Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Enrico Heine
You shouldn't modify these files. Put it into /etc/default/squid and I assume it should work out. For Debian this is the right way of doing it, for CentOS I am unsure but I strongly believe it is the same over there. Am 5. Februar 2018 19:13:25 MEZ schrieb erdosain9 : >Thanks for your time! Kno

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread erdosain9
Thanks for your time! Know is working fine. a little and stupid question where i can found the start script of squid??? This is a Centos 7. I want put this KRB5RCACHETYPE=none export KRB5RCACHETYPE [root@squid etc]# cat /usr/lib/systemd/system/squid.service ## Copyright (C) 1996-2015 The Sq

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Flashdown
Also on a specific interval windows will automatically refresh kerberos tickets in the background but when depends on your domain settings and I am unsure about the default interval. Am 5. Februar 2018 17:46:29 MEZ schrieb Enrico Heine : >Only users that can't use the proxy need to do it. > >Am

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Enrico Heine
Only users that can't use the proxy need to do it. Am 5. Februar 2018 17:43:58 MEZ schrieb Enrico Heine : >This is maybe because the users have a old kerberos ticket and need to >renew it. So simple solution for them is to log off and logon again to >their windows PC or they can close the browsers

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Enrico Heine
This is maybe because the users have a old kerberos ticket and need to renew it. So simple solution for them is to log off and logon again to their windows PC or they can close the browsers and tools that need to authenticate against the proxy afterwards they should lock and directly unlock thei

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread erdosain9
Ok. Thanks Know the ticket is fine, and is working (people are going throug internet and i see in access.log there user names) but... im having this error in the log. 2018/02/05 12:56:46 kid1| ERROR: Negotiate Authentication validating user. Result: {result=BH, notes={message: gss_accept_sec

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Flashdown
You could also give this parameter of msktutil a try: flush Flushes all principals for the current host or service account from the keytab, and deletes servicePrincipalName from AD. Am 2018-02-05 16:55, schrieb Flashdown: I am answering to fast,

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Flashdown
I am answering to fast, but I am writing in my little break, so sorry for that :D forget my last mail regarding "to call it correctly" that was misleading and wrong. sure you are talking about the HTTP SPN which have the same KVNO. So if you want to get rid of it delete the computer object, as

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Flashdown
Just to call it correctly, what is wrong is the host principle after you have deleted the computer object and waited for the object to disappear on other DC's as well (if you have replication between dc's) and rejoined it, it should be as you want it to be. Hope this helps with your setup. Am 5

Re: [squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread Flashdown
Delete the Computer Object in Active Directory to clear these spn's up. Am 5. Februar 2018 15:54:26 MEZ schrieb erdosain9 : >Hi to all. > >The squid was working fine, but i made a mistake and... delete the >proxy.keytab. I try to do it again, but make a mistake in the syntax > >wrong syntax (the r

[squid-users] Problem with Kerberos ticket keytab

2018-02-05 Thread erdosain9
Hi to all. The squid was working fine, but i made a mistake and... delete the proxy.keytab. I try to do it again, but make a mistake in the syntax wrong syntax (the real name is not squidproxy.domain.lan is squid.domain.lan): msktutil -c -b "CN=COMPUTERS" -s HTTP/squidproxy.domain.lan -k /etc/sq

Re: [squid-users] 4.0.23 release in Debian

2018-02-05 Thread Flashdown
Well, I've forwarded my old mail just now after subcribing to this list which I did sent directly to luigi and manty because I was unaware of these mailing lists. Thank you Amos! Am 2018-02-05 04:00, schrieb Eliezer Croitoru: It seems they are not even trying to block spam... Eliezer El