Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SquidGuard 1.16.18_15 does't filter content in mixed auth mode

    Scheduled Pinned Locked Moved Cache/Proxy
    7 Posts 3 Posters 828 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      CZvacko
      last edited by

      I authenticate proxy user (squid) against LDAP, and due to LDAP channel binding, I have to use SSL LDAP auth. Since SquidGuard doesn't support SSL LDAP auth, I used "mixed authentication mode". It means Groups ACL use simple 'username' string (that match with LDAP username) to apply filtering.

      That was working properly in 1.16.18_6. But SquidGuard 1.16.18_15 now just allow everything, even deny category in ACL. Any fix possible ? Or how to downgrade to 1.16.18_6 ?

      C 1 Reply Last reply Reply Quote 0
      • C
        CZvacko @CZvacko
        last edited by

        @czvacko Tried update to 1.16.18_17 but my issue persist. SquidGuard still allow everything...

        viktor_gV M 2 Replies Last reply Reply Quote 0
        • viktor_gV
          viktor_g Netgate @CZvacko
          last edited by

          @czvacko Please show your SquidGuard configration (WebGUI pages) + /usr/local/etc/squidGuard/squidGuard.conf

          C 1 Reply Last reply Reply Quote 0
          • C
            CZvacko @viktor_g
            last edited by

            @viktor_g said in SquidGuard 1.16.18_15 does't filter content in mixed auth mode:

            /usr/local/etc/squidGuard/squidGuard.conf

            Requested information are in attachment.
            Config.zip
            User names are anonymized, I'm user 'john_doe' authenticated like this by LDAP - so I can connect Squid. Same user name used for squidGuard / Group ACL - that worked in previous version.

            Now,

            • when 'john_doe' exist in Allow_youtu_face, everything is allowed, even "deny" URL from group ACL / common ACL.

            • when 'john_doe' NOT exist in any group (so he should follow common ACL) nothing works.

            viktor_gV 1 Reply Last reply Reply Quote 0
            • viktor_gV
              viktor_g Netgate @CZvacko
              last edited by

              @czvacko Please update to the latest version of SquidGuard pkg

              C 1 Reply Last reply Reply Quote 0
              • M
                maycontuckmantel @CZvacko
                last edited by

                @czvacko Boa noite, resolvi meu problema configurando uma linha no squid.

                vou postar a linha abaixo

                url_rewrite_program /usr/local/bin/squidGuard -c /usr/local/etc/squidGuard/squidGuard.conf;url_rewrite_bypass off;url_rewrite_children 16 startup=8 idle=4 concurrency=0

                caminho para verificar a linha:
                services/ squid proxy server / show advanced options

                1 Reply Last reply Reply Quote 0
                • C
                  CZvacko @viktor_g
                  last edited by

                  @viktor_g Updated, category filtering now works well.
                  But still there is something broken:
                  In the past, when I add/remove user from group ACL, it was enough just press Save&Apply.
                  But now I have to restart SquidGuard service to apply new membership.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.