h1 { text-align: center }

ext_lm_group_acl

NAME
SYNOPSIS
DESCRIPTION
OPTIONS
CONFIGURATION
TESTING
AUTHOR
COPYRIGHT
QUESTIONS
REPORTING BUGS
SEE ALSO

NAME

ext_lm_group_acl − Squid external ACL helper to check Windows users group membership.

Version 1.22

SYNOPSIS

ext_lm_group_acl [−D domain ] [−cdhGP]

DESCRIPTION

ext_lm_group_acl is an installed binary in Squid for Windows builds.

This helper must be used in with an authentication scheme (typically Basic or NTLM) based on Windows NT/2000 domain users (LM mode).

It reads from the standard input the domain username and a list of groups and tries to match each against the groups membership of the specified username.

OPTIONS

−c

Use case insensitive compare.

−d

Write debug info to stderr.

−D domain

Specify the default user’s domain.

−G

Start helper in Domain Global Group mode.

−h

Display the binary help and command line syntax info using stderr.

−P

Use ONLY PDCs for group validation.

CONFIGURATION

external_acl_type NT_global_group %LOGIN c:/squid/libexec/ext_lm_group_acl.exe -G
external_acl_type NT_local_group %LOGIN c:/squid/libexec/ext_lm_group_acl.exe
acl GProxyUsers external NT_global_group GProxyUsers
acl LProxyUsers external NT_local_group LProxyUsers
acl password proxy_auth REQUIRED
http_access allow password GProxyUsers
http_access allow password LProxyUsers
http_access deny all

In the previous example all validated NT users member of GProxyUsers Global domain group or member of LProxyUsers machine local group are allowed to use the cache.

Groups with spaces in name, for example Domain Users , must be quoted and the acl data ( Domain Users ) must be placed into a separate file included by specifying /path/to/file The previous example will be:

acl ProxyUsers external NT_global_group "c:/squid/etc/DomainUsers.txt"

The DomainUsers.txt file will contain only the following line:

Domain Users

NOTE: The standard group name comparison is case sensitive, so group name must be specified with same case as in the NT/2000 Domain. It’s possible to enable case insensitive group name comparison ( −c ), but on some not-english locales, the results can be unexpected.

NOTE: Native WIN32 NTLM and Basic Helpers must be used without the −A and −D switches.

Refer to Squid documentation for the more details on squid.conf.

TESTING

I strongly recommend that ext_lm_group_acl is tested prior to being used in a production environment. It may behave differently on different platforms.

To test it, run it from the command line. Enter username and group pairs separated by a space (username must entered with URL-encoded domain%5Cusername syntax). Press ENTER to get an OK or ERR message.

Make sure pressing CTRL+D behaves the same as a carriage return.

Make sure pressing CTRL+C aborts the program.

Test that entering no details does not result in an OK or ERR message.

Test that entering an invalid username and group results in an ERR message.

Test that entering an valid username and group results in an OK message.

AUTHOR

This program was written by Guido Serassio <[email protected]> with contributions by Henrik Nordstrom <[email protected]>

Based in part on prior work in check_group by Rodrigo Albani de Campos

This manual was written by Guido Serassio <[email protected]> Amos Jeffries <[email protected]>

COPYRIGHT

This program and documentation is copyright to the authors named above.

Distributed under the GNU General Public License (GNU GPL) version 2 or later (GPLv2+).

QUESTIONS

Questions on the usage of this program can be sent to the Squid Users mailing list <[email protected]>

REPORTING BUGS

Bug reports need to be made in English. See http://wiki.squid-cache.org/SquidFaq/BugReporting for details of what you need to include with your bug report.

Report bugs or bug fixes using http://bugs.squid-cache.org/

Report serious security bugs to Squid Bugs <[email protected]>

Report ideas for new improvements to the Squid Developers mailing list <[email protected]>

SEE ALSO

squid(8), GPL(7),
The Squid FAQ wiki http://wiki.squid-cache.org/SquidFaq
The Squid Configuration Manual http://www.squid-cache.org/Doc/config/


 

Introduction

Documentation

Support

Miscellaneous

Web Site Translations

Mirrors