Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
# LDAP authentication
auth_param basic program /usr/lib/squid3/squid_ldap_auth \
-R \
-b "DC=company,DC=lan" \
-f "(sAMAccountName=%s)" \
-h dc1.company.lan \
-D "CN=squid,OU=Users_Special,DC=company,DC=lan" \
-W /etc/squid3/LDAP.pass
auth_param basic children 5
auth_param basic realm Company Proxy Authentication
auth_param basic credentialsttl 2 hours
# Define ACL type for groups (using AD)
external_acl_type group_dn %LOGIN /usr/lib/squid3/squid_ldap_group \
-R \
-b "DC=company,DC=lan" \
-f "(&(sAMAccountname=%u)(memberOf=%g))" \
-h dc1.company.lan \
-D "CN=squid,OU=Users_Special,DC=company,DC=lan" \
-W /etc/squid3/LDAP.pass -K
# Define AD groups
acl group-proxy-users external group_dn cn=proxy-users,ou=groups,dc=company,dc=lan
# Allow all for group-proxy-users
http_access allow group-proxy-users
[global]
# Domain auth configuration
workgroup = COMPANY
realm = COMPANY.LAN
security = ADS
restrict anonymous = 2
idmap uid = 10000-100000
idmap gid = 10000-100000
winbind enum users = Yes
winbind enum groups = Yes
wins server = 172.20.1.101
# Logs
syslog = 0
log file = /var/log/samba/log.%m
log level = 3
# Disable print server
disable spoolss = Yes
# Allow to delete readonly files
delete readonly = yes
# Shared folders
[DEPTS]
path = /mnt/data/depts
admin users = "@COMPANY\localadmin zel"
read only = No
hide unreadable = Yes
# Full support MS ACL
vfs objects = acl_tdb
[SHARE1]
...
Аутентификация файловых серверов GNU/Linux в домене Windows на базе AD. Часть 2