Jump to content

ind1ekid

Members
  • Posts

    82
  • Joined

  • Last visited

Everything posted by ind1ekid

  1. You need to change the krb5.conf (realm/kdc/admin server) and smb.conf (realm/password server/workgroup) with the new domain info. Resolv.conf will need the dns servers/search domain changing too. Then you can re-add your server to AD. I may have missed something... but thats where you'd start. Squid shouldn't need reconfiguring iirc.
  2. Squid 3.0 here running on CentOS 5, it connects to the embc who run squid and netsweeper.
  3. Vote here for Proxy Switchy! extension if you use Chrome. Works a treat.
  4. You don't have to get an expensive SAN. There's 2 very good free SAN's in Nexenta and OpenFiler that will run on pretty much any hardware you give them! Been using OpenFiler for 4 months now, and its been rock solid - and it wasn't anywhere near expensive!
  5. Wish I was still at uni and could print it in A0, bet its awesome that big! A3 will have to do I guess! Cheers
  6. Can you be any more specific with what breaks? What are the logs saying? check /var/log/squid/cache.log and the logs in /var/log/samba/
  7. You need to get Winbind and samba installed and working, join the server to the domain then look at squid config. Which is usually pretty straight forward in ubuntu, if you follow what cools suggested above you should on the right path, if you run into specific problems, post your troubles and someone may be able to help.
  8. Which version of samba does your method install onto turnkey? The problems with R2 are that most versions of samba aren't compatible with r2 for ntlm auth. Ubuntu/CentOS/Debian all install an incompatible version through their package managers, which is why I opted for using enterprise samba packages.
  9. What OS and Samba versions you running? winbind logs will no doubt tell the tale if you want to post them I can have a look for you. ** And sorry I totally forgot to update this thread. The problem all along was that the version of samba/winbind wouldn't talk to Server 2008 R2 - i was wrong to blame M$ for this one. I was using ubuntu at the time I started this thread, and I failed in trying to compile and install the latest version of samba. So I tried debian 5.04, to no avail when I ran into problems again compiling samba. I ended up using Enterprise Samba in the end on debian. Which worked a treat. But I've since switched to CentOS last week because its better supported on XenServer (which I didnt really want to do because Debian installs squid 2.7 by default which allows for include files.. which 2.7< doesnt ). So now im using 64bit CentOS 5.4 and the latest versions of Enterprise Samba for RHEL5. I must have installed and reinstalled linux servers 10 times in the last few weeks to crack this one but im pretty happy with it all now. I can confirm that: Debian 5 + Enterprise Samba (3.5) + Squid 2.7 will authenticate to AD no probs. CentOS 5.4 + Enterprise Samba (3.5) + Squid 2.6 will also work.
  10. Could try Nexenta as an alternative, supposed to be a bit easier to use than OF, but "apparently" a bit pickier when it comes to the hardware. Pretty decent How To on OpenFiler here that you might want to bookmark - OpenFiler How To
  11. Ah, yea so it is. I gave up to soon whilst searching for cache_peer in your squid.conf. The never direct should fix your problem. Let us know how you get on. Sean
  12. I'd think you will need to add that as a cache_peer in your squid conf then. And also add a never_direct allow all. Cache Peer never_direct
  13. Do you normally go through an isp or local authority proxy/filter?
  14. Try squidclient (apt-get install squidclient) - its pretty handy for checking squid itself directly from your server! If you don't get very far post your squid conf, maybe theres something astray in there.
  15. Think I may have solved this one :: Introducing the Restriction of NTLM Authentication. Basically override the default setting that denys NTLM authentication with the 2008r2 dc. Seems to work now.
  16. Thanks guys. I've got no issues setting squid up for NTLM, just that it doesn't seem to work with 2008r2 like it does with 2003r2.The issues arise with winbind/samba when you point them at the 2008r2 DC - in that NTLM authentication doesn't work. I've read all sorts about it being Samba's issue, and that it is fixed with 3.3>, but samba is a pain in the *(*& to configure and install from source (at least its proving to be on ubuntu 8.04, ill be trying others shortly). So.. does anyone have kerberos method set up with Squid?
  17. Afternoon all. Pretty simple question really. Do any of you have Squid set up, to authenticate your users with Active Directory off a 2008/2008R2 Domain controller? Either with NTLM or Kerberos methods. Testing with wbinfo -K username%password works fine, the 2k8r2 dc auths ok, but with NTLM ie, wbinfo -a username%password, it returns errors from the 2k8r2 dc. My problem is ive never successfully set up Kerberos authentication on a linux box. ConfigExamples/Authenticate/Kerberos - Squid Web Proxy Wiki - Squid guide to doing... what I think I want to achieve? Any input would be appreciated. Thanks
  18. Yea I sure I could do that. PM'd you.
  19. Hi all. I recently composed a simple guide to creating an image using FOG to help my colleagues understand it, as we're currently using Ghost for Imaging, so there's quite a difference in methods. I didn't feel pointing them to FOG's wiki/documentation would useful, because it's so vast it would just be information overload. Anyway, thought id share it - feel free to make revisions to it, use it as your own, add comments, whatever. Quick Start to Imaging with FOG.docx
  20. I didnt really no. I was in the process of moving to XenServer from VMWare anyway, so I didnt spend to much time on it, and when I rebuilt my FOG server for XenServer my multicasting issues were gone :| Sorry I can't help you.
  21. I had this problem since BBC started streaming Championship football last year. I managed to prevent the streams loading, and it is still appropriate for the world cup by the looks of it. I blocked the domains below iirc. If you can prevent it access to the XML file it wont be able to load the stream. open.live.bbc.co.uk/mediaselector cp45415.edgefcs.net
  22. I had a single sas drive die in a raid 5 on a proliant 380g5 not too long back, the spare kicked in straight away and once I got a new drive in to replace the dead on it soon rebuilt the raid quickly and quietly in the OS, P400 raid card. Lucky me ey?
  23. Addusers or CSVDE CSVDE - Examples Import Export of user accounts Active Directory Simple, but it works.
  24. Are you multicasting? I've had that problem previously when trying to multicast.
  25. Thanks for that, I thought that would be the case
×
×
  • Create New...