Hi I use suse 10.0 and have problems to set up ntlm_auth for squid. It uses samba 3.0.20 and squid 2.5.stable10 I have set up winbind and everyhting seems to work. I've changes groupownerchip of /var/lib/samba/winbindd_privileged to squid. squid runs as group squid. Everyhting is working fine for several minutes. After a while it doesn't work anymore proxy:/var/log/samba # /usr/local/sbin/ntlm_auth --helper-protocol=squid-2.5-basic --debuglevel=3 tilo *secret* [2005/10/15 09:25:11, 3] utils/ntlm_auth.c:check_plaintext_auth(292) NT_STATUS_INVALID_HANDLE: Invalid handle (0xc0000008) ERR After restarting winbindd it works again: proxy:/var/log/samba # /usr/local/sbin/ntlm_auth --helper-protocol=squid-2.5-basic --debuglevel=3 tilo *secret* [2005/10/15 09:26:49, 3] utils/ntlm_auth.c:check_plaintext_auth(292) NT_STATUS_OK: Success (0x0) OK log.winbindd (log level=3) doesn't show anything interessting: [2005/10/15 09:31:12, 3] nsswitch/winbindd_misc.c:winbindd_interface_version(460) [ 0]: request interface version [2005/10/15 09:31:12, 3] nsswitch/winbindd_misc.c:winbindd_priv_pipe_dir(493) [ 0]: request location of privileged pipe [2005/10/15 09:31:12, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth(202) [ 0]: pam auth tilo Any idea how to keep it running? Cheers, Tilo
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Tilo Lutz schrieb: | Hi | | I use suse 10.0 and have problems to set up ntlm_auth for squid. | It uses samba 3.0.20 and squid 2.5.stable10 | | I have set up winbind and everyhting seems to work. | I've changes groupownerchip of /var/lib/samba/winbindd_privileged | to squid. squid runs as group squid. | | Everyhting is working fine for several minutes. | After a while it doesn't work anymore | | proxy:/var/log/samba # /usr/local/sbin/ntlm_auth | --helper-protocol=squid-2.5-basic --debuglevel=3 | tilo *secret* | [2005/10/15 09:25:11, 3] utils/ntlm_auth.c:check_plaintext_auth(292) | NT_STATUS_INVALID_HANDLE: Invalid handle (0xc0000008) | ERR | | After restarting winbindd it works again: | | proxy:/var/log/samba # /usr/local/sbin/ntlm_auth | --helper-protocol=squid-2.5-basic --debuglevel=3 | tilo *secret* | [2005/10/15 09:26:49, 3] utils/ntlm_auth.c:check_plaintext_auth(292) | NT_STATUS_OK: Success (0x0) | OK | | log.winbindd (log level=3) doesn't show anything interessting: | [2005/10/15 09:31:12, 3] | nsswitch/winbindd_misc.c:winbindd_interface_version(460) | [ 0]: request interface version | [2005/10/15 09:31:12, 3] nsswitch/winbindd_misc.c:winbindd_priv_pipe_dir(493) | [ 0]: request location of privileged pipe | [2005/10/15 09:31:12, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth(202) | [ 0]: pam auth tilo | | Any idea how to keep it running? | | Cheers, Tilo Hi perhaps you should change to 3.0.20b latest version of samba cause of winbind errors suse 10 rpms are for download at ftp.suse.com or samba mirrors Regards - -- Mit freundlichen Gruessen Best Regards Robert Schetterer robert_at_schetterer.org Munich / Bavaria / Germany https://www.schetterer.org \********************************** \* gnupgp \* public key: \* https://www.schetterer.org/public.key \********************************** -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDULPlb0iqzJq+0MgRAmDTAJ9MEAmCQIzBdlXwAbbO5Xw8cBm0hACfQRsN HvzRRdOptLKHQmsDB3zzHRs=oFdx -----END PGP SIGNATURE-----
Hi> Tilo Lutz schrieb: > | I use suse 10.0 and have problems to set up ntlm_auth for squid. > | It uses samba 3.0.20 and squid 2.5.stable10Am Samstag 15 Oktober 2005 09:46 schrieb Robert Schetterer:> perhaps you should change to 3.0.20b latest version of samba > cause of winbind errors suse 10 rpms are for download at ftp.suse.com or > samba mirrorsI have installed the latest rpm and now it seems to work. Any idea why those patches not reported by "you"? Cheers, Tilo
Hi
I use suse 10.0. I want to use ntlm_auth
to authenticated users in squid.
Unfortunatly when I try to test the helper
I get this error:
proxy:~ # /usr/local/sbin/ntlm_auth --helper-protocol=squid-2.5-basic
--debuglevel=3
tilo *password*
[2005/10/14 18:10:58, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
NT_STATUS_INVALID_HANDLE: Invalid handle (0xc0000008)
ERR
I have googled a bit but I didn't found a hint what this error means.
Other logfiles, e.g. log.smbd on the server doesn't change anything
This is the smb.conf:
[global]
workgroup = WMS-NET
netbios name = proxy
username map = /etc/samba/smbusers
map to guest = Bad User
include = /etc/samba/dhcp.conf
security = domain
password server = home
wins server = 192.168.0.7
encrypt passwords = yes
idmap uid = 90000-100000
idmap gid = 90000-100000
winbind use default domain = yes
Any ideas what is wrong?
Cheers, Tilo