19.4.09

Squid and Active Directory authentication (NTLM auth)

First join linux box to Actiwe directory

Add next rows to /etc/squid/squid.conf

#Configure auth helper: Domain - Active Directory domain name, "Internet users" - domain #group for internet access.

auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp --require-membership-of=DOMAIN\\"Internet Users"
auth_param ntlm children 5
auth_param ntlm keep_alive on
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic --require-membership-of=DOMAIN\\"Internet Users"
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off


#Create access list

acl DOMAIN proxy_auth REQUIRED

#Create rule

http_access allow DOMAIN

Now all users from domain group "Internet users" have access to internet
share on: facebook

No comments:

Post a Comment