squid_ldap_auth and SSL on Novell eDirectory
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > Squid > squid_ldap_auth and SSL on Novell eDirectory




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    squid_ldap_auth and SSL on Novell eDirectory  
~matteo


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
05-24-07 06:14 PM

Hi all,

I need Squid to authenticate users against a Novell eDirectory 8. I'd
like to use SSL encryption between Squid and the LDAP tree, thus I
guess I need to use the helper squid_ldap_auth. Although I've read a
lot of threads about this topic I haven't gotten very far with the
current implementation of the helper.

I'm using Squid 2.6.STABLE12 on Gentoo. In the squid.conf file I have

auth_param basic program /usr/libexec/squid/squid_ldap_auth -b
"o=myroot" -f "(&(objectClass=person)(cn=%s)
 (groupMembership=cn=Internet,ou=CommonGr
oups,o=myroot))" -u cn -P
ldaps://horus

where horus is the Novell machine with the LDAP tree (horus is DNS-
mapped, actually that machine is THE dns server). This solution
doesn't work, as I keep getting a "Can't contact LDAP server" message
error in /var/log/squid/cache.log logfile. Switching to horus'
ipaddress doesn't change anything. The solution I found is using
squid_ldap_auth without ssl encryption with stunnel on the squid
machine, listening on the unencrypted ldap port and sending encrypted
data to the horus encrypted ldap port (636). This works!

Now I want to do the same on an IpCop 1.4.15 box, as I'd like to have
firewall + proxy + content filter on the same machine. I installed the
advenced proxy addon for IpCop, which installs the very same Squid
version (2.6.STABLE12). Now the problem is that I cannot install
stunnel on IpCop, as there's no addon for it nor does it have gcc.

Now the question is: is there any squid-only solution to this problem
(avoiding stunnel usage)? Why do I keep getting error messages when
specifying ldap URIs as ldaps:// ?

Thanks in advance

--
~matteo






[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 03:45 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register