lachesis 12-13-2006 11:25 AM

[FC5] Trying to integrate Squid proxy with LDAP

We're trying to integrate the squid proxy with ldap authentication. I've made all necessary changes to the squid.conf, but when I uncomment out the line which looks correct the service fails to start. Can anyone with a bit of time please take a look over it and see if I've done anything horrendously wrong?


[root@rq6squid01 squid]# cd /etc/squid
[root@rq6squid01 squid]# vi squid.conf

hierarchy_stoplist cgi-bin ?
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
;;auth_param basic program /etc/squid/ldap_auth -R -b "dc=rlbuht,dc=lan" -D "cn=Administrator,cn=Users,dc=rlbuht,dc=lan" -w "password" -f sAMAccountname=%s -h
auth_param basic children 5
auth_param basic realm rlbuht.lan
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern . 0 20% 4320
acl all src
acl manager proto cache_object
acl localhost src
acl to_localhost dst
acl SSL_ports port 443 563
http_access allow manager localhost
http_access deny manager
#http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access allow all
http_reply_access allow all
icp_access allow all
coredump_dir /var/spool/squid

