LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-16-2007, 03:36 AM   #1
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Rep: Reputation: 32
auth_param Squid asking to much


Hello!

We have auth_param working without problems.

squid.conf:

Quote:
auth_param basic program /usr/local/squid/libexec/ncsa_auth /usr/local/squid/user
auth_param basic children 5
auth_param basic realm XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
auth_param basic credentialsttl 2 hours
acl POWERUSER proxy_auth "/usr/local/squid/user"
acl POWERUSER proxy_auth REQUIRED

But I also have useres which are no poweruser and should have access to a site for telefonnumbers. The Problem is that this site has a whole bunch of sublinks leading to Banner pages (as the finance about this clicks).

The problem is that users that are not auth. and in the poweruser group get a loginpage for each of the banners as they come not from that site.

So the internatpage A.html is free to access for everybody but on that site are a lot of sublinks eg. B.html, C.html, D.html. If the user is not in the poweruser group for each of the linked sites a loginwindow is opened. How can i change that, so that the user only gets a login window once each session ?

Thanks
 
Old 04-17-2007, 08:54 AM   #2
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Original Poster
Rep: Reputation: 32
push

no one ?
 
Old 04-19-2007, 12:01 AM   #3
runnerfrog
Member
 
Registered: Jul 2006
Location: Paraná, Argentina
Distribution: Frugalware 0.6 (Terminus) - Kubuntu 7.04 (Feisty Fawn Herd 5)
Posts: 217

Rep: Reputation: 31
Saavik, many things are not clear there, too many for anyone to answer clearly. My strong guess is that your squid.conf is wrong at some point (not visible at your quote). Unfortunately you are so unclear, that your /usr/local/squid/user file can be the problem too.
Just a guess because it is very hard answering something with this available data. Your post doesn't show any differences between the powerusers group and any other group. Be clear to have a clear answer, and I can give a little try, with my little time.
 
Old 04-19-2007, 01:06 AM   #4
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Original Poster
Rep: Reputation: 32
Well

Ok, so I`ll do my very best....


1. We have added the auth_mod to squid so that user CAN auth. by name and password
2. We also have a whitelist with http adresses which are free for access for anybody WITHOUT auth. needed
3. If a user wants to access a site which is not listed in the whitelist he MUST auth to squid and than he can access ANY site on the internet.

So it looks like in the squid.conf

Quote:
#AUTH
auth_param basic program /usr/local/squid/libexec/ncsa_auth /usr/local/squid/user
auth_param basic children 5
auth_param basic realm XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
auth_param basic credentialsttl 2 hours
acl POWERUSER proxy_auth "/usr/local/squid/user"
acl POWERUSER proxy_auth REQUIRED


acl whitelist url_regex "/usr/local/squid/whitelist"
acl blacklist url_regex "/usr/local/squid/blacklist"

http_access allow whitelist
http_access allow POWERUSER
http_access deny blacklist
So my problem is that if there is a site a.html which is in the whitelist but this site includes a link in a frame to the site b.html, you get the login window.

If this would only be once it would not be a big thing, but some site have 5-10 links and thats really not so nice.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SQUID for blocking yahoo and msn [inc squid.conf] chrisfirestar Linux - Security 10 03-03-2008 08:33 AM
Squid: special configuration for remote Squid server hamish Linux - Software 0 12-06-2005 03:58 PM
squid message customization, hiding squid versioin rajnishmishra Linux - Networking 0 11-27-2004 03:55 AM
squid conf: squid failed when I type insert redirect_program /usr/bin/squidguard Niceman2005 Linux - Software 1 11-24-2004 02:29 PM
Squid load testing software / Squid optimisation? gundelgauk Linux - Networking 2 08-31-2004 07:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 06:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration