Bluehost.com Web Hosting $6.95

Re: [squid-users] squid_ldap_group authentication against Active

This is a discussion on Re: [squid-users] squid_ldap_group authentication against Active within the Squid Users forums, part of the Web Server and Related Forums category; On Thu, 18 Dec 2003, Keppner, Christoph wrote: > I know so far, that squid_ldap_group is the right program, but ...


Go Back   Usenet Forums > Web Server and Related Forums > Squid Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-19-2003
Henrik Nordstrom
 
Posts: n/a
Default Re: [squid-users] squid_ldap_group authentication against Active

On Thu, 18 Dec 2003, Keppner, Christoph wrote:

> I know so far, that squid_ldap_group is the right program, but how do i use
> it? In a mail from Henrik Nordstrom, there was this description:


squid_ldap_group is used via the external_acl_type directive. See the
manual (yes there is a manual for squid_ldap_group).

> > 0. Optionally bind (login) as a dummy user (by DN) if anonymous
> > searches is disallowed in the directory (-D+-W arguments)
> > 1. Search for the user in the directory (-F argument with the same data
> > as -f to squid_ldap_auth)
> > 2. Search for the group in the directory and verify that the user is
> > member of the group (-f argument).

>
> How must the -f argument looks like?!?


The manual has some good hints on this. The purpose of the -f argument to
squid_ldap_group is similar to the purpose of the -f argument to
squid_ldap_auth but looking for a matching group rather than a matching
user.

Usually this looks like

-f "(&(cn=%g)(member=%u)(objectClass=groupOfNames ))"

asking the helper to search for a groupOfNames with the group name as cn
and the user DN as member. Should probably make this the default when -F
is specified.

The user DN is looked up by the -F argument in the same manner as the -f
argument to squid_ldap_auth.

Regards
Henrik

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 10:00 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0