[squid-users] squid and check_ad_group multidomain

From: Cornaggia <cornaggia26_at_googlemail.com>
Date: Thu, 10 Jul 2008 11:59:06 +0200

Hi,

I have a big problem and, after reading the guidelines for
configuration and manuals, I thought to write here to have any kind of
advice.

Squid2.7 is running in windows environment, as reverse proxy on a
machine before the web server in a domain xy.
With the external helper mswin_check_ad_group I try to match against
an AD global group K created in this domain.
Member of a group is a user on the same domain of squid and of the AD
group K (domain xy) another user has also membership in the AD group K
but the user belongs to the domain zy:
-the authentication of the first user works perfectly cause (for what
I saw in the logs) the request goes on the DC of domain xy.
-the authentication of the second user failed cause (always from logs)
I saw squid goes to make request on the DC of the domain zy where the
user belongs to.

In the group K the users are members with the right features (user1=
domain xy\user1 user2= domain zy\user2.

My question is: how may I set squid so that goes to search the
matching always on the right DC? or How can I solve the problem where
users of other domain zy can be matched against the AD where the Group
K is?

I�ll be thankful for each suggestion.

D
Received on Thu Jul 10 2008 - 09:59:09 MDT

This archive was generated by hypermail 2.2.0 : Thu Jul 10 2008 - 12:00:03 MDT