LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-15-2009, 09:45 AM   #1
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Rep: Reputation: 30
Deleted testuser from passwd file but squid still allows connections


I deleted a user from my squid_passwd file.
Restarted my browser and on the next connection, squid requested the password. However, it still allowed me in even though the user name testuser wasn't in the password file?

I tried with a fake user called fakeuser at the browser prompt and that denied me so the ncsa_auth must be working.

Any ideas as to what could be wrong?

On a related note on existingt connections, if the user is removed from the password file, shouldn't squid reauthenticate or does it only do that when the session is lost?
 
Old 08-15-2009, 11:26 AM   #2
repo
LQ 5k Club
 
Registered: May 2001
Location: Belgium
Distribution: Arch
Posts: 8,529

Rep: Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899
Did you restart squid ?
 
Old 08-15-2009, 11:46 AM   #3
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by repo View Post
Did you restart squid ?
No - would be pointless to restart squid every time you added a user or deleted one as that would affect all the existing users:
According to the squid user group it seems this affects the user cache auth schemes and I probably need to uncomment it in the conf and then restart.
Quote:
# "credentialsttl" timetolive
# Specifies how long squid assumes an externally validated
# usernameassword pair is valid for - in other words how often the
# helper program is called for that user. Set this low to force
# revalidation with short lived passwords. Note that setting this high
# does not impact your susceptibility to replay attacks unless you are
# using an one-time password system (such as SecureID). If you are using
# such a system, you will be vulnerable to replay attacks unless you
# also use the max_user_ip ACL in an http_access rule.
# auth_param basic credentialsttl 2 hours
However, I am not sure whether that means the user is asked for the user password every 2 hours or whether it is only since the last request.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
squid accepts connections only from localhost stefanolima Linux - Software 5 06-26-2009 02:33 AM
SQUID and /etc/passwd auth (with group?) pam? columb Linux - Server 1 03-02-2009 03:23 AM
Squid cache_peer and ssl connections BerzinTehvs Linux - Software 2 04-09-2008 02:50 PM
squid proxy connections not going through Moebius Linux - Networking 1 11-13-2005 09:42 AM
Squid problem with https connections thermoponch Linux - Networking 0 11-03-2004 04:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration