following at the moment:
acl winauth external wb_group wwwusers
acl banned external wb_group banned
I have this as my external_acl_directive:
external_acl_type wb_group %LOGIN /usr/local/squid/libexec/wb_group -d
Can you pass paramaters like that? eg could I use -c ?
Yes - in fact, that's what I do. My config is:
external_acl_type NT_global_group ttl=300 %LOGIN
/opt/squid/libexec/wb_group
Hmm, just noticed the -d in that line, don't know whether that has just slipped in
while testing or not.
There is a readme.txt in the winbind_group directory explaining the
available command line options and required squid.conf syntax.
I can't use the proxy from home so will check that out
Henrik Nordstrom said:
Another thing to note is delay_access is not too happy about external
acl types or other acl types which may require an external lookup of
any kind. But it should work pretty good (but still not perfect) if
you force the same acls to be evaluated in http_access.
I
Hi all,
I am working my way through why the delay_pools do not work for me, I suspected
winbind and have been rebuilding everything. I have an issue with wb_group that I
can't resolve. If I use wb_group -d and enter a valid username I get a list of
groups as below:
student
readable,
even for a non-programmer) what conditions cause this status to be
generated.
Regards,
Tony
-Original Message-
From: Simon Bryan [mailto:[EMAIL PROTECTED]
Sent: Monday, 4 August 2003 11:13
To: [EMAIL PROTECTED]
Subject: [squid-users] wb_group
Hi all,
I am working my way through
August 2003 9:13 AM
To: [EMAIL PROTECTED]
Subject: [squid-users] wb_group
Hi all,
I am working my way through why the delay_pools do not work for
me, I suspected
winbind and have been rebuilding everything. I have an issue with
wb_group that I
can't resolve. If I use wb_group -d
Bryan [mailto:[EMAIL PROTECTED]
Sent: Monday, 4 August 2003 9:13 AM
To: [EMAIL PROTECTED]
Subject: [squid-users] wb_group
Hi all,
I am working my way through why the delay_pools do not work for
me, I suspected
winbind and have been rebuilding everything. I have an issue with
wb_group that I
Bryan [mailto:[EMAIL PROTECTED]
Sent: Monday, 4 August 2003 11:20 AM
To: [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: RE: [squid-users] wb_group
Jay Turner said:
You need to supply the account name and the group to the
wb_group helper.
OK will be returned if the user provided
My wb_group dies from time to time. It was built from 2.5.2. Can I just
compile the wb_group external helper from 2.5.3 and replace the old one,
or do I have to re-compile and replace squid also with 2.5.3 for the new
wb_group to work? TIA.
You might as well just fully install 2.5STABLE3,
Hi,
At 21.31 03/07/2003, Mark Pelkoski wrote:
List,
My wb_group dies from time to time. It was built from 2.5.2. Can I just
compile the wb_group external helper from 2.5.3 and replace the old one,
or do I have to re-compile and replace squid also with 2.5.3 for the new
wb_group to work? TIA.
Hello,
I am using samba 2.2.7 and squid 2.5-stable1.
I need that only people belonging to specific NT groups can have
access to the intranet, or our intranet,...
I've failed to make it work with wb_group as external helper, but it
is running fine with wbinfo_group.pl
Is there any impact to use
On Friday 28 February 2003 10.52, [EMAIL PROTECTED] wrote:
Hello,
I am using samba 2.2.7 and squid 2.5-stable1.
I need that only people belonging to specific NT groups can have
access to the intranet, or our intranet,...
I've failed to make it work with wb_group as external helper, but
it
Hi All,
I have successfully got wb_group installed and running on my Squid2.5-STABLE1 install.
I am having a problem with NT domains that have a space in them (Domain Users).
I downloaded the squid-2.5.STABLE1-spaces.patch file and it appears to have applied
correctly:
patching file
51 matches
Mail list logo