EFW Support

Support => EFW SMTP, HTTP, SIP, FTP Proxy Support => Topic started by: chipbr on Thursday 14 May 2015, 10:49:06 am



Title: web proxy + active directory group authentication = not working
Post by: chipbr on Thursday 14 May 2015, 10:49:06 am
hi there
i'm using a custom hyper-v VM made available on the other board which works great now.
first, SQUID was not working at all, but I managed to update from 3.0 to 3.0.5 and is now everything OK, except group authentication is not working.

I've joined endian to my domain, it recognizes all groups and users, but every config I try to made using GROUP AUTHENTICATION, it always prompt me for username and password and no one seems to work. after 5-6 tries, it gives up with a squid access denied page.
changing the same rule to user authentication works perfect.

is something I am missing?
even a "allow everything/no filter" rule does not work and asks for user/pass


Title: Re: web proxy + active directory group authentication = not working
Post by: crisman on Friday 15 May 2015, 01:11:49 am
I also would like to have some information on this since I've also used AD groups without success, but if I use one or more users from AD it works.


Title: Re: web proxy + active directory group authentication = not working
Post by: dda on Friday 15 May 2015, 03:18:13 am
Are you using NTLM?


Title: Re: web proxy + active directory group authentication = not working
Post by: crisman on Friday 15 May 2015, 06:17:25 pm
Are you using NTLM?

Hi,

In my case yes I'm using NTLM.

Regards.


Title: Re: web proxy + active directory group authentication = not working
Post by: chipbr on Friday 15 May 2015, 09:40:37 pm
yes, NTLM.
endian 3.0.5 fully updated to latest version
custom kernel/VM by user Timmeh (downloaded from the installation support board).

My Windows Server is 2012 R2, but my domain/forest level still 2008, not an issue because on 2.5 version it worked ok.

something is just not validating the user INSIDE the group, that's why it keep asking for user/password.

please help


Title: Re: web proxy + active directory group authentication = not working
Post by: crisman on Friday 15 May 2015, 11:47:07 pm
yes, NTLM.
endian 3.0.5 fully updated to latest version
custom kernel/VM by user Timmeh (downloaded from the installation support board).

My Windows Server is 2012 R2, but my domain/forest level still 2008, not an issue because on 2.5 version it worked ok.

something is just not validating the user INSIDE the group, that's why it keep asking for user/password.

please help

Hi chipbr,

Do you have any error on the squid.log file?

Thanks.


Title: Re: web proxy + active directory group authentication = not working
Post by: chipbr on Saturday 16 May 2015, 02:59:02 am
just a usual access denied