http://www.lissyara.su/?id=2101
Имею
Код: Выделить всё
uname -a
FreeBSD proxy.xxxx.local 10.1-RELEASE-p5 FreeBSD 10.1-RELEASE-p5 #0: Tue Jan 27 08:55:07 UTC 2015 root@amd64-builder.daemonology.net:/usr/obj/usr/src/sys/GENERIC amd64
Код: Выделить всё
# squid -v
Squid Cache: Version 3.4.11
Создал учетку в АД получил squid.keytab настроил Kerberos в клетке благополучно получаю билетики и прохожу все проверки
Код: Выделить всё
# kinit -k HTTP/proxy.xxxx.local
root@proxy:/usr/local/etc/squid # klist
Credentials cache: FILE:/tmp/krb5cc_0
Principal: HTTP/proxy.xxxx.local@XXXX.LOCAL
Issued Expires Principal
Feb 12 23:00:12 2015 Feb 13 09:00:12 2015 krbtgt/XXXX.LOCAL@XXXX.LOCAL
root@proxy:#
Код: Выделить всё
auth_param negotiate program /usr/local/libexec/squid/negotiate_kerberos_auth -d -i -s HTTP/proxy.хххх.local@ХХХХ.LOCAL
auth_param negotiate children 10 startup=5 idle=1
auth_param negotiate keep_alive off
acl localnet src 10.93.1.0/24
acl SSL_ports port 443acl SSL_ports port 443
acl Safe_ports port 80
acl Safe_ports port 443
acl Safe_ports port 1025-65535
http_access deny !Safe_ports
acl CONNECT method CONNECT
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
http_access allow localhost
http_access deny to_localhost
external_acl_type ldap_users ttl=3600 negative_ttl=3600 children-max=50 children-startup=10 \
children-idle=5 grace=15 %LOGIN /usr/local/libexec/squid/ext_kerberos_ldap_group_acl -a -i -g squid.fullaccess -m 64 -D ХХХХ.LOCAL -u squid -p хххххх
acl squid.denyall external ldap_users squid.denyall
acl squid.fullaccess external ldap_users squid.fullaccess
http_access deny all squid.denyall
http_access allow all squid.fullaccess
http_access deny all
http_port 192.168.120.3:3128
cache_dir ufs /var/squid/cache 20480 16 256
maximum_object_size_in_memory 1024 KB
cache_mem 256 MB
coredump_dir /var/squid/cache
access_log stdio:/var/squid/logs/access.log squid
cache_log /var/squid/logs/cache.log
cache_store_log none
logfile_rotate 14
pid_filename /var/run/squid/squid.pid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
cache_mgr damir@хххх.local
visible_hostname proxy.хххх.local
icp_port 0
error_default_language ru
error_directory /usr/local/etc/squid/errors/ru
error_log_languages on
hosts_file /etc/hosts
forwarded_for off
Код: Выделить всё
tail -f /var/squid/logs/access.log
1423754603.344 0 10.93.1.96 TCP_DENIED/407 3737 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/News/Today.xml - HIER_NONE/- text/html
1423755503.887 0 10.93.1.96 TCP_DENIED/407 3794 GET http://finance.services.appex.bing.com/Market.svc/AppTileV2? - HIER_NONE/- text/html
1423755503.888 0 10.93.1.96 TCP_DENIED/407 3727 GET http://travel.tile.appex.bing.com/api/livetile.xml? - HIER_NONE/- text/html
1423755504.377 0 10.93.1.96 TCP_DENIED/407 3801 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/HealthAndFitness/Home.xml? - HIER_NONE/- text/html
1423755504.399 0 10.93.1.96 TCP_DENIED/407 3765 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/Sports/Today.xml? - HIER_NONE/- text/html
1423755504.399 0 10.93.1.96 TCP_DENIED/407 3765 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/Sports/Today.xml? - HIER_NONE/- text/html
1423755504.400 0 10.93.1.96 TCP_DENIED/407 3794 GET http://finance.services.appex.bing.com/Market.svc/AppTileV2? - HIER_NONE/- text/html
1423755504.400 0 10.93.1.96 TCP_DENIED/407 3727 GET http://travel.tile.appex.bing.com/api/livetile.xml? - HIER_NONE/- text/html
1423755504.478 0 10.93.1.96 TCP_DENIED/407 3801 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/HealthAndFitness/Home.xml? - HIER_NONE/- text/html
1423755508.428 5047 10.93.1.96 TCP_DENIED/407 3777 GET http://foodanddrink.tile.appex.bing.com/api/feed/? - HIER_NONE/- text/html
1423756355.931 0 10.93.1.250 TCP_DENIED/407 3707 CONNECT iecvlist.microsoft.com:443 - HIER_NONE/- text/html
1423756355.960 0 10.93.1.250 TCP_DENIED/407 3793 CONNECT iecvlist.microsoft.com:443 - HIER_NONE/- text/html
1423756390.887 0 10.93.1.250 TCP_DENIED/407 3793 CONNECT ieonline.microsoft.com:443 - HIER_NONE/- text/html
1423756403.358 0 10.93.1.96 TCP_DENIED/407 3737 GET http://ru-ru.appex-rf.msn.com/cgtile/v1/ru-RU/News/Today.xml - HIER_NONE/- text/html
1423756661.640 0 10.93.1.96 TCP_DENIED/407 3755 CONNECT safebrowsing.google.com:443 - HIER_NONE/- text/html
1423756661.669 0 10.93.1.96 TCP_DENIED/407 3755 CONNECT safebrowsing.google.com:443 - HIER_NONE/- text/html
1423756661.673 0 10.93.1.96 TCP_DENIED/407 3775 CONNECT alt1-safebrowsing.google.com:443 - HIER_NONE/- text/html
1423756661.699 0 10.93.1.96 TCP_DENIED/407 3775 CONNECT alt1-safebrowsing.google.com:443 - HIER_NONE/- text/html
1423756968.124 0 10.93.1.96 TCP_DENIED/407 3706 CONNECT iecvlist.microsoft.com:443 - HIER_NONE/- text/html
1423756968.155 0 10.93.1.96 TCP_DENIED/407 3792 CONNECT iecvlist.microsoft.com:443 - HIER_NONE/- text/html
Код: Выделить всё
tail -f /var/log/squid/cache.log
2015/02/12 22:08:24 kid1| Starting new dnsserver helpers...
2015/02/12 22:08:24 kid1| helperOpenServers: Starting 1/32 'dnsserver' processes
2015/02/12 22:08:24 kid1| Starting new dnsserver helpers...
2015/02/12 22:08:24 kid1| helperOpenServers: Starting 1/32 'dnsserver' processes
2015/02/12 23:10:04 kid1| Set Current Directory to /var/squid/cache
2015/02/12 23:10:04 kid1| Starting Squid Cache version 3.4.11 for amd64-portbld-freebsd10.1...
2015/02/12 23:10:04 kid1| Process ID 2881
2015/02/12 23:10:04 kid1| Process Roles: worker
2015/02/12 23:10:04 kid1| With 58284 file descriptors available
2015/02/12 23:10:04 kid1| Initializing IP Cache...
2015/02/12 23:10:04 kid1| helperOpenServers: Starting 1/32 'dnsserver' processes
2015/02/12 23:10:04 kid1| helperOpenServers: Starting 5/10 'negotiate_kerberos_auth' processes
negotiate_kerberos_auth.cc(212): pid=2883 :2015/02/12 23:10:04| negotiate_kerberos_auth: INFO: Starting version 3.0.4sq
negotiate_kerberos_auth.cc(212): pid=2884 :2015/02/12 23:10:04| negotiate_kerberos_auth: INFO: Starting version 3.0.4sq
negotiate_kerberos_auth.cc(212): pid=2885 :2015/02/12 23:10:04| negotiate_kerberos_auth: INFO: Starting version 3.0.4sq
negotiate_kerberos_auth.cc(212): pid=2886 :2015/02/12 23:10:04| negotiate_kerberos_auth: INFO: Starting version 3.0.4sq
2015/02/12 23:10:04 kid1| helperOpenServers: Starting 10/50 'ext_kerberos_ldap_group_acl' processes
negotiate_kerberos_auth.cc(212): pid=2887 :2015/02/12 23:10:04| negotiate_kerberos_auth: INFO: Starting version 3.0.4sq
2015/02/12 23:10:05 kid1| Logfile: opening log stdio:/var/squid/logs/access.log
если перевожу на связку через LDAP то все начинает работать!
Подскажите куда еще глянуть?