Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid auth failed

    Scheduled Pinned Locked Moved pfSense Packages
    11 Posts 3 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      titus91360
      last edited by

      Hi,
      We've got some problem to authenticate user via the active directory.
      It works except for people having french charaters in there password (ie. école, très, …)

      Is there a way to change that ?

      1 Reply Last reply Reply Quote 0
      • T Offline
        titus91360
        last edited by

        Nobody encounter this problem of accent characters ?

        1 Reply Last reply Reply Quote 0
        • M Offline
          mhab12
          last edited by

          Sounds like a Squid issue.  I would search the Squid mailing lists here:
          http://www.mail-archive.com/squid-users@squid-cache.org/

          1 Reply Last reply Reply Quote 0
          • T Offline
            titus91360
            last edited by

            So ?
            Did you find something on squid for my problem ?

            1 Reply Last reply Reply Quote 0
            • G Offline
              Gloom
              last edited by

              Your post is a bit light on information but my guess is you are seeing the old UTF8 problem.

              If you Google it you will get loads of posts telling you to not use accented characters in AD passwords if you use any form of LDAPv2 authentication and I'm assuming you are using squid_ldap_auth or one of it's variants. The fix is to update your AD servers to use LDAPv3 which does use UTF8 encoding.

              Never underestimate the power of human stupidity

              1 Reply Last reply Reply Quote 0
              • T Offline
                titus91360
                last edited by

                I'm actually using a v3 ldap version. So I'm not sure the problem is the same. Am I wrong with that ?
                How to be sure to use the good version of squid_ldap_auth ?

                1 Reply Last reply Reply Quote 0
                • G Offline
                  Gloom
                  last edited by

                  A quick way to see if squid_ldap_auth is working properly is to start a packet capture and then get a user to attempt to authenticate using a password with an extended character in it. You should get both sides of the conversation and then post it here so I can see what's going on.

                  I forgot to ask, which version of Squid do you have installed?

                  Never underestimate the power of human stupidity

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    titus91360
                    last edited by

                    I'v got version 2.6.21_10, but just see that a new version is out (v2.7.7)
                    I'll try an update tomorrow and try a capture if the problem still exist

                    1 Reply Last reply Reply Quote 0
                    • G Offline
                      Gloom
                      last edited by

                      yes 2.6 is the original pkg branch for FreeBSD 7 when it was released and as you have now guessed it did not support the utf8  on|off tag. when you upgrade to 2.7.7 just turn it on in the squid.conf file

                      Never underestimate the power of human stupidity

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        titus91360
                        last edited by

                        Thks for your response Gloom  but can't manage to find where to switch on utf8 support  :-[
                        If I change it in squid.conf, it will not be persistent. Is there the same option on squid.inc ?

                        1 Reply Last reply Reply Quote 0
                        • G Offline
                          Gloom
                          last edited by

                          yes you should just be able to insert a line like

                          auth_parm utf8 on

                          then restart squid and hopefully your users can enjoy passwords with accented characters

                          Never underestimate the power of human stupidity

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.