Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid + Active Directory

    pfSense Packages
    4
    7
    18.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      avorobyev
      last edited by

      How can I authorize fpSense's squid against AD?
      LDAP, NT Domain doesn't work out-of-box.

      Any method is fine. What should i do? nothing works :(

      Thanks

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        This was never completed by the original package author.  If you want this functionality, I suggest you put together a bounty for it.

        1 Reply Last reply Reply Quote 0
        • L
          lordarcane
          last edited by

          After browsing arount the forum and searching, I still really cant find an answer to if the ldap auth works with squid or not. Some people seems to say that yes it works, and other as in this post that it is not completed. If I try enable it it indeed shows the dialog box but, doesent take my credentials. I´ve used this as an guide.

          Here is the setup that it currently working for me!!

          Authentication method - LDAP
          LDAP version - 3
          Authentication server - (windows server IP address)
          LDAP server user DN - cn=administrator,cn=Users,dc=yourdomain,dc=co,dc=za
          LDAP password - (your password for the administrator account)
          LDAP base domain - dc=yourdomain,dc=co,dc=za
          LDAP search filter - sAMAccountName=%s

          I´m running PFsense 1.2.2
          built on Thu Jan 8 22:39:31 EST 2009

          So, any info from the admins or developers. Is LDAP auth towards 2003 server implemented in the squid package or not?

          1 Reply Last reply Reply Quote 0
          • G
            Gloom
            last edited by

            Why do people insist on using the domain administrator account for LDAP lookups to AD it is not and never has been required.

            AD is set to not allow anonymous lookups but all you need in there is an unprivileged standard account. Using the admin account in unencrypted format shows a serious disregard for security.

            The link is to a MS howto for AD as on large installs of over 1k users there are problems with returned results. It includes altering AD to allow anonymous lookups

            http://support.microsoft.com/kb/315071

            Never underestimate the power of human stupidity

            1 Reply Last reply Reply Quote 0
            • L
              lordarcane
              last edited by

              Thanks! Okey.

              But, still, do PfSense and Squid work with ldap auth?

              1 Reply Last reply Reply Quote 0
              • G
                Gloom
                last edited by

                Yes the squid package on pfsense can be configured to popup an authentication box to AD but not to do NTLM pass-through as this requires winbind and a full samba install.

                Never underestimate the power of human stupidity

                1 Reply Last reply Reply Quote 0
                • L
                  lordarcane
                  last edited by

                  Okey! Great! Thanks for the answer.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.