Setup for Active Directory Integration

373 views
Skip to first unread message

Ralph S.

unread,
Mar 17, 2021, 10:34:31 AM3/17/21
to e2guardian
Hi again,

I'm trying to get an instance of e2guardian with squid setup to automatically authenticate a user logged into their PC with AD credentials. From what I read, I'm pretty sure this would be NTLM, and I've gotten it so if I point the client at squid, they authenticate, but if I point it at e2guardian, I get a "Proxy Authentication Error". Any idea on what I'm doing wrong or missing? 

So far I've got the upstream set in e2guardian.conf to port 1328 (Squid http bind port), and I've enabled the nltm auth plugin in both squid and e2guardian.con

Versions:
e2guardian: 5.4.2r
squid: 4.10
OS: Ubuntu 20.04.2
Client: Windows 10 Pro 20H2
DC: Samba AD Server: 4.13.5
Winbind: 4.13.5

Renato C. Pacheco

unread,
Mar 18, 2021, 2:25:17 PM3/18/21
to e2guardian
Hi Ralph,

In the last few months ago, I faced the same situation: by enabling NTLM in e2guardian, many sites didn't authenticate user's requests with "Proxy Authentication Error". I only could fix that puting squid authenticating first (in front of e2guardian) and forwarding all requests authenticated to e2guardian. In that way, this error doesn't appear anymore. If you want my confs (squid.conf and e2guardian.conf), I send them to you privately.

Best regards,
--
Renato Carneiro Pacheco
Security Analyst
http://www.facebook.com/renatocarneirop

"Não acredite no que eu digo, pois é a minha experiência e não a sua. Experimente, indague e busque." - Osho Rajneesh


--
E2guardian:
https://groups.google.com/d/forum/e2guardian
Github:
https://github.com/e2guardian/e2guardian
Follow us on twitter:
https://twitter.com/e2guardian
---
You received this message because you are subscribed to the Google Groups "e2guardian" group.
To unsubscribe from this group and stop receiving emails from it, send an email to e2guardian+...@googlegroups.com.
To view this discussion on the web, visit https://groups.google.com/d/msgid/e2guardian/ade0cb94-e4b8-41ff-a852-ceff4640f2b8n%40googlegroups.com.

Ralph S.

unread,
Mar 19, 2021, 7:14:28 AM3/19/21
to e2guardian
Hi Renato,

That would be appreciated!

Ralph

Ralph S.

unread,
Mar 19, 2021, 8:38:47 AM3/19/21
to e2guardian
Seems you can't actually reply directly to me, so I'll share my email:
blackbi...@gmail.com

On Thursday, March 18, 2021 at 2:25:17 PM UTC-4 renato....@gmail.com wrote:

Klaus Gundermann

unread,
Mar 19, 2021, 9:06:17 AM3/19/21
to e2guardian
Hi Renato,

could you send me the config files too, so I may create a chapter in the documentation handling the NTLM authentication ?

Best regards

Klaus

FredB

unread,
Mar 19, 2021, 9:15:33 AM3/19/21
to Klaus Gundermann, e2guardian
ICAP mode should be also a valid option, I guess
--
Envoyé de mon appareil Android avec Courriel K-9 Mail. Veuillez excuser ma brièveté.

Ralph S.

unread,
Mar 19, 2021, 9:51:41 AM3/19/21
to e2guardian
Could you elaborate Fred?

FredB

unread,
Mar 19, 2021, 10:08:58 AM3/19/21
to Ralph S., e2guardian
With ICAP, filtering is delegate to e2 but requests are not through in.
E2guardian is totally unaware about identification method, squid just sends URL, IP, ID, etc and E2 answers yes/no

FredB

unread,
Mar 19, 2021, 10:18:12 AM3/19/21
to Ralph S., e2guardian

Ralph S.

unread,
Mar 19, 2021, 10:21:58 AM3/19/21
to e2guardian
Oh I see, well would any sort of content filtering still work on E2Guardian whilst utilizing ICAP with Squid?
Message has been deleted

Andy Duandy

unread,
Mar 26, 2021, 10:16:04 AM3/26/21
to e2guardian
Bom dia Renato!

Se puder me ajudar enviando o squid.conf e e2guardian.conf para mim, estou encontrando a mesma dificuldade.

Obrigado.

Andy Duandy
Reply all
Reply to author
Forward
0 new messages