quinta-feira, 30 de abril de 2009

Squid : using LDAP groups to validate users access

Simple guide to show how one can use LDAP groups to set some acl's on Squid proxy.

All you'll have to do is edit the squid.conf file and add these entries:

external_acl_type ldapgroup %LOGIN /usr/lib/squid/squid_ldap_group -b "ou=Groups,dc=example,dc=local" -f "(&(cn=%g)(memberUid=%u))" -h ldap_server

Create a new external acl which validates if a user belongs to a ldap group

acl ldapgroup-domainallowed external ldapgroup google_allowed

This acl will validate if the user belongs to the group google_allowed. Notice that one could set multiple acl like this one, but to check other ldap groups.

acl domain_allow dstdomain google.com

Example of an acl which checks the domain destination

http_access deny domain_allow !ldapgroup-domainallowed

With this you'll only allow access to google to users which belong to group google_allowed

segunda-feira, 27 de abril de 2009

Windows Vista - Error 0x80072f8f

A few days ago a friend asked me to find out why IE was not loading gmail web page (IE could not found this page!). My first thought was:
"I'm almost sure it is being blocked either by IE filter or some kind of anti-virus program".
Unfortunately it was not the problem, although quite simple to solve, to discover the cause was not so simple.
Since with Firefox I had no problem accessing it, I assumed it had to be related with some IE configuration...
After some search i found that it had to do with the system date. Not only did it affected web pages that required certificates but also some other windows features like, windows defender update and date synchronize. It took me a while to figure it out since the problem was with the month, not the hour or the year, and it took me 3 checks before I noticed that ^_^

Perfect World - Don't Mess with a Venomancer

Hi,
For those who don't know, Perfect World is a free to download and play MMORPG, which, by the way, is quite good. It's a new approach to the video game market, and one that has been quite successful.

This video shows why you shouldn't mess with Venomancers: