• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

SquidGuard 1.16.18_15 does't filter content in mixed auth mode

Scheduled Pinned Locked Moved Cache/Proxy
7 Posts 3 Posters 827 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    CZvacko
    last edited by Feb 22, 2021, 10:59 AM

    I authenticate proxy user (squid) against LDAP, and due to LDAP channel binding, I have to use SSL LDAP auth. Since SquidGuard doesn't support SSL LDAP auth, I used "mixed authentication mode". It means Groups ACL use simple 'username' string (that match with LDAP username) to apply filtering.

    That was working properly in 1.16.18_6. But SquidGuard 1.16.18_15 now just allow everything, even deny category in ACL. Any fix possible ? Or how to downgrade to 1.16.18_6 ?

    C 1 Reply Last reply Mar 26, 2021, 11:44 AM Reply Quote 0
    • C
      CZvacko @CZvacko
      last edited by Mar 26, 2021, 11:44 AM

      @czvacko Tried update to 1.16.18_17 but my issue persist. SquidGuard still allow everything...

      V M 2 Replies Last reply Mar 26, 2021, 1:53 PM Reply Quote 0
      • V
        viktor_g Netgate @CZvacko
        last edited by Mar 26, 2021, 1:53 PM

        @czvacko Please show your SquidGuard configration (WebGUI pages) + /usr/local/etc/squidGuard/squidGuard.conf

        C 1 Reply Last reply Mar 26, 2021, 2:29 PM Reply Quote 0
        • C
          CZvacko @viktor_g
          last edited by Mar 26, 2021, 2:29 PM

          @viktor_g said in SquidGuard 1.16.18_15 does't filter content in mixed auth mode:

          /usr/local/etc/squidGuard/squidGuard.conf

          Requested information are in attachment.
          Config.zip
          User names are anonymized, I'm user 'john_doe' authenticated like this by LDAP - so I can connect Squid. Same user name used for squidGuard / Group ACL - that worked in previous version.

          Now,

          • when 'john_doe' exist in Allow_youtu_face, everything is allowed, even "deny" URL from group ACL / common ACL.

          • when 'john_doe' NOT exist in any group (so he should follow common ACL) nothing works.

          V 1 Reply Last reply Mar 30, 2021, 9:53 AM Reply Quote 0
          • V
            viktor_g Netgate @CZvacko
            last edited by Mar 30, 2021, 9:53 AM

            @czvacko Please update to the latest version of SquidGuard pkg

            C 1 Reply Last reply Mar 31, 2021, 11:49 AM Reply Quote 0
            • M
              maycontuckmantel @CZvacko
              last edited by Mar 31, 2021, 12:29 AM

              @czvacko Boa noite, resolvi meu problema configurando uma linha no squid.

              vou postar a linha abaixo

              url_rewrite_program /usr/local/bin/squidGuard -c /usr/local/etc/squidGuard/squidGuard.conf;url_rewrite_bypass off;url_rewrite_children 16 startup=8 idle=4 concurrency=0

              caminho para verificar a linha:
              services/ squid proxy server / show advanced options

              1 Reply Last reply Reply Quote 0
              • C
                CZvacko @viktor_g
                last edited by Mar 31, 2021, 11:49 AM

                @viktor_g Updated, category filtering now works well.
                But still there is something broken:
                In the past, when I add/remove user from group ACL, it was enough just press Save&Apply.
                But now I have to restart SquidGuard service to apply new membership.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received