Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.

Bug 1058107

Summary: regression - squid rpm no longer includes ldap group support
Product: [Fedora] Fedora Reporter: G Crowe <gcrhbug>
Component: squidAssignee: Michal Luscon <mluscon>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 19CC: henrik, jonathansteffan, mluscon, psimerda, thozza
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: squid-3.2.13-2.fc19 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-02-22 00:54:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Description G Crowe 2014-01-27 03:07:36 UTC
Description of problem:
The squid RPM does not include a method for authentication based on LDAP groups. This is "ext_ldap_group_acl"

Older version of squid used the file "squid_ldap_group". This used to be included in the Fedora squid rpm (note - I am updating from Fedora 14 - it was included in squid-3.1.16-1.fc14.i686)

Version-Release number of selected component (if applicable):
squid-3.2.9-1.fc19.x86_64

How reproducible:
100% - the file is not in the package.

Steps to Reproduce:
1. The squid package does not include ext_ldap_group_acl

Actual results:
No method to verify squid groups

Expected results:
A binary executable that can be used to verify squid groups - "ext_ldap_group_acl" (previous version used "squid_ldap_group")

Additional info:

I have managed to obtain the file by doing the following...
- download source code for squid 3.2.9
- yum install openldap-devel
- ./configure --enable-external-acl-helpers=LDAP_group
- make all
- cp helpers/external_acl/LDAP_group/ext_ldap_group_acl /usr/lib64/squid/
- cp helpers/external_acl/LDAP_group/ext_ldap_group_acl.8 /usr/share/man/man8
- cd /usr/share/man/man8
- gzip ext_ldap_group_acl.8

Comment 1 Fedora Update System 2014-02-07 23:18:30 UTC
squid-3.2.13-2.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/squid-3.2.13-2.fc19

Comment 2 Fedora Update System 2014-02-09 03:53:43 UTC
Package squid-3.2.13-2.fc19:
* should fix your issue,
* was pushed to the Fedora 19 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing squid-3.2.13-2.fc19'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2014-2205/squid-3.2.13-2.fc19
then log in and leave karma (feedback).

Comment 3 Fedora Update System 2014-02-22 00:54:06 UTC
squid-3.2.13-2.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.