Re: [squid-users] WebServer-SRG or Application SRG for Squid?

2020-08-10 Thread Eliezer Croitor
Hey Leonard, Can you clarify what do you mean by STIGing and SRG etc.. What are you trying to achieve? Plain text might make more sense to these who doesn't understand these terms. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email:

Re: [squid-users] Basic explanation on configuration

2020-08-10 Thread Amos Jeffries
On 10/08/20 8:43 pm, Roberto Nunnari wrote: > Hello. > >   > > I need to build a new linux server with squid to replace an old one. > > The old server is running squid version 3.3.8 and authenticates against > Active Directory. In the conf I see ldap, ntlm, kerberos and negotiator > + wbinfo. >

[squid-users] SOLVED: ext_ldap_group_acl

2020-08-10 Thread Roberto Nunnari
Hello. I just solved myself this problem. It was my mistake with the filters. Here’s how it goes : /usr/lib64/squid/ext_ldap_group_acl -R -b "dc=my,dc=domain" -D "squid@my.domain" -W /etc/squid/ldappass.txt -f "(&(sAMAccountName=%u)(memberof:1.2.840.113556.1.4.1941:=CN=%g,DC=my,dc=doma in)

[squid-users] R: Basic explanation on configuration

2020-08-10 Thread Roberto Nunnari
Hello. In the previous message I forgot to include what I did till now in squid.conf (edited to replace sensitive information). In part from default conf and in part from old installation and in part adapted to my needs. Thank you and best regards. Robi Da: squid-users Per conto d

[squid-users] Basic explanation on configuration

2020-08-10 Thread Roberto Nunnari
Hello. I need to build a new linux server with squid to replace an old one. The old server is running squid version 3.3.8 and authenticates against Active Directory. In the conf I see ldap, ntlm, kerberos and negotiator + wbinfo. The new server is running squid version 4.4.8. I'm trying to

[squid-users] ext_ldap_group_acl

2020-08-10 Thread Roberto Nunnari
Hello. I'm setting up squid on a CentOS 8 server. Authentication against active directory works well with basic_ldap_auth, but I fail when trying to check that a user belongs to a group. It seems to me that for ext_ldap_group_acl it's enough that both the user and the group exist and it retur