search for: wbinfo_group

Displaying 20 results from an estimated 29 matches for "wbinfo_group".

2015 Dec 01
2
Problems with authentication in Samba4
...39;m implementing Squid3 Server and this server is working properly. But I think there is a problem with winbind (perhaps winbind separator), because when I put ^ as separator, how in Domain^Users, the error message appeared: root at proxy:~# *echo "bacci Domain^Users" | /usr/lib/squid3/wbinfo_group.pl <http://wbinfo_group.pl>* failed to call wbcLookupName: WBC_ERR_DOMAIN_NOT_FOUND Could not lookup name Domain^Users failed to call wbcStringToSid: WBC_ERR_INVALID_PARAM Could not convert sid to gid ERR But, when I put %20 as separator, how in Domain%20Users, the authentication is OK. ro...
2006 Mar 23
0
squid + external_acl_type + wbinfo_group.pl, Help needed
...================================== auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp auth_param ntlm children 30 auth_param ntlm max_challenge_reuses 0 auth_param ntlm max_challenge_lifetime 2 minutes external_acl_type nt_group ttl=0 concurrency=5 %LOGIN /usr/lib/squid/wbinfo_group.pl acl unrestrictedusers external nt_group internet http_access allow unrestrictedusers ========================================================== samba-3.0.21c-1 [global] workgroup = DNA server string = Samba Server log level = 3 log file = /var/log/samba/samba.log max log size =...
2006 Feb 27
1
wbinfo_group.pl / wbinfo -r not working!
...to set up my ACL's based on groups, rather than individual user accounts. I have successfully joined my samba box to our windows domain (2k). For some reason I had to enter the domain controller name instead of the domain name when doing so. I am now having issues looking up user groups using wbinfo_group and/or "wbinfo -r username". The following are some commands, conf files & logs (the parts that I believe are relevant). I have a feeling I have more than one issue going on here. Please let me know if you need more info. I doubt there are limitations, but we are in a somewhat large...
2009 Jun 17
1
getent group fails
...groups. BUILTIN+administrators BUILTIN+users But if I do a wbinfo -g, all the AD groups show up. This alone is not the overall problem, but it is creating a problem because I need getent to return the groups for logging different AD groups to different log files in squid. Another problem is the wbinfo_group.pl and I know this is a squid app, but from what I understand it used wbinfo. /usr/lib/squid/wbinfo_group.pl tuser password Could not get groups for user tuser I can provice config data and anything else necessary. Thanks in advance.
2004 Apr 19
0
RES: squid authentication to samba 3
Yes, it is. I've made that some times... After having the Samba infra-structure running (winbind -u, winbind -g, winbind -a), you need to create some ACLs in squid.conf, take a look at: http://www.squid-cache.org/Doc/FAQ/FAQ-23.html#winbind To check group membership you can use wbinfo_group or LDAP, I had some problems setting wbinfo_group with Samba 3.0.2, that's why I use LDAP. If you can I can send you a sample. Estevam Henrique -----Mensagem original----- De: samba-bounces+ecarvalho=bmf.com.br@lists.samba.org [mailto:samba-bounces+ecarvalho=bmf.com.br@lists.samba.org] Em no...
2005 Nov 04
1
wbinfo and 3.0.21pre1
Hello we are facing issue to check the membership of some users in AD groups (for winbind). When using the script wbinfo_group.pl, we had not the same result for the same couple "user group", if we lauch the script several times. We've noticed in particular that the wbinfo -r command sometimes sends back the list of group, but the next sends backs nothing (again, while using the same couple "user group&...
2013 Feb 08
2
NTLM autentication problems
I'm trying to configure Squid ntlm autentication on Samba4 DC. I followed Squid and Samba's documentation and i got success when I login with user natalia.silva, but if I log with natalia.vaz i get the error -- Nat?lia Vaz Silva Administradora de redes
2006 Jul 28
2
WINBIND on a VERY LARGE FOREST
...mbership. I need to allow access to squid only to some users on different group. So i setup samba with winbind, ads and kerberos support. Configuing /etc/krb5.conf correctly to permit samba to join and query the gc with net ads join. Configured samba and winbind correclty, all ok. Now i need to use wbinfo_group.pl to verify user's groups. But before that i tested the configuration with wbinfo -r DOMAIN\\user. If i search a user on GC domain, the domain samba joined directly, i can see all group belonging to a user correclty. If i add and remove users form AD, i need to wait 5 second (i setup winbind c...
2005 Sep 30
1
Trouble with ntlm_auth
Hi all, I'm having trouble getting ntlm_auth working with the "--require-membership-of=" option. I did rebuild the Samba RPM so that it had the --enable-auth="ntlm,basic" and --enable-external-acl-helpers="wbinfo_group" settings. The command line test for the squid-2.5-basic protocol returns an "OK". The one using the squid-2.5-ntlmssp protocol returns what looks like a line that should be going to a log file and then a "BH". Any time that I add the --require-membership parameter to th...
2005 Oct 25
1
winbind or netsamlogon_cache.tdb issue
...ear. Last week, we have defined new AD groups to use for this project. The problem that i am facing, is that for some users, the check to see if the user is in the group is working fine, but for some other users, it returns me an error (but the user is in the group !)I am using for this check the wbinfo_group.pl file. What i have noticed is that if i start winbind without cache, everything seems to be ok. Also, if i delete the netsamlogon_cache.tdb file and restart winbind, everything seems to be ok. Do you have a idea of what could have generated this situation ? By the way, in my context could it be...
2005 Jun 30
1
active directory auth & some more
I've been trying for a few days to get a samba server 3.0.13 to work as an adition to some servers inside a Active Directory domain (windows 2003) servers. My first problem is that wbinfo_group.pl does not work anymore after SP1 update to windows domain controllers, it is not capable of getting sig for the group. Second pb. I managed to get access for windows workstations to the samba server according to the authentication from Active Directory. Managing rights from the Security tab...
2017 Apr 18
2
winbind and white spaces on user/group names
...buntu 16.04 LTS with Samba 4.3.11 (from distribution). Our ADS is Windows 2008 R2. We want to use Linux as a squid proxy with domain auth (SSO). Problem is, that most of the usernames have a white space and it seems that winbind wont handle it. I get this on my cache log with /usr/lib/squid/ext_wbinfo_group_acl (wbinfo_group.pl) script. Got max Internet-Access from squid User: -max- Group: -Internet-Accesss- SID: -S-1-5-21-3122064890-3824127986-1965815265-2719- GID: -10004- failed to call wbcGetGroups: WBC_ERR_DOMAIN_NOT_FOUND Could not get groups for user max Sending ERR to squid Problem is,...
2005 Oct 14
1
wbinfo not looking up groups in mixed MS NT/2k AD
Hello, I'm having trouble when I try do get a group SID from my domain, the user lookup and authentication is working fine. Actually what I'm trying to do is to authenticate squid against MS AD using winbind. I need to restrict access by group, so I'm using wbinfo_group.pl to do it. The machine has been built to be a proxy server only. I'm using Suse Linux 9.3 Professional samba-3.0.13-1.1 squid-2.5.STABLE9-4.4 Below are my .conf files: /etc/nsswitch.conf passwd: files winbind shadow: files nis group: files winbind hosts: files lwres dns networks: f...
2008 Aug 31
2
smb_auth problem
...28 squid_kerb_auth -rwxr-xr-x 1 root root 19000 Jul 6 06:28 squid_ldap_group -rwxr-xr-x 1 root root 5996 Jul 6 06:28 squid_session -rwxr-xr-x 1 root root 10248 Jul 6 06:28 squid_unix_group -rwxr-xr-x 1 root root 3732 Jul 6 06:26 unlinkd -rwxr-xr-x 1 root root 2359 Abr 9 2007 wbinfo_group.pl -rwxr-xr-x 1 root root 8776 Jul 6 06:28 yp_auth 8<---------------------------------- The SMB configuration sek:/usr/lib/squid# cat /etc/samba/smb.conf # Samba config file created using SWAT # from 192.168.0.2 (192.168.0.2) # Date: 2008/04/04 23:07:20 [global] workgroup = sekplast...
2017 Apr 18
0
winbind and white spaces on user/group names
...4.3.11 (from distribution). Our > ADS is Windows 2008 R2. We want to use Linux as a squid proxy with > domain auth (SSO). > Problem is, that most of the usernames have a white space and it > seems that winbind wont handle it. > > I get this on my cache log with /usr/lib/squid/ext_wbinfo_group_acl > (wbinfo_group.pl) script. > > Got max Internet-Access from squid > User: -max- > Group: -Internet-Accesss- > SID: -S-1-5-21-3122064890-3824127986-1965815265-2719- > GID: -10004- > failed to call wbcGetGroups: WBC_ERR_DOMAIN_NOT_FOUND > Could not get groups fo...
2004 May 13
0
winbindd lookup failure
...t_require_membership_sid(237) Winbindd lookupname failed to resolve 'DOMAIN/Group' into a SID! If I do wbinfo -n Group, I get a sid and wbinfo -s "sid" gives me the group. I have gone through mailing list and seen some people that indicate you can use an external helper like wbinfo_group.pl, but I just wondered if second squid.conf setting I got from the Samba docs is known to work, or if there is something else I need to look at?
2005 Jun 06
0
Problems Winbindd/Squid ?
...ate homedir = /home/%D/%U socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192 interfaces = 10.206.1.251/24 local master = no name resolve order = wins lmhosts bcast host wins server = 172.16.1.15,172.16.1.27,172.17.1.14 dns proxy = no i use Winbind only for proxy auth ntlm with wbinfo_group.pl ... no for file server
2006 Oct 06
0
Problem with ntlm authentication - Please help!!
...g with the 32 bits version. Squid?s compile options are the following: configure options: --enable-auth=ntlm,basic --enable-delay-pools --enable-snmp --enable-useragent-log --prefix=/usr/local/squid --enable-ssl --enable-underscores --enable-storeio=ufs,aufs,diskd --enable-external-acl-helpers=wbinfo_group The problem we are facing is that ntlm helpers begin to enter in "R" and "B" states, until every one of them stops authenticating, and then Squid dies. The error message associated to the crash is this: " Too many queued ntlmauthenticator requests (301 on 60)". D...
2005 May 25
1
Winbind - loss of trust
Hi We are running a OpenBSD 3.6 server with squid 2.5.STABLE7 configure options: --enable-auth=ntlm,basic --enable-external-acl-helpers=wbinfo_group --localstatedir=/var/squid --enable-snmp. We are running samba with vers 3.0.4 with winbind support This is our samba file workgroup = apac netbios name = auasv-00001 server string = Sydney LAN Proxy security = domain password server = audc-00001 audc-00002 audc-00003 winbind uid = 1000...
2008 Apr 29
1
winbindd hangs up while retreiving usernames.
...estme returns plaintext password authentication succeeded challenge/response password authentication succeeded wbinfo -s successfuly converts SIDs to object-names. however, wbinfo -u and wbinfo -g returns lists only after 20-30 seconds. wbinfo -r testme doesn't work, hanging up, so squid's wbinfo_group.pl script doesn't work also. I have in my /var/log/samba/log.winbindd error's: nsswitch/winbindd_ads.c:query_user_list(218) Not a user account? atype=0x30000000 and rpc_api_pipe: Remote machine CITY2 pipe \NETLOGON fnum 0x8returned critical error. Error was Call timed out: server did no...