OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] proxy authentication against a Samba 4 AD
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] proxy authentication against a Samba 4 AD  (Read 2633 times)

FriendOfCarlotta

  • Newbie
  • *
  • Posts: 13
  • Karma: 1
    • View Profile
[SOLVED] proxy authentication against a Samba 4 AD
« on: August 10, 2017, 03:30:31 pm »
Hello!

Does proxy authentication against a samba 4 AD work at least?

I have successfully set up the LDAP access on a 17.7 test system:
* imported ca.pem of the samba server.
* port 636 and ssl configured.
* bind credentials work.
* authentication container queried and selected.
* servername of the AD server is resolvable via DNS.
* AD users can be successfully authenticated with  System | Access | Tester.

So far so good. But if I try to log in on the proxy with the client browser I get a loop. After the user data has been entered, the empty login dialog appears again and again.
The system log file shows:
Squid: LDAP bind error (Can not contact LDAP server)
Squid: user 'username' could not authenticate.

Why can squid not query the AD, but the OPNsense web interface very well?

Regards, Thomas
« Last Edit: August 11, 2017, 11:21:06 am by linuxmuster »
Logged

FriendOfCarlotta

  • Newbie
  • *
  • Posts: 13
  • Karma: 1
    • View Profile
Re: proxy authentication against a Samba 4 AD
« Reply #1 on: August 11, 2017, 11:19:16 am »
Hi!

It's a browser issue. Don't use the browser proxy settings! Configure the proxy in the system settings of the os (works for Linux and Windows) and tell the browser to use the system settings. Works now like a charm!

Thomas
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] proxy authentication against a Samba 4 AD
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2