Displaying 20 results from an estimated 29 matches for "wbinfo_group".
2015 Dec 01
2
Problems with authentication in Samba4
...39;m implementing
Squid3 Server and this server is working properly. But I think there is a
problem with winbind (perhaps winbind separator), because when I put ^ as
separator, how in Domain^Users, the error message appeared:
root at proxy:~# *echo "bacci Domain^Users" | /usr/lib/squid3/wbinfo_group.pl
<http://wbinfo_group.pl>*
failed to call wbcLookupName: WBC_ERR_DOMAIN_NOT_FOUND
Could not lookup name Domain^Users
failed to call wbcStringToSid: WBC_ERR_INVALID_PARAM
Could not convert sid to gid
ERR
But, when I put %20 as separator, how in Domain%20Users, the authentication
is OK.
ro...
2006 Mar 23
0
squid + external_acl_type + wbinfo_group.pl, Help needed
...==================================
auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 30
auth_param ntlm max_challenge_reuses 0
auth_param ntlm max_challenge_lifetime 2 minutes
external_acl_type nt_group ttl=0 concurrency=5 %LOGIN
/usr/lib/squid/wbinfo_group.pl
acl unrestrictedusers external nt_group internet
http_access allow unrestrictedusers
==========================================================
samba-3.0.21c-1
[global]
workgroup = DNA
server string = Samba Server
log level = 3
log file = /var/log/samba/samba.log
max log size =...
2006 Feb 27
1
wbinfo_group.pl / wbinfo -r not working!
...to set up my
ACL's based on groups, rather than individual user accounts.
I have successfully joined my samba box to our windows domain (2k).
For some reason I had to enter the domain controller name instead of
the domain name when doing so. I am now having issues looking up user
groups using wbinfo_group and/or "wbinfo -r username".
The following are some commands, conf files & logs (the parts that I
believe are relevant). I have a feeling I have more than one issue
going on here. Please let me know if you need more info.
I doubt there are limitations, but we are in a somewhat large...
2009 Jun 17
1
getent group fails
...groups.
BUILTIN+administrators
BUILTIN+users
But if I do a wbinfo -g, all the AD groups show up.
This alone is not the overall problem, but it is creating a problem
because I need getent to return the groups for logging different AD
groups to different log files in squid.
Another problem is the wbinfo_group.pl and I know this is a squid app,
but from what I understand it used wbinfo.
/usr/lib/squid/wbinfo_group.pl
tuser password
Could not get groups for user tuser
I can provice config data and anything else necessary.
Thanks in advance.
2004 Apr 19
0
RES: squid authentication to samba 3
Yes, it is. I've made that some times...
After having the Samba infra-structure running (winbind -u, winbind -g,
winbind -a), you need to create some ACLs in squid.conf, take a look at:
http://www.squid-cache.org/Doc/FAQ/FAQ-23.html#winbind
To check group membership you can use wbinfo_group or LDAP, I had some
problems setting wbinfo_group with Samba 3.0.2, that's why I use LDAP. If
you can I can send you a sample.
Estevam Henrique
-----Mensagem original-----
De: samba-bounces+ecarvalho=bmf.com.br@lists.samba.org
[mailto:samba-bounces+ecarvalho=bmf.com.br@lists.samba.org] Em no...
2005 Nov 04
1
wbinfo and 3.0.21pre1
Hello
we are facing issue to check the membership of some users in AD groups (for
winbind).
When using the script wbinfo_group.pl, we had not the same result for the same
couple "user group", if we lauch the script several times.
We've noticed in particular that the wbinfo -r command sometimes sends back the
list of group, but the next sends backs nothing (again, while using the same
couple "user group&...
2013 Feb 08
2
NTLM autentication problems
I'm trying to configure Squid ntlm autentication on Samba4 DC. I followed
Squid and Samba's documentation and i got success when I login with user
natalia.silva, but if I log with natalia.vaz i get the error
--
Nat?lia Vaz Silva
Administradora de redes
2006 Jul 28
2
WINBIND on a VERY LARGE FOREST
...mbership. I need to allow access to squid only to some users on different group.
So i setup samba with winbind, ads and kerberos support.
Configuing /etc/krb5.conf correctly to permit samba to join and query the gc with net ads join. Configured samba and winbind correclty, all ok.
Now i need to use wbinfo_group.pl to verify user's groups.
But before that i tested the configuration with wbinfo -r DOMAIN\\user. If i search a user on GC domain, the domain samba joined directly, i can see all group belonging to a user correclty. If i add and remove users form AD, i need to wait 5 second (i setup winbind c...
2005 Sep 30
1
Trouble with ntlm_auth
Hi all,
I'm having trouble getting ntlm_auth working with the
"--require-membership-of=" option. I did rebuild the Samba RPM so that it
had the --enable-auth="ntlm,basic" and
--enable-external-acl-helpers="wbinfo_group" settings. The command line
test for the squid-2.5-basic protocol returns an "OK". The one using the
squid-2.5-ntlmssp protocol returns what looks like a line that should be
going to a log file and then a "BH". Any time that I add the
--require-membership parameter to th...
2005 Oct 25
1
winbind or netsamlogon_cache.tdb issue
...ear.
Last week, we have defined new AD groups to use for this project.
The problem that i am facing, is that for some users, the check to see if
the user is in the group is working fine, but for some other users, it returns
me an error (but the user is in the group !)I am using for this check the
wbinfo_group.pl file.
What i have noticed is that if i start winbind without cache, everything seems
to be ok.
Also, if i delete the netsamlogon_cache.tdb file and restart winbind, everything
seems to be ok.
Do you have a idea of what could have generated this situation ?
By the way, in my context could it be...
2005 Jun 30
1
active directory auth & some more
I've been trying for a few days to get a samba server 3.0.13 to work as
an adition to some servers inside a Active Directory domain (windows
2003) servers.
My first problem is that wbinfo_group.pl does not work anymore after SP1
update to windows domain controllers, it is not capable of getting sig
for the group.
Second pb. I managed to get access for windows workstations to the samba
server according to the authentication from Active Directory. Managing
rights from the Security tab...
2017 Apr 18
2
winbind and white spaces on user/group names
...buntu 16.04 LTS with Samba 4.3.11 (from distribution). Our ADS
is Windows 2008 R2. We want to use Linux as a squid proxy with domain
auth (SSO).
Problem is, that most of the usernames have a white space and it seems
that winbind wont handle it.
I get this on my cache log with /usr/lib/squid/ext_wbinfo_group_acl
(wbinfo_group.pl) script.
Got max Internet-Access from squid
User: -max-
Group: -Internet-Accesss-
SID: -S-1-5-21-3122064890-3824127986-1965815265-2719-
GID: -10004-
failed to call wbcGetGroups: WBC_ERR_DOMAIN_NOT_FOUND
Could not get groups for user max
Sending ERR to squid
Problem is,...
2005 Oct 14
1
wbinfo not looking up groups in mixed MS NT/2k AD
Hello,
I'm having trouble when I try do get a group SID from my domain, the
user lookup and authentication is working fine.
Actually what I'm trying to do is to authenticate squid against MS AD
using winbind. I need to restrict access by group, so I'm using
wbinfo_group.pl to do it.
The machine has been built to be a proxy server only.
I'm using Suse Linux 9.3 Professional
samba-3.0.13-1.1
squid-2.5.STABLE9-4.4
Below are my .conf files:
/etc/nsswitch.conf
passwd: files winbind
shadow: files nis
group: files winbind
hosts: files lwres dns
networks: f...
2008 Aug 31
2
smb_auth problem
...28 squid_kerb_auth
-rwxr-xr-x 1 root root 19000 Jul 6 06:28 squid_ldap_group
-rwxr-xr-x 1 root root 5996 Jul 6 06:28 squid_session
-rwxr-xr-x 1 root root 10248 Jul 6 06:28 squid_unix_group
-rwxr-xr-x 1 root root 3732 Jul 6 06:26 unlinkd
-rwxr-xr-x 1 root root 2359 Abr 9 2007 wbinfo_group.pl
-rwxr-xr-x 1 root root 8776 Jul 6 06:28 yp_auth
8<----------------------------------
The SMB configuration
sek:/usr/lib/squid# cat /etc/samba/smb.conf
# Samba config file created using SWAT
# from 192.168.0.2 (192.168.0.2)
# Date: 2008/04/04 23:07:20
[global]
workgroup = sekplast...
2017 Apr 18
0
winbind and white spaces on user/group names
...4.3.11 (from distribution). Our
> ADS is Windows 2008 R2. We want to use Linux as a squid proxy with
> domain auth (SSO).
> Problem is, that most of the usernames have a white space and it
> seems that winbind wont handle it.
>
> I get this on my cache log with /usr/lib/squid/ext_wbinfo_group_acl
> (wbinfo_group.pl) script.
>
> Got max Internet-Access from squid
> User: -max-
> Group: -Internet-Accesss-
> SID: -S-1-5-21-3122064890-3824127986-1965815265-2719-
> GID: -10004-
> failed to call wbcGetGroups: WBC_ERR_DOMAIN_NOT_FOUND
> Could not get groups fo...
2004 May 13
0
winbindd lookup failure
...t_require_membership_sid(237)
Winbindd lookupname failed to resolve 'DOMAIN/Group' into a SID!
If I do wbinfo -n Group, I get a sid and wbinfo -s "sid" gives me the group.
I have gone through mailing list and seen some people that indicate you
can use an external helper like wbinfo_group.pl, but I just wondered if
second squid.conf setting I got from the Samba docs is known to work, or
if there is something else I need to look at?
2005 Jun 06
0
Problems Winbindd/Squid ?
...ate homedir = /home/%D/%U
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
interfaces = 10.206.1.251/24
local master = no
name resolve order = wins lmhosts bcast host
wins server = 172.16.1.15,172.16.1.27,172.17.1.14
dns proxy = no
i use Winbind only for proxy auth ntlm with wbinfo_group.pl ... no for
file server
2006 Oct 06
0
Problem with ntlm authentication - Please help!!
...g with the 32 bits version.
Squid?s compile options are the following:
configure options: --enable-auth=ntlm,basic
--enable-delay-pools --enable-snmp
--enable-useragent-log --prefix=/usr/local/squid
--enable-ssl --enable-underscores
--enable-storeio=ufs,aufs,diskd
--enable-external-acl-helpers=wbinfo_group
The problem we are facing is that ntlm helpers begin
to enter in "R" and "B" states, until every one of
them stops authenticating, and then Squid dies. The
error message associated to the crash is this: " Too
many queued ntlmauthenticator requests (301 on 60)".
D...
2005 May 25
1
Winbind - loss of trust
Hi
We are running a OpenBSD 3.6 server with squid 2.5.STABLE7
configure options: --enable-auth=ntlm,basic
--enable-external-acl-helpers=wbinfo_group --localstatedir=/var/squid
--enable-snmp.
We are running samba with vers 3.0.4 with winbind support
This is our samba file
workgroup = apac
netbios name = auasv-00001
server string = Sydney LAN Proxy
security = domain
password server = audc-00001 audc-00002 audc-00003
winbind uid = 1000...
2008 Apr 29
1
winbindd hangs up while retreiving usernames.
...estme returns
plaintext password authentication succeeded
challenge/response password authentication succeeded
wbinfo -s successfuly converts SIDs to object-names.
however, wbinfo -u and wbinfo -g returns lists only after 20-30 seconds.
wbinfo -r testme doesn't work, hanging up, so squid's wbinfo_group.pl script
doesn't work also.
I have in my /var/log/samba/log.winbindd error's:
nsswitch/winbindd_ads.c:query_user_list(218)
Not a user account? atype=0x30000000
and
rpc_api_pipe: Remote machine CITY2 pipe \NETLOGON fnum 0x8returned critical
error. Error was Call timed out: server did no...