<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="fr">
	<id>https://wiki.blaxeen.com/index.php?action=history&amp;feed=atom&amp;title=Proxy_squid_sous_windows</id>
	<title>Proxy squid sous windows - Historique des versions</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.blaxeen.com/index.php?action=history&amp;feed=atom&amp;title=Proxy_squid_sous_windows"/>
	<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;action=history"/>
	<updated>2026-04-18T13:34:31Z</updated>
	<subtitle>Historique des révisions pour cette page sur le wiki</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4414&amp;oldid=prev</id>
		<title>127.0.0.1 : /* Finalisation - Instalation de Squid et des autres */</title>
		<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4414&amp;oldid=prev"/>
		<updated>2021-07-13T10:46:04Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Finalisation - Instalation de Squid et des autres&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;fr&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Version précédente&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version du 13 juillet 2021 à 10:46&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l100&quot;&gt;Ligne 100 :&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Ligne 100 :&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cd /root/install &amp;amp;&amp;amp; rpm2cpio ./squid-helpers-4.1-5.el7.centos.x86_64.rpm | cpio -idmv &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;   &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cd /root/install &amp;amp;&amp;amp; rpm2cpio ./squid-helpers-4.1-5.el7.centos.x86_64.rpm | cpio -idmv &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;  &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cp /root/install/usr/lib64/squid/negotiate_wrapper_auth /usr/lib64/squid/&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cp /root/install/usr/lib64/squid/negotiate_wrapper_auth /usr/lib64/squid/&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Une dépendance a changé de nom, il faut créer un lien symbolique.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Une dépendance a changé de nom, il faut créer un lien symbolique.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l316&quot;&gt;Ligne 316 :&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Ligne 318 :&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;(Le compte est renseigné dans la fiche AO de srv78dc01.csn-interne.fr )&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;(Le compte est renseigné dans la fiche AO de srv78dc01.csn-interne.fr )&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Les services qui doivent tourner et leurs roles =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Les services qui doivent tourner et leurs roles =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>127.0.0.1</name></author>
	</entry>
	<entry>
		<id>https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4413&amp;oldid=prev</id>
		<title>127.0.0.1 : /* Création et opérations sur le &quot;.keytab&quot;. */</title>
		<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4413&amp;oldid=prev"/>
		<updated>2021-07-13T10:45:37Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Création et opérations sur le &amp;quot;.keytab&amp;quot;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;fr&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Version précédente&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version du 13 juillet 2021 à 10:45&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l8&quot;&gt;Ligne 8 :&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Ligne 8 :&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Sur  &amp;#039;&amp;#039;&amp;#039;srv78dc01.csn-interne.fr&amp;#039;&amp;#039;&amp;#039; :&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Sur  &amp;#039;&amp;#039;&amp;#039;srv78dc01.csn-interne.fr&amp;#039;&amp;#039;&amp;#039; :&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;cmd&amp;#039;&amp;#039; ou &amp;#039;&amp;#039;powershellcmd&amp;#039;&amp;#039; ( en admin du comaine ) =&amp;gt; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;cd &amp;lt;le répertoire souhaité&amp;gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}}&lt;/del&gt;, puis&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;cmd&amp;#039;&amp;#039; ou &amp;#039;&amp;#039;powershellcmd&amp;#039;&amp;#039; ( en admin du comaine ) =&amp;gt; cd &amp;lt;le répertoire souhaité&amp;gt;, puis&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;ktpass -out srv78squid01b.csn-interne.fr.keytab -mapUser squid@CSN-INTERNE.FR +rndPass -mapOp set +DumpSalt -crypto ALL -ptype KRB5_NT_PRINCIPAL -princ HTTP/srv78squid01b.csn-interne.fr@CSN-INTERNE.FR&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;ktpass -out srv78squid01b.csn-interne.fr.keytab -mapUser squid@CSN-INTERNE.FR +rndPass -mapOp set +DumpSalt -crypto ALL -ptype KRB5_NT_PRINCIPAL -princ HTTP/srv78squid01b.csn-interne.fr@CSN-INTERNE.FR&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>127.0.0.1</name></author>
	</entry>
	<entry>
		<id>https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4412&amp;oldid=prev</id>
		<title>127.0.0.1 le 13 juillet 2021 à 10:45</title>
		<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4412&amp;oldid=prev"/>
		<updated>2021-07-13T10:45:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;amp;diff=4412&amp;amp;oldid=4411&quot;&gt;Voir les modifications&lt;/a&gt;</summary>
		<author><name>127.0.0.1</name></author>
	</entry>
	<entry>
		<id>https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4411&amp;oldid=prev</id>
		<title>127.0.0.1 le 13 juillet 2021 à 10:41</title>
		<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4411&amp;oldid=prev"/>
		<updated>2021-07-13T10:41:24Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;fr&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Version précédente&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version du 13 juillet 2021 à 10:41&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l2&quot;&gt;Ligne 2 :&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Ligne 2 :&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;= Pre requis =&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{{yum install sssd-tools realmd squid samba-common.noarch samba-common-tools samba-winbind samba-winbind-clients krb5-workstation sssd-ad sssd sssd-common sssd-client sssd-krb5-common sssd-krb5}}}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{{yum install sssd-tools realmd squid samba-common.noarch samba-common-tools samba-winbind samba-winbind-clients krb5-workstation sssd-ad sssd sssd-common sssd-client sssd-krb5-common sssd-krb5}}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>127.0.0.1</name></author>
	</entry>
	<entry>
		<id>https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4410&amp;oldid=prev</id>
		<title>127.0.0.1 : Page créée avec « Le but de cette configuration est qu&#039;un user connecté à un windows dans un domaine puisse utiliser le proxy d une machine linux en s&#039;authentifiant automatiquement avec s... »</title>
		<link rel="alternate" type="text/html" href="https://wiki.blaxeen.com/index.php?title=Proxy_squid_sous_windows&amp;diff=4410&amp;oldid=prev"/>
		<updated>2021-07-13T10:41:00Z</updated>

		<summary type="html">&lt;p&gt;Page créée avec « Le but de cette configuration est qu&amp;#039;un user connecté à un windows dans un domaine puisse utiliser le proxy d une machine linux en s&amp;#039;authentifiant automatiquement avec s... »&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nouvelle page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Le but de cette configuration est qu&amp;#039;un user connecté à un windows dans un domaine puisse utiliser le proxy d une machine linux en s&amp;#039;authentifiant automatiquement avec son compte windows AD &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{{yum install sssd-tools realmd squid samba-common.noarch samba-common-tools samba-winbind samba-winbind-clients krb5-workstation sssd-ad sssd sssd-common sssd-client sssd-krb5-common sssd-krb5}}}&lt;br /&gt;
&lt;br /&gt;
= Création et opérations sur le &amp;quot;.keytab&amp;quot;. =&lt;br /&gt;
Sur  &amp;#039;&amp;#039;&amp;#039;srv78dc01.csn-interne.fr&amp;#039;&amp;#039;&amp;#039; :&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;cmd&amp;#039;&amp;#039; ou &amp;#039;&amp;#039;powershellcmd&amp;#039;&amp;#039; ( en admin du comaine ) =&amp;gt; {{{cd &amp;lt;le répertoire souhaité&amp;gt;}}}, puis&lt;br /&gt;
&lt;br /&gt;
{{{ktpass -out srv78squid01b.csn-interne.fr.keytab -mapUser squid@CSN-INTERNE.FR +rndPass -mapOp set +DumpSalt -crypto ALL -ptype KRB5_NT_PRINCIPAL -princ HTTP/srv78squid01b.csn-interne.fr@CSN-INTERNE.FR}}}&lt;br /&gt;
&lt;br /&gt;
ensuite,  rapatrier le &amp;#039;&amp;#039;&amp;#039;srv78squid01b.csn-interne.fr.keytab&amp;#039;&amp;#039;&amp;#039; sur le serveur &amp;#039;&amp;#039;&amp;#039;srv78squid01b.csn-interne.fr&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Ma technique perso pour les nouveaux arrivants: copier/coller sur votre desktop du rdsh puis via putty click droit &amp;quot;upload to CWD&amp;quot; pour ramener le fichier sur le serveur&amp;#039;&amp;#039; ) et le mettre dans le dossier &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;/etc/squid/&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; .&lt;br /&gt;
&lt;br /&gt;
Puis on duplique ensuite les entrées du keytab dans la keytab par default de krb5 et reciproquement. ( mieux pour quand faut debug )&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
ktutil  &lt;br /&gt;
read_kt /etc/krb5.keytab &lt;br /&gt;
read_kt /etc/squid/srv78squid01b.csn-interne.fr.keytab &lt;br /&gt;
write_kt /etc/krb5.keytab &lt;br /&gt;
write_kt /etc/squid/srv78squid01b.csn-interne.fr.keytab&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
= Fichiers system non standards Agarik =&lt;br /&gt;
/!\ Les modifications sont indispensables sinon ça marche pas. /!\&lt;br /&gt;
&lt;br /&gt;
== /etc/hosts ==&lt;br /&gt;
{{{&lt;br /&gt;
127.0.0.1   localhost localhost.localdomain srv78squid01b.csn-interne.fr srv78squid01  &lt;br /&gt;
::1         localhost6 localhost6.localdomain6 &lt;br /&gt;
# BEGIN ANSIBLE MANAGED BLOCK &lt;br /&gt;
192.168.26.15       ntp1.agarik.com &lt;br /&gt;
172.26.0.15       ntp2.agarik.com &lt;br /&gt;
# END ANSIBLE MANAGED BLOCK &lt;br /&gt;
10.252.42.27      supervision.agarik.com &lt;br /&gt;
# Necessaire a squid &lt;br /&gt;
172.30.102.33   svr78dc01.csn-interne.fr &lt;br /&gt;
svr78dc01 10.1.2.1        svr75dc01.csn-interne.fr }}}&lt;br /&gt;
&lt;br /&gt;
== /etc/resolv.conf ==&lt;br /&gt;
{{{&lt;br /&gt;
# Generated by NetworkManager&lt;br /&gt;
  search csn-interne.fr&lt;br /&gt;
 nameserver 172.30.102.33&lt;br /&gt;
 nameserver 10.1.2.1 }}}&lt;br /&gt;
&lt;br /&gt;
== /etc/chrony.conf ==&lt;br /&gt;
{{{# Use public servers from the pool.ntp.org project.&lt;br /&gt;
# Please consider joining the pool (http://www.pool.ntp.org/join.html).&lt;br /&gt;
#pool 2.rhel.pool.ntp.org iburst&lt;br /&gt;
&lt;br /&gt;
# Record the rate at which the system clock gains/losses time.&lt;br /&gt;
driftfile /var/lib/chrony/drift&lt;br /&gt;
&lt;br /&gt;
# Allow the system clock to be stepped in the first three updates&lt;br /&gt;
# if its offset is larger than 1 second.&lt;br /&gt;
makestep 1.0 3&lt;br /&gt;
&lt;br /&gt;
# Enable kernel synchronization of the real-time clock (RTC).&lt;br /&gt;
rtcsync&lt;br /&gt;
&lt;br /&gt;
# Enable hardware timestamping on all interfaces that support it.&lt;br /&gt;
#hwtimestamp *&lt;br /&gt;
&lt;br /&gt;
# Increase the minimum number of selectable sources required to adjust&lt;br /&gt;
# the system clock.&lt;br /&gt;
#minsources 2&lt;br /&gt;
&lt;br /&gt;
# Allow NTP client access from local network.&lt;br /&gt;
#allow 192.168.0.0/16&lt;br /&gt;
&lt;br /&gt;
# Serve time even if not synchronized to a time source.&lt;br /&gt;
#local stratum 10&lt;br /&gt;
&lt;br /&gt;
# Specify file containing keys for NTP authentication.&lt;br /&gt;
keyfile /etc/chrony.keys&lt;br /&gt;
&lt;br /&gt;
# Get TAI-UTC offset and leap seconds from the system tz database.&lt;br /&gt;
leapsectz right/UTC&lt;br /&gt;
&lt;br /&gt;
# Specify directory for log files.&lt;br /&gt;
logdir /var/log/chrony&lt;br /&gt;
&lt;br /&gt;
# Select which information is logged.&lt;br /&gt;
#log measurements statistics tracking&lt;br /&gt;
# BEGIN ANSIBLE MANAGED BLOCK&lt;br /&gt;
pool svr78dc01.csn-interne.fr iburst&lt;br /&gt;
# END ANSIBLE MANAGED BLOCK&lt;br /&gt;
&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
= Finalisation - Instalation de Squid et des autres =&lt;br /&gt;
Récupérer ( mais /!\ Ne pas l&amp;#039;installer, mais on a juste besoin d&amp;#039;un fichier dedans /!\  ) sur le net rpm squid-helpers-4.1-5.el7.centos.x86_64.rpm et le placer dans le repertoire /root/install&lt;br /&gt;
&lt;br /&gt;
Extraire les fichiers du rpm puis récupérer celui qu&amp;#039;il nous faut&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
cd /root/install &amp;amp;&amp;amp; rpm2cpio ./squid-helpers-4.1-5.el7.centos.x86_64.rpm | cpio -idmv    &lt;br /&gt;
cp /root/install/usr/lib64/squid/negotiate_wrapper_auth /usr/lib64/squid/ }}}&lt;br /&gt;
Une dépendance a changé de nom, il faut créer un lien symbolique.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
 ln -s /usr/lib64/libnsl.so.2 /lib64/libnsl.so.1 }}}&lt;br /&gt;
&lt;br /&gt;
== /etc/squid/squid.conf ==&lt;br /&gt;
{{{&lt;br /&gt;
#&lt;br /&gt;
# Recommended minimum configuration:&lt;br /&gt;
#&lt;br /&gt;
#Authentification automatique via Kerberos&lt;br /&gt;
&lt;br /&gt;
auth_param negotiate program /usr/bin/sg wbpriv -c &amp;quot;/usr/lib64/squid/negotiate_wrapper_auth --ntlm /usr/bin/ntlm_auth -i --diagnostics --helper-protocol=squid-2.5-ntlmssp --domain=CSN-INTERNE.FR --kerberos /usr/lib64/squid/negotiate_kerberos_auth -d -k /etc/squid/srv78squid01b.csn-interne.fr.keytab -s HTTP/srv78squid01b.csn-interne.fr@CSN-INTERNE.FR&amp;quot;&lt;br /&gt;
auth_param negotiate children 20 startup=20&lt;br /&gt;
auth_param negotiate keep_alive off&lt;br /&gt;
&lt;br /&gt;
# Authentification LDAP pour ceux qui ne sont pas en Kerberos&lt;br /&gt;
auth_param basic program /usr/lib64/squid/basic_ldap_auth -R -b &amp;quot;dc=csn-interne,dc=fr&amp;quot; -D &amp;quot;cn=squidLDAP,ou=Applicatif,ou=Utilisateurs - Service,ou=CSNStandard,dc=csn-interne,dc=fr&amp;quot; -W /etc/squid/ldap_passwd.txt -f &amp;quot;sAMAccountName=%s&amp;quot; -h svr78dc01.csn-interne.fr -v 3&lt;br /&gt;
&lt;br /&gt;
acl authenticated_user proxy_auth REQUIRED&lt;br /&gt;
&lt;br /&gt;
http_access deny !authenticated_user&lt;br /&gt;
&lt;br /&gt;
logformat timereadable %tl %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt&lt;br /&gt;
access_log daemon:/var/log/squid/access.log timereadable&lt;br /&gt;
# Example rule allowing access from your local networks.&lt;br /&gt;
# Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
# should be allowed&lt;br /&gt;
acl localnet src 0.0.0.1-0.255.255.255  # RFC 1122 &amp;quot;this&amp;quot; network (LAN)&lt;br /&gt;
acl localnet src 10.0.0.0/8             # RFC 1918 local private network (LAN)&lt;br /&gt;
acl localnet src 100.64.0.0/10          # RFC 6598 shared address space (CGN)&lt;br /&gt;
acl localnet src 169.254.0.0/16         # RFC 3927 link-local (directly plugged) machines&lt;br /&gt;
acl localnet src 172.16.0.0/12          # RFC 1918 local private network (LAN)&lt;br /&gt;
acl localnet src 192.168.0.0/16         # RFC 1918 local private network (LAN)&lt;br /&gt;
acl localnet src fc00::/7               # RFC 4193 local private network range&lt;br /&gt;
acl localnet src fe80::/10              # RFC 4291 link-local (directly plugged) machines&lt;br /&gt;
&lt;br /&gt;
acl SSL_ports port 443&lt;br /&gt;
acl Safe_ports port 80          # http&lt;br /&gt;
acl Safe_ports port 21          # ftp&lt;br /&gt;
acl Safe_ports port 443         # https&lt;br /&gt;
acl Safe_ports port 70          # gopher&lt;br /&gt;
acl Safe_ports port 210         # wais&lt;br /&gt;
acl Safe_ports port 1025-65535  # unregistered ports&lt;br /&gt;
acl Safe_ports port 280         # http-mgmt&lt;br /&gt;
acl Safe_ports port 488         # gss-http&lt;br /&gt;
acl Safe_ports port 591         # filemaker&lt;br /&gt;
acl Safe_ports port 777         # multiling http&lt;br /&gt;
acl CONNECT method CONNECT&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
# Recommended minimum Access Permission configuration:&lt;br /&gt;
#&lt;br /&gt;
# Deny requests to certain unsafe ports&lt;br /&gt;
http_access deny !Safe_ports&lt;br /&gt;
&lt;br /&gt;
# Deny CONNECT to other than secure SSL ports&lt;br /&gt;
http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
# Only allow cachemgr access from localhost&lt;br /&gt;
http_access allow localhost manager&lt;br /&gt;
http_access deny manager&lt;br /&gt;
&lt;br /&gt;
# We strongly recommend the following be uncommented to protect innocent&lt;br /&gt;
# web applications running on the proxy server who think the only&lt;br /&gt;
# one who can access services on &amp;quot;localhost&amp;quot; is a local user&lt;br /&gt;
#http_access deny to_localhost&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
# Example rule allowing access from your local networks.&lt;br /&gt;
# Adapt localnet in the ACL section to list your (internal) IP networks&lt;br /&gt;
# from where browsing should be allowed&lt;br /&gt;
http_access allow localnet&lt;br /&gt;
http_access allow localhost&lt;br /&gt;
&lt;br /&gt;
# And finally deny all other access to this proxy&lt;br /&gt;
http_access deny all&lt;br /&gt;
&lt;br /&gt;
# Squid normally listens to port 3128&lt;br /&gt;
http_port 3128&lt;br /&gt;
&lt;br /&gt;
# Uncomment and adjust the following to add a disk cache directory.&lt;br /&gt;
#cache_dir ufs /var/spool/squid 100 16 256&lt;br /&gt;
&lt;br /&gt;
# Leave coredumps in the first cache dir&lt;br /&gt;
coredump_dir /var/spool/squid&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
# Add any of your own refresh_pattern entries above these.&lt;br /&gt;
#&lt;br /&gt;
refresh_pattern ^ftp:           1440    20%     10080&lt;br /&gt;
refresh_pattern ^gopher:        1440    0%      1440&lt;br /&gt;
refresh_pattern -i (/cgi-bin/|\?) 0     0%      0&lt;br /&gt;
refresh_pattern .               0       20%     4320&lt;br /&gt;
&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== /etc/krb5.conf ==&lt;br /&gt;
{{{[logging]&lt;br /&gt;
        Default = FILE:/var/log/krb5.log&lt;br /&gt;
[libdefaults]&lt;br /&gt;
        default_realm = CSN-INTERNE.FR&lt;br /&gt;
        clock_skew = 300&lt;br /&gt;
        ticket_lifetime = 24000&lt;br /&gt;
        default_tkt_enctypes = arcfour-hmac&lt;br /&gt;
        permitted_enctypes   = des-cbc-crc des-cbc-md5 arcfour-hmac aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac arcfour-hmac-md5&lt;br /&gt;
        rdns = false&lt;br /&gt;
        udp_preference_limit = 0&lt;br /&gt;
        dns_lookup_realm = true&lt;br /&gt;
        dns_lookup_kdc = true&lt;br /&gt;
        forwardable = yes&lt;br /&gt;
[realms]&lt;br /&gt;
        CSN-INTERNE.FR = {&lt;br /&gt;
                kdc = svr78dc01.csn-interne.fr&lt;br /&gt;
                admin_server = svr78dc01.csn-interne.fr&lt;br /&gt;
                default_domain = CSN-INTERNE.FR&lt;br /&gt;
                }&lt;br /&gt;
[domain_realm]&lt;br /&gt;
        .csn-interne.fr = CSN-INTERNE.FR&lt;br /&gt;
        csn-interne.fr = CSN-INTERNE.FR&lt;br /&gt;
&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== /etc/samba/smb.conf ==&lt;br /&gt;
&lt;br /&gt;
{{{# See smb.conf.example for a more detailed config file or&lt;br /&gt;
# read the smb.conf manpage.&lt;br /&gt;
# Run &amp;#039;testparm&amp;#039; to verify the config is correct after&lt;br /&gt;
# you modified it.&lt;br /&gt;
&lt;br /&gt;
[global]&lt;br /&gt;
   workgroup = CSN-INTERNE&lt;br /&gt;
   client signing = yes&lt;br /&gt;
   client use spnego = yes&lt;br /&gt;
   kerberos method = secrets and keytab&lt;br /&gt;
   log file = /var/log/samba/%m.log&lt;br /&gt;
   password server = SRV78DC01.CSN-INTERNE.FR&lt;br /&gt;
   realm = CSN-INTERNE.FR&lt;br /&gt;
   security = ads&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== /usr/lib/realmd/realmd-defaults.conf ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{{# Default values for realmd&lt;br /&gt;
[service]&lt;br /&gt;
debug = no&lt;br /&gt;
automatic-install = yes&lt;br /&gt;
&lt;br /&gt;
[paths]&lt;br /&gt;
net = /usr/bin/net&lt;br /&gt;
winbindd = /usr/sbin/winbindd&lt;br /&gt;
smb.conf = /etc/samba/smb.conf&lt;br /&gt;
sssd.conf = /etc/sssd/sssd.conf&lt;br /&gt;
adcli = /usr/sbin/adcli&lt;br /&gt;
ipa-client-install = /usr/sbin/ipa-client-install&lt;br /&gt;
pam_winbind.conf = /etc/security/pam_winbind.conf&lt;br /&gt;
krb5.conf = /etc/krb5.conf&lt;br /&gt;
&lt;br /&gt;
[active-directory]&lt;br /&gt;
default-client = sssd&lt;br /&gt;
os-name =&lt;br /&gt;
os-version =&lt;br /&gt;
&lt;br /&gt;
[providers]&lt;br /&gt;
sssd = yes&lt;br /&gt;
samba = yes&lt;br /&gt;
example = no&lt;br /&gt;
&lt;br /&gt;
[samba-packages]&lt;br /&gt;
&lt;br /&gt;
[winbind-packages]&lt;br /&gt;
&lt;br /&gt;
[sssd-packages]&lt;br /&gt;
&lt;br /&gt;
[adcli-packages]&lt;br /&gt;
&lt;br /&gt;
[commands]&lt;br /&gt;
&lt;br /&gt;
[users]&lt;br /&gt;
default-shell = /bin/bash&lt;br /&gt;
default-home = /home/%U@%D&lt;br /&gt;
&lt;br /&gt;
[example.com]&lt;br /&gt;
example-administrator = Administrator&lt;br /&gt;
example-password = bureaucracy&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== /etc/sssd/sssd.conf ==&lt;br /&gt;
&lt;br /&gt;
{{{[sssd]&lt;br /&gt;
domains = csn-interne.fr&lt;br /&gt;
config_file_version = 2&lt;br /&gt;
services = nss, pam&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[domain/csn-interne.fr]&lt;br /&gt;
id_provider = ad&lt;br /&gt;
ad_domain = csn-interne.fr&lt;br /&gt;
realmd_tags = manages-system joined-with-samba&lt;br /&gt;
cache_credentials = True&lt;br /&gt;
ldap_id_mapping = True&lt;br /&gt;
auth_provider = krb5&lt;br /&gt;
krb5_server = svr78dc01.csn-interne.fr&lt;br /&gt;
krb5_realm = CSN-INTERNE.FR&lt;br /&gt;
krb5_store_password_if_offline = True&lt;br /&gt;
access_provider = simple&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Apres faut joindre la machine au domaine.&lt;br /&gt;
&lt;br /&gt;
{{{ net ads join -U admin-agarik }}}&lt;br /&gt;
&lt;br /&gt;
(Le compte est renseigné dans la fiche AO de srv78dc01.csn-interne.fr )&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Les services qui doivent tourner et leurs roles =&lt;br /&gt;
&lt;br /&gt;
 - squid =&amp;gt; le service de proxy. &lt;br /&gt;
{{{ systemctl enable squid.service }}}&lt;br /&gt;
&lt;br /&gt;
 - sssd/realmd/winbind =&amp;gt; sssd est le service qui fait le mapping pour squid aupres de l&amp;#039;AD ( il l&amp;#039;interroge en LDAP/AD grace au compte de service à la keytab indiqué dans la conf de squid pour connaitre la correspondance &amp;quot;Ticket kerberos&amp;quot; &amp;lt;=&amp;gt; &amp;quot;Nom d&amp;#039;utilisateur&amp;quot;. Pour faire ça il utilise comme outil kerberos client et le service winbind pour interroger l&amp;#039;AD. Le service Winbind utilise la configuration de realmd ( samba ) pour trouver le nom de domaine , le DC, etc ....&lt;br /&gt;
{{{ systemctl enable sssd.service }}}&lt;br /&gt;
{{{ systemctl enable realmd.service }}}&lt;br /&gt;
{{{ systemctl enable winbind.service }}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Ajout de SquidGuard ( + mise en place d&amp;#039;un page de redirection pour les sites bloqués en http ) =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{{ yum install squidGuard httpd }}}&lt;br /&gt;
{{{ cd /var/squidGuard/ &amp;amp;&amp;amp; tar -xzvf blacklists.tar.gz }}}&lt;br /&gt;
&lt;br /&gt;
 - fichier /etc/squid/squidGuard.conf&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
#&lt;br /&gt;
# CONFIG FILE FOR SQUIDGUARD&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
dbhome /var/squidGuard&lt;br /&gt;
logdir /var/log/squidGuard&lt;br /&gt;
&lt;br /&gt;
dest adult {&lt;br /&gt;
        domainlist      blacklists/porn/domains&lt;br /&gt;
        urllist         blacklists/porn/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
dest drugs {&lt;br /&gt;
        domainlist      blacklists/drugs/domains&lt;br /&gt;
        urllist         blacklists/drugs/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
dest warez {&lt;br /&gt;
        domainlist      blacklists/warez/domains&lt;br /&gt;
        urllist         blacklists/warez/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
dest spyware {&lt;br /&gt;
        domainlist      blacklists/spyware/domains&lt;br /&gt;
        urllist         blacklists/spyware/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
dest suspect {&lt;br /&gt;
        domainlist      blacklists/suspect/domains&lt;br /&gt;
        urllist         blacklists/suspect/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
dest hacking {&lt;br /&gt;
        domainlist      blacklists/hacking/domains&lt;br /&gt;
        urllist         blacklists/hacking/urls&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
acl {&lt;br /&gt;
&lt;br /&gt;
        default {&lt;br /&gt;
                pass     !adult !drugs !warez !spyware !suspect !hacking any&lt;br /&gt;
                redirect  http://172.30.104.195/access-denied.html?site=%u&lt;br /&gt;
        }&lt;br /&gt;
}&lt;br /&gt;
}}}  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Catégorie:windows]]&lt;/div&gt;</summary>
		<author><name>127.0.0.1</name></author>
	</entry>
</feed>