Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Upgrade PFSense 2.4.5 SQUID+LDAP erro

    Scheduled Pinned Locked Moved Portuguese
    11 Posts 5 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      IsmaelPA
      last edited by

      2.4.4p3 squid com autenticação LDAP estava funcionando corretamente, após atualização para 2.4.5 fica solicitando usuário e senha, mesmo utilizando usuário e senha corretos. Servidor estava operando normalmente antes da atualização, configuração está correta, proxy em uso a muitos anos, sem erros em atualizações anteriores. Reinstalado pacote squid mas erro persiste. Tentei usar os mesmos parâmetros de integração ldap do squid em outro proxy, e apresenta o mesmo erro.

      J 1 Reply Last reply Reply Quote 2
      • B
        brittos
        last edited by

        Também estou com o mesmo problema.
        Você conseguiu resolver o problema?

        1 Reply Last reply Reply Quote 0
        • I
          IsmaelPA
          last edited by

          Ainda não, fiquei de meia noite até meio dia fazendo dúzias de testes mas sem sucesso, abri um ticket no redmine. https://redmine.pfsense.org/issues/10379

          1 Reply Last reply Reply Quote 1
          • B
            brittos
            last edited by

            Eu fiz alguns testes e cheguei a conclusão que o problema está na versão do squid. Deu o mesmo problema com a versão 2.4.4 limpa

            1 Reply Last reply Reply Quote 0
            • C
              CZvacko
              last edited by

              Same issue at my side...

              1 Reply Last reply Reply Quote 1
              • C
                CZvacko
                last edited by

                I checked packetcapture data sent to LDAP server:
                in LDAP bind request packet is WRONG password, there is space (HEX 20) added before real password.
                That is obviously rejected by LDAP server with "Invalid credentials" status.
                Some typo in source code ??

                In packet I also noticed double quotes were added to "LDAP Server user DN" & "LDAP base domain", but in previous version I had to input double quotes into textbox to let LDAP work. Now, extra double quotes are sent to server, now sure if that will cause another issue. Of course I can delete my double quotes from textbox, but other users will not know it. Maybe some (i) information hint should be added near related textbox.

                1 Reply Last reply Reply Quote 0
                • viktor_gV
                  viktor_g Netgate
                  last edited by

                  fix: https://redmine.pfsense.org/issues/10379#note-6

                  1 Reply Last reply Reply Quote 1
                  • B
                    brittos
                    last edited by

                    Solução manual para corrigir o problema.

                    Baixar o arquivo squid.inc  do link e copiar para a pasta /usr/local/pkg/

                    [2.4.5-RELEASE][root@pfSense]/home: fetch https://github.com/pfsense/FreeBSD-ports/raw/0342afde429be7e07e1426547ecb63f6ac56503e/www/pfSense-pkg-squid/files/usr/local/pkg/squid.inc

                    [2.4.5-RELEASE][root@pfSense]/home: cp  squid.inc  /usr/local/pkg/

                    The Save button at the bottom of this page must be clicked to save configuration changes.
                    To activate squidGuard configuration changes, the Apply button must be clicked.

                    I 1 Reply Last reply Reply Quote 1
                    • I
                      IsmaelPA @brittos
                      last edited by

                      @brittos said in Upgrade PFSense 2.4.5 SQUID+LDAP erro:

                      cp  squid.inc  /usr/local/pkg/

                      I tried and it did not work here

                      Date IP Status Address User Destination
                      28.03.2020 23:34:45 10.34.100.6 NONE/000 error:transaction-end-before-headers - -
                      28.03.2020 23:34:45 10.34.100.6 NONE/000 error:transaction-end-before-headers - -
                      28.03.2020 23:34:44 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:43 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:42 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:39 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:34 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:29 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -
                      28.03.2020 23:34:13 10.34.100.6 TCP_DENIED/407 www.bol.uol.com.br:443 ismael-azambuja -
                      28.03.2020 23:33:54 10.34.100.6 TCP_DENIED/407 http://detectportal.firefox.com/success.txt - -

                      B 1 Reply Last reply Reply Quote 0
                      • B
                        brittos @IsmaelPA
                        last edited by

                        @IsmaelPA Tem que aplicar alguma regra no squid para salvar o squid.conf corretamente.

                        1 Reply Last reply Reply Quote 0
                        • J
                          juniorsilva @IsmaelPA
                          last edited by

                          @IsmaelPA Vc consegiu resolver o problema? estou exatamente com o mesmo erro.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.