<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://forum.ubuntu-fr.org/extern.php?action=feed&amp;tid=1127131&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Forum Ubuntu-fr.org / Squid3 (AD/NTLM) - performances médiocre (TCP_MISS, TCP_DENIED)]]></title>
		<link>http://forum.ubuntu-fr.org/viewtopic.php?id=1127131</link>
		<description><![CDATA[Les sujets les plus récents dans Squid3 (AD/NTLM) - performances médiocre (TCP_MISS, TCP_DENIED).]]></description>
		<lastBuildDate>Tue, 04 Dec 2012 16:27:42 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Squid3 (AD/NTLM) - performances médiocre (TCP_MISS, TCP_DENIED)]]></title>
			<link>http://forum.ubuntu-fr.org/viewtopic.php?pid=11746931#p11746931</link>
			<description><![CDATA[<p>Bonjour,</p><p>Je viens d&#039;installer squid en suivant <a href="http://www.pixxlisation.net/?p=1403">ce tuto</a> et j&#039;ai un comportement étrange de mon proxy.<br />Installé sur une version serveur 12.04<br />l&#039;authentification kerberos semble ok, kinit et klist montrent qu&#039;un ticket est bien validé<br />l&#039;intégration au domain est faite, </p><div class="codebox"><pre><code>sudo net ads testjoin
Join is OK</code></pre></div><p>J&#039;arrive à lister les utilisateurs et groupes du domaine avec wbinfo -u / -g<br />Par contre j&#039;ai un message d&#039;erreur avec wbinfo -t</p><div class="codebox"><pre><code>checking the trust secret for domain MONDOMAIN via RPC calls failed
failed to call wbcCheckTrustCredentials: WBC_ERR_WINBIND_NOT_AVAILABLE
Could not check secret</code></pre></div><p>et un test d&#039;authentification passe en plaintext password mais pas en challenge/response</p><div class="codebox"><pre><code>wbinfo -a testuser
Enter testuser&#039;s password: 
plaintext password authentication succeeded
Enter testuser&#039;s password: 
challenge/response password authentication failed
Could not authenticate user testuser with challenge/response</code></pre></div><p>à l&#039;utilisation, la navigation sur un poste avec IE (ou FF) est lente, mais l&#039;authentification fonctionne, si je suis loggué avec un compte du domaine, je n&#039;ai aucune demande, par contre avec un compte local, j&#039;ai bien une demande d&#039;authentification de la par du proxy.</p><p>J&#039;ai regénéré le dossier de cache avec la commande squid3 -z<br />Le dossier du cache semble se remplir correctement, je ne sais plus ou chercher.</p><div class="codebox"><pre><code>sudo du -sh /var/spool/squid3/*
28M	/var/spool/squid3/00
1,1M	/var/spool/squid3/01
1,1M	/var/spool/squid3/02
1,1M	/var/spool/squid3/03
1,1M	/var/spool/squid3/04
1,1M	/var/spool/squid3/05
1,1M	/var/spool/squid3/06
1,1M	/var/spool/squid3/07
1,1M	/var/spool/squid3/08
1,1M	/var/spool/squid3/09
1,1M	/var/spool/squid3/0A
1,1M	/var/spool/squid3/0B
1,1M	/var/spool/squid3/0C
1,1M	/var/spool/squid3/0D
1,1M	/var/spool/squid3/0E
1,1M	/var/spool/squid3/0F
60K	/var/spool/squid3/swap.state</code></pre></div><p>Et dans le fichier access.log j&#039;ai 99% de TCP_DENIED/407 ou TCP_MISS/200 et très peu de HIT</p><div class="codebox"><pre class="vscroll"><code>1354543654.421     26 10.10.48.138 TCP_MISS/200 507 GET http://www.google-analytics.com/__utm.gif? monuserad DIRECT/173.194.34.32 image/gif
1354543655.493     27 10.10.48.138 TCP_MISS/200 1780 GET http://www.google.com/enterprise/apps/images/common/ui_sprite.png monuserad DIRECT/173.194.34.49 image/png
1354543660.329  11759 10.10.48.138 TCP_MISS/200 8710 GET http://apis.google.com/js/plusone.js monuserad DIRECT/74.125.230.224 application/javascript
1354543660.502      0 10.10.48.138 TCP_DENIED/407 3872 CONNECT apis.google.com:443 - NONE/- text/html
1354543660.541      1 10.10.48.138 TCP_DENIED/407 4100 CONNECT apis.google.com:443 - NONE/- text/html
1354543660.673      0 10.10.48.138 TCP_DENIED/407 3884 CONNECT plusone.google.com:443 - NONE/- text/html
1354543660.693     26 10.10.48.138 TCP_MISS/200 708 GET http://www.google.com/images/icons/product/gplus-16.png monuserad DIRECT/173.194.34.49 image/png
1354543661.491      1 10.10.48.138 TCP_DENIED/407 4112 CONNECT plusone.google.com:443 - NONE/- text/html
1354543661.493     44 10.10.48.138 TCP_MISS/200 615 GET http://www.google.com/images/icons/product/blogger-16.png monuserad DIRECT/173.194.34.49 image/png
1354543661.513      0 10.10.48.138 TCP_DENIED/407 4364 GET http://www.google.com/images/icons/product/youtube-16.png - NONE/- text/html
1354543661.579     45 10.10.48.138 TCP_MISS/200 627 GET http://www.google.com/images/icons/product/youtube-16.png monuserad DIRECT/173.194.34.49 image/png
1354543661.936      0 10.10.48.138 TCP_DENIED/407 4328 GET http://www.google.com/enterprise/apps/js/view.js - NONE/- text/html
1354543661.981      4 10.10.48.138 TCP_DENIED/407 4556 GET http://www.google.com/enterprise/apps/js/view.js - NONE/- text/html
1354543662.074     78 10.10.48.138 TCP_MISS/200 45461 GET http://www.google.com/enterprise/apps/js/view.js monuserad DIRECT/173.194.34.49 text/javascript
1354543662.497   1948 10.10.48.138 TCP_MISS/200 29677 CONNECT apis.google.com:443 monuserad DIRECT/74.125.230.224 -
1354543662.596      0 10.10.48.138 TCP_DENIED/407 3872 CONNECT ssl.gstatic.com:443 - NONE/- text/html
1354543662.776      1 10.10.48.138 TCP_DENIED/407 4100 CONNECT ssl.gstatic.com:443 - NONE/- text/html
1354543663.816      0 10.10.48.138 TCP_DENIED/407 3874 CONNECT login.live.com:443 - NONE/- text/html
1354543663.902     26 10.10.48.138 TCP_MISS/200 483 GET http://www.google.com/images/cleardot.gif monuserad DIRECT/173.194.34.49 image/gif
1354543664.059      1 10.10.48.138 TCP_DENIED/407 4102 CONNECT login.live.com:443 - NONE/- text/html
1354543665.516     35 10.10.48.138 TCP_MISS/200 6096 GET http://www.google.com/intl/fr/enterprise/apps/js/sitemap.min.js monuserad DIRECT/173.194.34.49 text/javascript
1354543667.459      0 10.10.48.138 TCP_DENIED/407 4260 GET http://www.google.com/js/maia.js - NONE/- text/html
1354543667.765      3 10.10.48.138 TCP_DENIED/407 4488 GET http://www.google.com/js/maia.js - NONE/- text/html
1354543667.889     35 10.10.48.138 TCP_MISS/200 2992 GET http://www.google.com/js/maia.js monuserad DIRECT/173.194.34.49 text/javascript
1354543667.962   6429 10.10.48.138 TCP_MISS/200 68967 CONNECT plusone.google.com:443 monuserad DIRECT/173.194.34.37 -
1354543668.180     24 10.10.48.138 TCP_MISS/200 507 GET http://www.google-analytics.com/__utm.gif? monuserad DIRECT/173.194.34.32 image/gif
1354543670.349   6271 10.10.48.138 TCP_MISS/200 16237 CONNECT login.live.com:443 monuserad DIRECT/65.54.186.19 -
1354543671.290  16095 10.10.48.138 TCP_MISS/200 19343 GET http://themes.googleusercontent.com/static/fonts/opensans/v6/cJZKeOuBrn4kERxqtaUH3fY6323mHUZFJMgTvxaG2iE.eot monuserad DIRECT/74.125.230.236 font/eot
1354543678.280  11472 10.10.48.138 TCP_MISS/302 866 GET http://fls.doubleclick.net/activityi;src=2507573;type=enter133;cat=appsh4;ord=7493270981721.024? monuserad DIRECT/74.125.230.252 text/html
1354543683.675   5348 10.10.48.138 TCP_MISS/200 622 GET http://2507573.fls.doubleclick.net/activityi;src=2507573;type=enter133;cat=appsh4;ord=7493270981721.024 monuserad DIRECT/173.194.34.60 text/html
1354543683.847     36 10.10.48.138 TCP_MISS/200 5885 GET http://www.google.com/favicon.ico monuserad DIRECT/173.194.34.49 image/x-icon
1354543713.480  63469 10.10.48.138 TCP_MISS/200 5551 CONNECT home.live.com:443 monuserad DIRECT/65.55.114.223 -
1354543724.741  73800 10.10.48.138 TCP_MISS/200 6424 CONNECT mail.live.com:443 monuserad DIRECT/157.55.0.135 -</code></pre></div><p>Malgré cela, les pages s&#039;affichent, elles arrivent d&#039;un bloc après plusieurs secondes d&#039;attente ! Le gain est pour ainsi dire nul en terme de rapidité de navigation, même sur des sites dont un gros pourcentage de la page n&#039;est pas dynamique.<br />Cela fait plusieurs jours que j&#039;essaie des configurations différentes sans avoir trouvé de solution.</p><p>voici mes fichiers de conf<br />krb5.conf</p><div class="codebox"><pre class="vscroll"><code>[logging]
    default = FILE10000:/var/log/krb5lib.log
 
[libdefaults]
    ticket_lifetime = 24000
    default_realm = MONDOMAIN.MONENTREPRISE.LOCAL
    dns_fallback = no
    dns_lookup_realm = no
    dns_lookup_kdc = true

; for Windows 2003
    default_tgs_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
    default_tkt_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
    permitted_enctypes = rc4-hmac des-cbc-crc des-cbc-md5

; for Windows 2008 with AES
;    default_tgs_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
;    default_tkt_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
;    permitted_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
     
[realms]
    MONDOMAIN.MONENTREPRISE.LOCAL = {
        kdc = dc1.MONDOMAIN.MONENTREPRISE.local:88
        kdc = dc2.MONDOMAIN.MONENTREPRISE.local:88
        admin_server = dc1.MONDOMAIN.MONENTREPRISE.local:789
        default_domain = MONDOMAIN.MONENTREPRISE.LOCAL
	}
 
[domain_realm]
    .MONDOMAIN.MONENTREPRISE.local = MONDOMAIN.MONENTREPRISE.LOCAL
    MONDOMAIN.MONENTREPRISE.local = MONDOMAIN.MONENTREPRISE.LOCAL</code></pre></div><p>smb.conf</p><div class="codebox"><pre><code>[global]
        security = ADS
        realm = MONDOMAIN.MONENTREPRISE.LOCAL
        password server = dc1.mondomain.monentreprise.local
        workgroup = mondomain
        winbind separator = /
        idmap uid = 10000-20000
        idmap gid = 10000-20000
        winbind enum users = yes
        winbind enum groups = yes
        template homedir = /home/%D/%U
        template shell = /bin/bash
        client use spnego = yes
        winbind use default domain = yes
# empeche le client de devenir maitre explorateur
        domain master = no
        local master = no
        preferred master = no
        os level = 0</code></pre></div><p>squid.conf</p><div class="codebox"><pre class="vscroll"><code>###########PRISE EN CHARGE DU LOGIN AD########################################
 
auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 50
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic children 50
auth_param basic realm mondomain.monentreprise.local
auth_param basic credentialsttl 2 hours
 
###########ACCESS LISTE######################################################
 
acl ntlm proxy_auth REQUIRED
acl manager proto cache_object
acl localhost src 127.0.0.1/32 ::1
acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1
acl localnet src 10.10.0.0/16   # RFC1918 possible internal network
acl SSL_ports port 443
acl Safe_ports port 80          # http
acl Safe_ports port 21          # ftp
acl Safe_ports port 443         # https
acl Safe_ports port 70          # gopher
acl Safe_ports port 210         # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280         # http-mgmt
acl Safe_ports port 488         # gss-http
acl Safe_ports port 591         # filemaker
acl Safe_ports port 777         # multiling http
acl CONNECT method CONNECT

acl block_websites dstdomain .facebook.com .youtube.com 
##########LISTE DES ACL AUTORISEE###########################################
http_access deny block_websites

http_access allow ntlm
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localnet
http_access allow localhost
http_access deny all
 
#########PORT D&#039;ECOUTE######################################################
http_port 3128
 
############GESTION DES PARAMETRES DE CACHE#################################
cache_dir ufs /var/spool/squid3 10240 16 256
hierarchy_stoplist cgi-bin ?
coredump_dir /var/spool/squid3
refresh_pattern ^ftp:           1440    20%     10080
refresh_pattern ^gopher:        1440    0%      1440
refresh_pattern -i (/cgi-bin/|\?) 0     0%      0
refresh_pattern (Release|Packages(.gz)*)$      0       20%     2880
refresh_pattern .               0       20%     4320
 
############DOMAINE DE LOGIN PAR DEFAUT#####################################
 
append_domain .mondomain.monentreprise.local
visible_hostname proxy-admin </code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (2fast4u)]]></author>
			<pubDate>Tue, 04 Dec 2012 16:27:42 +0000</pubDate>
			<guid>http://forum.ubuntu-fr.org/viewtopic.php?pid=11746931#p11746931</guid>
		</item>
	</channel>
</rss>
