Re: [squid-users] Ldap and Active directory

From: Henrik Nordstrom <hno@dont-contact.us>
Date: 03 Apr 2003 13:31:20 +0200

tis 2003-04-01 klockan 20.47 skrev kevin stuttard:

> squid_ldap_auth by running make install as suggested
> elsewhere in this mailing list and read the
> documentation in the helper direcory of the source as
> suggested by Henrik. I have placed a couple of lines
> in my squid.conf as follows
>
> auth_param basic program
> /usr/local/squid/libexec/squid_ldap_auth
> /usr/local/squid/libexec/ldap_auth.conf

What is ldap_auth.conf? The squid_ldap_auth helper shipped with Squid
does not have a configuration file, only command line arguments.

> I have tried running squid_ldap_auth from the command
> line with all sorts of options such as squid_ldap_auth
> -b ou=All
> Users,dc=mansfield13104,dc=lancsngfl,dc=ac,dc=uk
> pluto:389

The help you there is a couple of questions regarding your LDAP server
which needs answers:

1. What does a typical user object in your LDAP structure look like?
Use ldapsearch to retrieve one LDAP user object if you are not sure.

2. What from this object do you want to use as login name?

Then the answer to these questions need to be translated into
squid_ldap_auth command line arguments. The squid_ldap_auth man page
documentation contains detailed descriptions of all options and also a
number of example configurations (including at least two configurations
for MS AD).

Regards
Henrik

-- 
Free Squid-users support provided by Henrik Nordström <hno@squid-cache.org>
PayPal donations welcome if you consider my Free Squid support helpful.
If you need commercial Squid support or cost effective Squid and
firewall appliances please refer to MARA Systems AB, Sweden
http://www.marasystems.com/, info@marasystems.com
Received on Thu Apr 03 2003 - 04:31:28 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:14:38 MST