Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I now have a squid + dansguardian proxy/filter set up with active directory user authentication.

 

Is it possible for the username and password to authenticate to be picked up automatically rather than them having to enter it into another box in the browser?

 

Cheers,

Tony

Posted

The authentication is working fine. It is done via squid_ldap_group which is part of squid. It is set up as described at http://papercut.biz/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

 

(Except I only have a deny group and a default 'allow everyone else' acl)

 

The machine isn't joined to the domain as the authentication is passed via http so it wouldn't be necessary I woudn't have thought?

Posted

Not sure on that score then; we have transparent authentication on our IPCop box (uses squid) and our auth_param uses ntlm rather than LDAP.

 

auth_param ntlm program /usr/lib/squid/ntlm_auth BBARRINGTON/bbs-svr-001 BBARRINGTON/bbs-svr-002

Posted
If you want it "done for you" in an out-of-the box solution with a nice UI, give us a call - SmoothWall - 0113 3874160. So yes, it is possible :)

 

I think I can manage with my config file hacking at the moment :) I'm here for another 4 years at least so I won't be passing complex systems on to someone else for a while :p

Posted
If you want it "done for you" in an out-of-the box solution with a nice UI, give us a call - SmoothWall - 0113 3874160. So yes, it is possible :)

 

... or download IPCop ;)

Posted
IPCop is no use to me without having to mess around loads - I have a single NIC firewall set-up which I am not able to change so IPCop would need some serious messing in order to get it to play nice.
Posted

Ah, that does the job fine. I worked through these 2:

 

https://help.ubuntu.com/community/ActiveDirectoryWinbindHowto

http://wiki.squid-cache.org/SquidFaq/ProxyAuthentication

 

The only difference now is that I can't do a check to see if the user is in a group or not via the AD - which is a shame.

 

Does anyone know how to block a single user from having access to the net through squid and ntlm? I'm guessing it will just be an ACL?

Posted

Ah, I've managed it in 2 different ways now :)

 

First way was by using the ldap group method on its own (and not the ldap auth part).

 

The way I'm using now is by using /usr/lib/squid/wbinfo_group.pl as an external ACL program as shown in the example towards the middle of http://linux.ittoolbox.com/groups/technical-functional/linuxadmin-l/squid-with-ntlm-729052#

 

Now just to rustle up a nice looking 'you can't get online because you've been banned' page.

  • 2 weeks later...
Posted

I've got Squid and Dansguardian working (Fedora Core 6), together with NTLM authentication (it was a very trying experience - designed to drive normal people into the dealth grip of Microsoft I think).

 

Now I'd like to be able to block individuals/groups using something similar to 'wbinfo_group.pl'. I've run into some problems though.

 

Whenever I try to use of the many, varied and conflicting articles, using wbinfo_group all I get is an authentication dialogue - I've tried localzuk's link.

 

Does anyone have a link to an article which is guaranteed, absolutely copper-bottomed, 100% to work?

 

I may have to hit something soon.

 

P.S Fedora Core 6's bouncing window effects are great.

Posted
how was your version of squid compiled? which options? There are several compile time options relating to winbind auth that must be selected for it to work.
Posted

These are the options for the default Squid configure on Fedora 6 using 'squid -v | grep configure'. Perhaps there's something missing?

 

Your help is appreciated.

 

configure options: '--build=i686-redhat-linux-gnu' '--host=i686-redhat-linux-gnu' '--target=i386-redhat-linux-gnu' '--program-prefix=' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--includedir=/usr/include' '--libdir=/usr/lib' '--libexecdir=/usr/libexec' '--sharedstatedir=/usr/com' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--exec_prefix=/usr' '--bindir=/usr/sbin' '--libexecdir=/usr/lib/squid' '--localstatedir=/var' '--datadir=/usr/share' '--sysconfdir=/etc/squid' '--enable-epoll' '--enable-snmp' '--enable-removal-policies=heap,lru' '--enable-storeio=aufs,coss,diskd,null,ufs' '--enable-ssl' '--with-openssl=/usr/kerberos' '--enable-delay-pools' '--enable-linux-netfilter' '--with-pthreads' '--enable-ntlm-auth-helpers=SMB,fakeauth' '--enable-external-acl-helpers=ip_user,ldap_group,unix_group,wbinfo_group' '--enable-auth=basic,digest,ntlm' '--enable-digest-auth-helpers=password' '--with-winbind-auth-challenge' '--enable-useragent-log' '--enable-referer-log' '--disable-dependency-tracking' '--enable-cachemgr-hostname=localhost' '--enable-underscores' '--enable-basic-auth-helpers=LDAP,MSNT,NCSA,PAM,SMB,YP,getpwnam,multi-domain-NTLM,SASL' '--enable-cache-digests' '--enable-ident-lookups' '--with-large-files' '--enable-follow-x-forwarded-for' '--enable-wccpv2' '--enable-fd-config' '--with-maxfd=16384' 'CFLAGS=-fPIE -Os -g -pipe -fsigned-char' 'LDFLAGS=-pie' 'build_alias=i686-redhat-linux-gnu' 'host_alias=i686-redhat-linux-gnu' 'target_alias=i386-redhat-linux-gnu'

Posted

If it won't work one way - then use another!

 

As ntlm_auth works, I've got Dansguardian to filter out the little blighters instead. It does mean I have to edit a text file now and then - but at least it works.

 

Client -> Dansguardian -> Squid.

 

All is well.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...