我在尝试启动集成了 NTLM/AD 身份验证设置的 Squid 时遇到错误,我需要一些建议。
这是背景故事:
在服务器的设置、安装和配置方面,我已经逐字遵循了本指南。到目前为止,一切都很顺利,我觉得离让这个系统运行只有几分钟的路程。
我能做
Wbinfo -a administrator
kinit Administrator
klist
每个命令都会确认它成功运行并按预期工作。
Linux 机器已成功加入我的域,我可以对用户和组进行 AD 查找。
但是,当我尝试启动 squid 服务时,我从 CLI 得到以下信息。
[root@squid ~]# service squid start
Starting squid: . [ OK ]
但随后从我的浏览器收到连接错误,说代理拒绝连接,在 /var/log/squid/cache.log 中对 squid 的进一步调查显示以下错误。
2013/07/31 09:57:30| StatefulHandleRead: no callback data registered
2013/07/31 09:57:30| helperHandleRead: unexpected read from basicauthenticator #2, 28 bytes 'NT_STATUS_OK: Success (0x0)
'
2013/07/31 09:57:30| helperHandleRead: unexpected read from basicauthenticator #3, 28 bytes 'NT_STATUS_OK: Success (0x0)
'
2013/07/31 09:57:30| helperHandleRead: unexpected read from basicauthenticator #4, 28 bytes 'NT_STATUS_OK: Success (0x0)
'
2013/07/31 09:57:30| helperHandleRead: unexpected read from basicauthenticator #5, 28 bytes 'NT_STATUS_OK: Success (0x0)
'
2013/07/31 09:57:30| WARNING: ntlmauthenticator #3 (FD 13) exited
2013/07/31 09:57:30| WARNING: ntlmauthenticator #1 (FD 9) exited
2013/07/31 09:57:30| WARNING: ntlmauthenticator #2 (FD 11) exited
2013/07/31 09:57:30| Too few ntlmauthenticator processes are running
2013/07/31 09:57:30| storeDirWriteCleanLogs: Starting...
2013/07/31 09:57:30| Finished. Wrote 0 entries.
2013/07/31 09:57:30| Took 0.00 seconds ( 0.00 entries/sec).
FATAL: The ntlmauthenticator helpers are crashing too rapidly, need help!
Squid Cache (Version 3.1.10): Terminated abnormally.
CPU Usage: 0.143 seconds = 0.038 user + 0.105 sys
Maximum Resident Size: 35040 KB
Page faults with physical i/o: 0
Memory usage for squid via mallinfo():
total space in arena: 2788 KB
Ordinary blocks: 2757 KB 13 blks
Small blocks: 0 KB 0 blks
Holding blocks: 1012 KB 4 blks
Free Small blocks: 0 KB
Free Ordinary blocks: 30 KB
Total in use: 3769 KB 135%
Total free: 30 KB 1%
这是 squid 配置文件的捕获。
auth_param ntlm program /usr/bin/ntlm_auth -–helper-protocol=squid-2.5-ntlm --username=admin --password=password
auth_param ntlm children 10
auth_param basic program /usr/bin/ntlm_auth -–helper-protocol=squid-2.5-basic --username=admin --password=password
auth_param basic children 5
auth_param basic realm Domain Proxy Server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
authenticate_cache_garbage_interval 10 seconds
##
# Credentials past their TTL are removed from memory
authenticate_ttl 0 seconds
为什么要指定
--username
and--password
参数ntlm_auth
?这些参数不是必需的,并且可能会导致ntlm_auth
进程终止(这很可能是您失败的根本原因)。