Здравствуйте, начал настраивать squid с ntlm и basic авторизацией в домене win2003.
Настроил Samba, получил билет kerberos, ввел машину в домен. wbinfo -t, -u и -g отрабатывают правильно, но wbinfo -a не хочет авторизовывать NT_STATUS_ACCESS_DENIED (0xc0000022). Соответственно ntlm_auth не хочет авторизировать пользователей. Если использовать squid_ldap_auth то проходит только basic авторизация, а с ntlm_auth вообще никак.конфиг сквида
auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 5
auth_param ntlm keep_alive on
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
# TAG: acl
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl localhost src 192.168.1.128/32
acl to_localhost dst 127.0.0.0/8
acl DOMAIN proxy_auth REQUIRED
acl SSL_ports port 443
acl purge method PURGE
acl CONNECT method CONNECT
http_access allow manager localhost DOMAIN
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access allow DOMAIN
http_access allow localhost
http_access deny all
http_reply_access allow all
конфиг samba
[global]
log file = /var/log/samba/log.%m
socket options = TCP_NODELAY SO_SNDBUF=8192 SO_RCVBUF=8192
null passwords = yes
interfaces = eth0
hosts allow = 192.168.1.128 127.0.0.1
encrypt passwords = yes
idmap uid = 10000-20000
idmap gid = 10000-20000
auth methods = winbind
winbind enum groups = yes
winbind enum users = yes
winbind use default domain = yes
name resolve order = hosts wins bcast lmhosts
case sensitive = no
dns proxy = no
netbios name = squid
server string = proxy
password server = 192.168.1.1
realm = DOMAIN
client use spnego = yes
client signing = yes
local master = no
domain master = no
preferred master = no
workgroup = DOMAIN
debug level = 2
security = ads
dos charset = 866
unix charset = UTF-8
max log size = 50
os level = 0
wins server = 192.168.1.1
template shell = /bin/false
Подскажите пожалуйста в чем дело, а то пол инета уже перерыл.