OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Squid Proxy - SSO with Kerberos does not work
« previous next »
  • Print
Pages: [1]

Author Topic: Squid Proxy - SSO with Kerberos does not work  (Read 188 times)

dng

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Squid Proxy - SSO with Kerberos does not work
« on: November 10, 2024, 07:51:04 pm »
Hello everyone,

I have configured the Squid Proxy on OPNsense (latest version) and successfully connected OPNsense to the AD. When I access a website from a client, the login prompt appears, and I can successfully authenticate with the AD user.

After that, I installed the Kerberos plugin and enabled SSO for the proxy. When I enter the username and password of an AD user on the SSO page for testing, a token is generated, and it seems to be OK. At least when I deliberately enter incorrect data, I get a different message.

However, when I then try to access a website from the client, the login prompt still appears. But even when I enter the AD user’s credentials, I can’t get any further.
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6923
  • Karma: 583
    • View Profile
Re: Squid Proxy - SSO with Kerberos does not work
« Reply #1 on: November 10, 2024, 10:19:20 pm »
I am not entirely sure if this is supposed to work at all or in a broken state, but ...

For Kerberos to work the OPNsense MUST use the AD DCs as its recursive name servers and no other one.
Also time synchronisation is critical.

Is that the case?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Squid Proxy - SSO with Kerberos does not work
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2