-
Notifications
You must be signed in to change notification settings - Fork 647
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
os-web-proxy-useracl // Proxy service crash after add any group rule #1065
Comments
|
LDAP-connector must be properly configured and available. Squid helper can't connect to LDAP-server. You can read the documentation on SSO configuration https://www.smart-soft.ru/support/documentation/handbook/ting/proxy_auth_kerberos.html |
|
Is there also an English version? :) |
|
No, only Russian. |
|
Yes, I read this manual and check every step. Maybe the problem is that in domain 3 DC, but only one can be specified in LDAP connector? |
|
"System: Access: Tester" for LDAP-connector working ok ? |
|
One DC is enough. |
|
You use domain on windows server 2003 ? |
No. We use Windows Server 2008R2+ |
|
I'm sorry. I closed the issue inadvertently. The problem is urgent |
|
This issue has been automatically timed-out (after 180 days of inactivity). For more information about the policies for this repository, If someone wants to step up and work on this issue, |


Latest OPNsense 18.7.9-amd64

LDAP, SSO (over Kerberos os-web-proxy-sso plugin) configured
Users log in correctly and transparently.
If I add new any user rule to os-web-proxy-useracl plugin - all good
but if i add any group rule:
and try to access to any site - squid crash
Error:
support_sasl.cc(276): pid=50035 :2018/12/13 14:49:03| kerberos_ldap_group: ERROR: ldap_sasl_interactive_bind_s error: Can't contact LDAP serversupport_ldap.cc(957): pid=50035 :2018/12/13 14:49:03| kerberos_ldap_group: ERROR: Error while binding to ldap server with SASL/GSSAPI: Can't contact LDAP server...
Crash:
...
2018/12/13 16:07:31 kid1| Too few ext_group_ldap_0 processes are running (need 1/5)2018/12/13 16:07:31 kid1| Starting new helpers2018/12/13 16:07:31 kid1| helperOpenServers: Starting 1/5 'ext_kerberos_ldap_group_acl' processes2018/12/13 16:07:57 kid1| WARNING: ext_group_ldap_0 #Hlpr2 exited2018/12/13 16:07:57 kid1| Too few ext_group_ldap_0 processes are running (need 1/5)2018/12/13 16:07:57 kid1| Closing HTTP port 192.168.XXX.YYY:31282018/12/13 16:07:57 kid1| storeDirWriteCleanLogs: Starting...2018/12/13 16:07:57 kid1| Finished. Wrote 0 entries.2018/12/13 16:07:57 kid1| Took 0.00 seconds ( 0.00 entries/sec).FATAL: The ext_group_ldap_0 helpers are crashing too rapidly, need help!Squid Cache (Version 3.5.28): Terminated abnormally.CPU Usage: 0.268 seconds = 0.208 user + 0.060 sysMaximum Resident Size: 115200 KBPage faults with physical i/o: 72018/12/13 16:07:57 kid1| Closing Pinger socket on FD 232018/12/13 16:08:00 kid1| Set Current Directory to /var/squid/cache2018/12/13 16:08:00 kid1| Starting Squid Cache version 3.5.28 for amd64-portbld-freebsd11.1...The text was updated successfully, but these errors were encountered: