Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense Plus can't work Google LDAP with Squid Proxy Server

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marceloengecom
      last edited by

      Hello,

      With Stunnel, I configured the authentication in pfSense and Captive Portal and this works fine, but does not work with my Proxy Squid.

      Squid doesn't have a integration with Stunnel?

      My Squid Authentication General Settings:
      Authentication Method: LDAP
      Authentication Server: 127.0.0.1
      Authentication server port: 1636

      Squid Authentication LDAP Settings
      LDAP version: 3
      Transport: TCP - Standard
      LDAP Server User DN: UserBindGoogleCredentials
      LDAP Password: PasswordBindGoogleCredentials
      LDAP Base Domain: Base DN: dc=MyDomain,dc=com,dc=br
      LDAP Username: uid
      LDAP Search Filter: uid=%s

      Can someone help me?

      Regards,

      Marcelo Costa

      telefone: (51) 3022.5100
      e-mail: marcelo@comdesk.com.br
      web-site: www.comdesk.com.br

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        What errors do you see logged?

        Do you see traffic leaving encrypted toward Google?

        M 1 Reply Last reply Reply Quote 1
        • M
          marceloengecom @stephenw10
          last edited by

          @stephenw10

          Deny errors are showed on the real time logs.

          I believe that be because I don't indicate the certificate on the squid.

          Marcelo Costa

          telefone: (51) 3022.5100
          e-mail: marcelo@comdesk.com.br
          web-site: www.comdesk.com.br

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            If you're using Stunnel the client certificate would be set there. I assume that works for other LDAP auth?

            M 1 Reply Last reply Reply Quote 1
            • M
              marceloengecom @stephenw10
              last edited by

              @stephenw10

              Yes...

              On Squid, authentication LDAP works fine with Microsoft AD.

              And with Stunnel, pfSense authentication and Captive Portal works with Google Workspace LDAP, but squid but doesn't works.

              The my Squid parameters are corrects?

              Marcelo Costa

              telefone: (51) 3022.5100
              e-mail: marcelo@comdesk.com.br
              web-site: www.comdesk.com.br

              M 1 Reply Last reply Reply Quote 0
              • M
                marceloengecom @marceloengecom
                last edited by

                @marceloengecom

                up!!

                Marcelo Costa

                telefone: (51) 3022.5100
                e-mail: marcelo@comdesk.com.br
                web-site: www.comdesk.com.br

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Up because you're still looking for suggestions?

                  It's not something I've ever configured (or seen configured) if it works against a local unencrypted ldap server I would expect it to work against GA via Stunnel.

                  Steve

                  M 1 Reply Last reply Reply Quote 1
                  • M
                    marceloengecom @stephenw10
                    last edited by

                    @stephenw10

                    Hi,

                    Yes, I look for sugestions because don't authentic the Proxy Squid. I try with and without Stunnel.

                    Marcelo Costa

                    telefone: (51) 3022.5100
                    e-mail: marcelo@comdesk.com.br
                    web-site: www.comdesk.com.br

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      But it does work against a local LDAP server?

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        marceloengecom @stephenw10
                        last edited by

                        @stephenw10

                        This works in a MS Active Directory, via LDAP. My goal is connect to our Google Workspace LDAP.

                        The pfSense Authentication and Captive Portal works, but Squid, not.

                        I have a change "Squid Authentication Method" to Local and doesn't autenticate.

                        Marcelo Costa

                        telefone: (51) 3022.5100
                        e-mail: marcelo@comdesk.com.br
                        web-site: www.comdesk.com.br

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.