Jump to content

Recommended Posts

Posted

Has anyone got a cachepilot to authenticate users from AD?

 

We have a cachepilot 4.1 and have tried to set up the authentication using AD or LDAP. It binds to the domain OK and we've set up the users and groups etc as specified in the instructions.

 

However, all the user gets is a long delay, and then a windows username dialogue box. No matter what credentials are in it stays at that point.

 

Nothing shows in the cachepilot logs - apart from the sucesseful bind message!

 

Equiinet weren't much help - they basically gave up on us. Its a bog standard Windows 2003 server domain so nothing weird!

Posted

You need a global security group in AD with all the appropriate users in it.

 

You then create a user in cachepilot with the exact same name as the group you have created above (use all lowercase to simplify things and do not use any spaces or special charachers).

 

iirc thats it.

Posted (edited)

Time synch'd correctly.

 

Global security group with same name as cachepilot user set up.

 

Still no joy! I've been trying this for months now and have deleted and recreated the users/groups several times to make sure.

 

Did you use AD or LDAP to authenticate? I've tried both.

Edited by GoldenWonder
Posted (edited)
Time synch'd correctly.

 

Global security group with same name as cachepilot user set up.

 

Still no joy! I've been trying this for months now and have deleted and recreated the users/groups several times to make sure.

 

Did you use AD or LDAP to authenticate? I've tried both.

 

AD. Worked first time, no problems at all which is an absolute miricle for cachepilot. We're had dodgt cachepilots in the past, maybe yours in the same as you cant really go far wrong when setting up AD intergration

 

Do you have 2 domains btw? If you do give me a shout once you get this bit working as there are issues with users having long names (and by long i mean more than 20 charachers including the domain name)

 

Our details are as follows;

 

Server address: the IP of the DC

Domain: domain.local (Maybe the local bit is the problem??)

User: basic user with no rights other than teh ability to query AD.

Edited by Guest
Posted

Equiinet say the box is fine :confused:

 

We have a single domain - pretty straightforward setup really. The cachepilot logs show the bind works so I guess the details for DC and user account are OK (I've tried a limited user account and an Admin account with the same result)

 

Haven't tried the .local on the domain name, I've been using the domain.org.uk FQDN version and the cachepilot gets the short version itself.

 

As you say, theres not much else to do!

Posted
Equiinet say the box is fine :confused:

 

We have a single domain - pretty straightforward setup really. The cachepilot logs show the bind works so I guess the details for DC and user account are OK (I've tried a limited user account and an Admin account with the same result)

 

Haven't tried the .local on the domain name, I've been using the domain.org.uk FQDN version and the cachepilot gets the short version itself.

 

As you say, theres not much else to do!

 

I only said .local as thats what ours is. If your domain is a valid FQDN then yeah you should be using that.

 

Maybe you should take a magnet to the HD so that they are forced to reinstall for you. We, and other schools, have had numerous problems which equinet replyed with "not our fault boss", only for us to later discover it was their fault.

Posted

Did anyone else set delegation rights on the cachepilots AD object?

 

I notice the DC has a load of the following errors when binding to the domain:

 

Event Type: Error

Event Source: KDC

Event Category: None

Event ID: 27

Date: 06/10/2008

Time: 16:23:09

User: N/A

Computer:

Description:

While processing a TGS request for the target server host/-web., the account -WEB$@ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 8). The requested etypes were 2. The accounts available etypes were 23 -133 -128 3 1.

 

If I set the cachepilots object to allow delegation for Kerberos these errors disappear, but it still fails to authenticate!

 

Any more of this and its going out of the window, and a nice new ISA server will take its place....

  • 7 months later...
Posted
the cachepilots wont work unless you have a FQDN as ive found out :( 1 of my schools doesn't have a '.local' after its name so we have to build a new domain.
Posted

Using LDAP here with the following setup in two schools:

 

CachePilot

 

Groups

 

SiteCode_Students

SiteCode_Staff

SiteCode_Open

etc

 

Users

 

Internet_Students

Internet_Staff

Internet_Open

etc

 

Groups set up first and then user matched to most appropriate group.

 

LDAP configured:

 

Server IP: 10.x.x.x

User Dir: OU=Establishments,DC=schoolname,DC=internal

User: CPAdmin,OU=CP

Pass:

 

Web Access: authorised users; url-filter

 

AD Side

 

Security groups set up to match CachePilot Users with Establishments\SiteCode

 

Users

 

Internet_Students

Internet_Staff

Internet_Open

etc

 

Then obviously network users are members of the appropriate groups.

 

AD Structure

 

|schoolname.internal

-Establishments

--SiteCode

--CP

 

CPAdmin is a member of the OU=CP at the same level as SiteCode with just Domain Users membership. Password same as in CachePilot LDAP settings.

 

If your cachepilot already runs off schoolname.internal the same as your network then this should just work a treat. If not you could always get it changed to that - two minute job (unless you have to wait around for your lea to do it).

 

In which case you're probably on schoolname.local so you need to do some DNSing:

 

DNS

 

Under Foward Lookup Zones create a new zone called 'local' then a new domain called *the bit before .local (whatever your CachePilot prompts with on authentication)* then within that domain create an A record named cachepilot pointing to the cachepilot IP Address.

 

Hope this helps you get it working.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...