<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Jan&#039;s blog</title>
	<atom:link href="http://janaps.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://janaps.wordpress.com</link>
	<description>don&#039;t ... too late</description>
	<lastBuildDate>Mon, 05 Dec 2011 13:32:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='janaps.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Jan&#039;s blog</title>
		<link>http://janaps.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://janaps.wordpress.com/osd.xml" title="Jan&#039;s blog" />
	<atom:link rel='hub' href='http://janaps.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Windows 7 SP1 x64 problems</title>
		<link>http://janaps.wordpress.com/2011/12/05/windows-7-sp1-x64-problems/</link>
		<comments>http://janaps.wordpress.com/2011/12/05/windows-7-sp1-x64-problems/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 13:32:31 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=63</guid>
		<description><![CDATA[I had some problems rolling out sp1 on my x64 windows 7. First round of failures was due to a lack of space on the C-drive. A minimum of 8G is required, but some people saved their VM&#8217;s on the C-drive. The second round was only one machine. I got an error like this:ERROR_NOT_FOUND 0×80070490. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=63&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I had some problems rolling out sp1 on my x64 windows 7. First round of failures was due to a lack of space on the C-drive. A minimum of 8G is required, but some people saved their VM&#8217;s on the C-drive.<br />
The second round was only one machine. I got an error like this:ERROR_NOT_FOUND 0×80070490.<br />
I solved it using the steps described in this article</p>
<p>http://beerpla.net/2011/05/06/how-to-fix-error_not_found-0&#215;80070490-during-windows-7-sp1-installation/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/63/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=63&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2011/12/05/windows-7-sp1-x64-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>New project: cheap ass physical to virtual conversion (p2v)</title>
		<link>http://janaps.wordpress.com/2011/11/21/new-project-cheap-ass-physical-to-virtual-conversion-p2v/</link>
		<comments>http://janaps.wordpress.com/2011/11/21/new-project-cheap-ass-physical-to-virtual-conversion-p2v/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 12:57:33 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=61</guid>
		<description><![CDATA[I&#8217;m on the verge of a complete server-upgrade of our network. I want&#8217;t to go virtual (what else&#8230;), but to be on the safe side, I also want to convert my current physical servers to virtual ones. Offcourse I could use ssvm or something else that costs money, but I we have no money. So [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=61&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m on the verge of a complete server-upgrade of our network. I want&#8217;t to go virtual (what else&#8230;), but to be on the safe side, I also want to convert my current physical servers to virtual ones. Offcourse I could use ssvm or something else that costs money, but I we have no money. So lets try it with the little tool from sysinternals Disk2VHD. I&#8217;ll keep you posted.</p>
<p><a href="http://technet.microsoft.com/en-us/sysinternals/ee656415">http://technet.microsoft.com/en-us/sysinternals/ee656415</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=61&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2011/11/21/new-project-cheap-ass-physical-to-virtual-conversion-p2v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Firefox, Flash Player etc deployment</title>
		<link>http://janaps.wordpress.com/2011/05/10/firefox-flash-player-etc-deployment/</link>
		<comments>http://janaps.wordpress.com/2011/05/10/firefox-flash-player-etc-deployment/#comments</comments>
		<pubDate>Tue, 10 May 2011 08:06:42 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=56</guid>
		<description><![CDATA[For some time now I&#8217;m struggling to maintain the most irritating software combination on the planet: Firefox, Internet Explorer plus Flash player, Shockwave player, Reader, some sort of Quicktime and some sort of Real First step: GPO deployment of FF: http://techierambles.blogspot.com/2010/10/deploy-firefox-using-msi-file-and-group.html helped a lot Also http://www.adobe.com/software/flash/about/ to check the flash version and http://www.wardvissers.nl/2008/10/15/flash-player-msi-download/ to download [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=56&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For some time now I&#8217;m struggling to maintain the most irritating software combination on the planet: Firefox, Internet Explorer plus Flash player, Shockwave player, Reader, some sort of Quicktime and some sort of Real</p>
<p>First step: GPO deployment of FF: http://techierambles.blogspot.com/2010/10/deploy-firefox-using-msi-file-and-group.html helped a lot</p>
<p>Also http://www.adobe.com/software/flash/about/ to check the flash version and http://www.wardvissers.nl/2008/10/15/flash-player-msi-download/ to download the most recent flash and shockwave versions</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=56&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2011/05/10/firefox-flash-player-etc-deployment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Squid with active directory SSO: non domain computers</title>
		<link>http://janaps.wordpress.com/2010/06/08/squid-with-active-directory-sso-non-domain-computers/</link>
		<comments>http://janaps.wordpress.com/2010/06/08/squid-with-active-directory-sso-non-domain-computers/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 18:53:06 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[squid]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=54</guid>
		<description><![CDATA[I&#8217;ve been testing the SSO contraption for a few days now, and suprise suprise: I&#8217;ve run in to a problem. If the computer the user is on is a member of the Active Directory domain, everything works smoothly. The problem lies with non-domain computers. As expected Iexplore prompts for a username and password. However the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=54&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been testing the SSO contraption for a few days now, and suprise suprise: I&#8217;ve run in to a problem. If the computer the user is on is a member of the Active Directory domain, everything works smoothly. The problem lies with non-domain computers.</p>
<p>As expected Iexplore prompts for a username and password. However the domain the user is working under is also put in, wich incedently is allso expected behaviour.  So in my cache.log users are trying to log in with WORKGROUP\user.</p>
<p>Great I thought, no problem: I&#8217;ll just tell ntlm_auth to discard the domain the user gives us and subtitute it with our Active directory domain. This does&#8217;nt seem to be possible. The problem now is that I never instructed my users to use the DOMAIN\user form, let alone user@domain.com for login. I&#8217;m gessing that the majority of the users doesn&#8217;t even know how to type the backslash (we use azerty keyboards).</p>
<p>So the solution maybe to write a custom script that strips the domain the users&#8217; browser gives and then calls ntlm_auth.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=54&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/06/08/squid-with-active-directory-sso-non-domain-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Show a denied URL</title>
		<link>http://janaps.wordpress.com/2010/06/07/show-a-denied-url/</link>
		<comments>http://janaps.wordpress.com/2010/06/07/show-a-denied-url/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 09:42:28 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[squid]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=30</guid>
		<description><![CDATA[In my previous post I talked about internet usage based on AD Group membership. What I want to do is present the users with an webpage explaining some things  if they are denied internet usage. If I don&#8217;t implement something like that, you can bet that you&#8217;ll have a number of calls from users asking [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=30&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In my <a href="http://janaps.wordpress.com/2010/06/07/internet-usage-based-on-ad-group-membership/">previous post</a> I talked about internet usage based on AD Group membership. What I want to do is present the users with an webpage explaining some things  if they are denied internet usage. If I don&#8217;t implement something like that, you can bet that you&#8217;ll have a number of calls from users asking why their students can&#8217;t surf the net. So to avoid these calls, a brief, simple webpage explaining that there is nothing wrong, but their account is blocked, will be presented.</p>
<p><strong>Setting failure url</strong></p>
<p>Squid allows you to set a url if  a proxy restriction is not passed</p>
<p>deny_info http://192.168.0.10/internetDenied.html noInternet</p>
<ul>
<li>http://192.168.0.10/internetDenied.html: the url to redirect the user to</li>
<li>noInternet: the name of the proxy ACL to wich this failure url applies to</li>
</ul>
<p>Offcourse the only problem with this is that we have denied the user internet-usage. If he/she can&#8217;t surf, he/she can&#8217;t access the failure url.</p>
<p><strong>Allow intranet usage</strong></p>
<p>The next step is to allow the user, authenticated or not, to visit the failure url. Add a line to /etc/squid/squid.conf</p>
<p>acl to_internal dst 192.168.0.0/24</p>
<p>With this line we allow the users to visit all local subnet addresses. If you want to allow only the webserver with the failure url, you specify</p>
<p>acl to_internal dst 192.168.0.1/32</p>
<p>provided that this webserver has 192.168.0.1 as IP</p>
<p>Now we have to add a proxy restriction with this acl</p>
<p>http_access allow to_internal</p>
<p>Be sure to put this line at the top</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=30&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/06/07/show-a-denied-url/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet usage based on AD group membership</title>
		<link>http://janaps.wordpress.com/2010/06/07/internet-usage-based-on-ad-group-membership/</link>
		<comments>http://janaps.wordpress.com/2010/06/07/internet-usage-based-on-ad-group-membership/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 09:26:28 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[squid]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=25</guid>
		<description><![CDATA[I was looking for a way to block internetusage for students in a class. As all students are member of active directory groups that correspond to classes they are member of, I decided I was going to deny users internet usage if they were a member of certain group, e.g. internetDenied. Prerequisites AD proxy-authentication: see [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=25&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I was looking for a way to block internetusage for students in a class. As all students are member of active directory groups that correspond to classes they are member of, I decided I was going to deny users internet usage if they were a member of certain group, e.g. internetDenied.</p>
<p><strong>Prerequisites</strong></p>
<p>AD proxy-authentication: see <a href="http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory/">this post</a></p>
<p><strong>Setting an external ACL program</strong></p>
<p>This is done by adding a directive to /etc/squid/squid.conf. Look for the tag external_acl_type and add this line</p>
<p>external_acl_type nt_group ttl=10 children=5 %LOGIN /usr/lib/squid/wbinfo_group.pl</p>
<ul>
<li>nt_group is just a name we give this external acl program so we can use it in our ACL</li>
<li>ttl: how long in seconds the results are cached. Set this to a low number if there is a good change the group membership will change often or if a quick response is needed</li>
<li>children: the number of times wbinfo_group.pl is spawned: set this according to your system resources and number of requests</li>
<li>%LOGIN: a variable that holds the username</li>
<li>/usr/lib/&#8230;: the acl program to use</li>
</ul>
<p><strong>Deny internet usage</strong></p>
<p>First  add an ACL to /etc/squid/squid.conf</p>
<p>acl noInternet external nt_group internetDenied</p>
<ul>
<li>noInternet: the name I gave this rule</li>
<li>nt_group: the name of the external acl previously defined</li>
<li>internetDenied: the name of AD-group</li>
</ul>
<p>Now I have to add a proxy restriction. In my previous post I added a rule to allow all authenticated users</p>
<p>acl AuthorizedUsers proxy_auth REQUIRED</p>
<p>http_access allow all AuthorizedUsers</p>
<p>Now basically what I want to do is allow everyone internet usage, EXCEPT to users who are member of the group internetDenied. So I added the following line</p>
<p>http_access deny noInternet</p>
<p>But be carefull here: the deny rule has to be inserted above the allow rule.</p>
<p>References</p>
<p><a href="http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory">http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory</a></p>
<p><a href="http://www.flatmtn.com/article/setting-squid-ntlm-auth">http://www.flatmtn.com/article/setting-squid-ntlm-auth</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=25&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/06/07/internet-usage-based-on-ad-group-membership/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>IIS mixed authentication</title>
		<link>http://janaps.wordpress.com/2010/05/31/iis-mixed-authentication/</link>
		<comments>http://janaps.wordpress.com/2010/05/31/iis-mixed-authentication/#comments</comments>
		<pubDate>Mon, 31 May 2010 14:30:56 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[iis]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=19</guid>
		<description><![CDATA[I&#8217;ve been looking for a way to implement a sort of a double authentication mechanism for our  intranet/extranet. When the users are logged in through a domain account, NTLM should be used, otherwise form based authenticatio should be used. I&#8217;ve found this article that explains just that and looks very promising. Now I just have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=19&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been looking for a way to implement a sort of a double authentication mechanism for our  intranet/extranet. When the users are logged in through a domain account, NTLM should be used, otherwise form based authenticatio should be used.</p>
<p>I&#8217;ve found <a href="http://blogs.claritycon.com/blogs/ryan_powers/archive/2007/06/12/3187.aspx">this</a> article that explains just that and looks very promising. Now I just have to find the time to try it&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=19&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/05/31/iis-mixed-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Squid single sign on with active directory AND dansguardian</title>
		<link>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory-and-dansguardian/</link>
		<comments>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory-and-dansguardian/#comments</comments>
		<pubDate>Sun, 30 May 2010 18:54:53 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[squid]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=11</guid>
		<description><![CDATA[I knew chaining squid with dansguardian wasn&#8217;t too difficult, because the installation of dansguardian is quite straightforward. And so is the NTLM part. Installing dansguardian On fedora this is as simple as it gets: #yum install dansguardian Configuring dansguardian I&#8217;m not going into the contentfiltering configuration of dansguardian (blacklist etc.). I&#8217;m only going to talk [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=11&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I knew chaining squid with dansguardian wasn&#8217;t too difficult, because the installation of dansguardian is quite straightforward. And so is the NTLM part.</p>
<p><strong>Installing dansguardian</strong></p>
<p>On fedora this is as simple as it gets:</p>
<p>#yum install dansguardian</p>
<p><strong>Configuring dansguardian</strong></p>
<p>I&#8217;m not going into the contentfiltering configuration of dansguardian (blacklist etc.). I&#8217;m only going to talk about the NTLM-authentication part.</p>
<p>If you have squid setup with ntml-authentication this is quite easy</p>
<p>Edit /etc/dansguardian/dansguardian.conf</p>
<p>proxyip = 127.0.0.1</p>
<p>proxyport = 3128</p>
<p>And uncomment these two lines</p>
<p>authplugin = &#8216;/etc/dansguardian/authplugins/proxy-basic.conf&#8217;<br />
authplugin = &#8216;/etc/dansguardian/authplugins/proxy-ntlm.conf&#8217;</p>
<p>If lets say your server has an IP 192.168.0.1 then point your clients to use a proxy on 192.168.0.1 on port 8080</p>
<p>Now watch the /var/log/dansguardian/access.log for the username.</p>
<p>That&#8217;s all</p>
<p>reference <a href="http://contentfilter.futuragts.com/wiki/doku.php?id=using_ntlm_for_user_identification&amp;s[]=ntlm">http://contentfilter.futuragts.com/wiki/doku.php?id=using_ntlm_for_user_identification&amp;s[]=ntlm</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=11&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory-and-dansguardian/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Squid single sign on with active directory</title>
		<link>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory/</link>
		<comments>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory/#comments</comments>
		<pubDate>Sun, 30 May 2010 16:18:24 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[squid]]></category>

		<guid isPermaLink="false">http://janaps.wordpress.com/?p=5</guid>
		<description><![CDATA[For my first post on this blog, I will publish my experience with NTLM-proxy authentication. I&#8217;ve gotten most of my info from http://tom.knaupp.com/2007/12/12/howto-single-sign-on-with-squid-proxy-and-active-directory/, but there are some addenda. So here goes Prerequisites You need some linux box, I&#8217;ve used Fedora 11 but anything goes here really A Windows domain, I&#8217;ve used a 2003 domain Prepping [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=5&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For my first post on this blog, I will publish my experience with  NTLM-proxy authentication. I&#8217;ve gotten most of my info from  http://tom.knaupp.com/2007/12/12/howto-single-sign-on-with-squid-proxy-and-active-directory/,  but there are some addenda.<br />
So here goes</p>
<p><strong>Prerequisites</strong><br />
You need some linux  box, I&#8217;ve used Fedora 11 but anything goes here really<br />
A Windows  domain, I&#8217;ve used a 2003 domain</p>
<p><strong>Prepping</strong><br />
install  squid, kerberos tools, winbind and sambaclient<br />
so<br />
#yum install samba-winbind<br />
#yum install  krb5-workstation<br />
#yum install squid<br />
Because of the  dependencies, you will have all necessaray packages if you issue these  three commands. But still, check&#8230;</p>
<p>Next you&#8217;ll have to configure  your firewall. Squid by default listens on TCP 3128, so add this to  your INPUT chain</p>
<p><strong>Configuring  Kerberos</strong><br />
Now we can configure the kerberos protocol.</p>
<p>First  of all, make sure the date and time of your linux-machine are in sync  with that of the domain controller. How big the clocks skew can be,  depends on some policy settings in the DC, but setting the DC as NTP  time source is allways a good idea.</p>
<p>Next we edit the  /etc/krb5.conf file. Mine looks like this.</p>
<p>[logging]<br />
default =  FILE:/var/log/krb5libs.log<br />
kdc =  FILE:/var/log/krb5kdc.log<br />
admin_server  = FILE:/var/log/kadmind.log</p>
<p>[libdefaults]<br />
default_realm =  MYDOMAIN.COM<br />
dns_lookup_realm = true<br />
dns_lookup_kdc = true<br />
ticket_lifetime   = 24h<br />
forwardable = yes</p>
<p>[realms]<br />
MYDOMAIN.COM = {<br />
kdc =   DC1.mydomain.com:88  DC2.mydomain.com:88<br />
admin_server =   DC1.mydomain.com DC2.mydomain.com<br />
default_domain = mydomain.com<br />
}</p>
<p>[domain_realm]<br />
.mydomain.com  = MYDOMAIN.COM<br />
mydomain.com =MYDOMAIN.COM</p>
<p>[appdefaults]<br />
pam  = {<br />
debug = false<br />
ticket_lifetime = 1d<br />
renew_lifetime = 1d<br />
forwardable  =  true<br />
krb4_convert = falsie<br />
retain_after_close = false<br />
minimum_uid  = 1<br />
}</p>
<p>The domain I&#8217;ve  been using is named mydomain.com (not really, but still), and this  domain has two domain-controllers: DC1 and DC2.<br />
Once this is done,  you&#8217;ll have to test kerberos</p>
<p>Get a kerberos ticket with<br />
<code># kinit Administrator<br />
Password  for Administrator@MYDOMAIN.COM:<br />
#</code><br />
Now test the kerberos ticket<br />
# klist<br />
Ticket cache: FILE:/tmp/krb5cc_0<br />
Default  principal: Administrator@MYDOMAIN.COM</p>
<p>Valid starting     Expires              Service principal<br />
05/30/10 15:59:12  05/31/10 01:59:14    krbtgt/MYDOMAIN.COM@MYDOMAIN.COM<br />
renew until 05/31/10  15:59:12</p>
<p>Kerberos  4 ticket cache: /tmp/tkt0<br />
klist: You  have no tickets cached</p>
<p><strong>Samba</strong><br />
Now edit /etc/samba/smb.conf.  Mine looks like this<br />
#GLOBAL PARAMETERS<br />
[global]<br />
workgroup  = LOCAL<br />
realm =  LOCAL.KSJOMA.BE<br />
preferred master = no<br />
server  string = squid  proxy server<br />
security = ADS<br />
encrypt passwords =  yes<br />
log level = 3<br />
log file = /var/log/samba/%m<br />
max log size =  50<br />
printcap name = cups<br />
printing = cups<br />
winbind enum users =   Yes<br />
winbind enum groups = Yes<br />
winbind use default domain =  Yes<br />
winbind  nested groups = Yes<br />
winbind separator = +<br />
idmap uid = 600-20000<br />
idmap  gid = 600-20000<br />
idmap backend =  rid<br />
;template primary group =  &#8220;Domain Users&#8221;<br />
template shell =  /bin/bash</p>
<p>[homes]<br />
comment =  Home Direcotries<br />
valid  users = %S<br />
read only = No<br />
browseable =  No</p>
<p>[printers]<br />
comment = All Printers<br />
path =  /var/spool/cups<br />
browseable =  no<br />
printable = yes<br />
guest ok = yes</p>
<p>Winbind  uses by default an anonymous connection to Active Directory to query  for users and groups. Domains in 2003 mode or higher do not allow this.  You have to provide a domain user to excecute the queries. So create a  user winbind in Active Directory with a very very long password. The  password isn&#8217;t going to be changed on a regular basis. So you can set  the password to NOT expire for this user. Then issue the following  command to tell winbind to use it to query AD<br />
# wbinfo &#8211;domain=MYDOMAIN &#8211;set-auth-user=winbind</p>
<p>A  common error if you try to join AD with winbind an issue with DNS  update. So the best thing to do is set the dns-search domain to your  domain. You can test this by using the command hostname. This should  return the FQDN of the linux box so<br />
#hostname  -f<br />
proxy.mydomain.com</p>
<p><strong>Domain  Join</strong><br />
If all the preparations went  according to plan, you should now be able to join the linux-box with<br />
#net  join -Uadministrator%password</p>
<p>After starting winbind, we  can test the functionality with<br />
#  wbinfo -t<br />
checking the trust secret via RPC calls succeeded<br />
And  you can check if winbind can retrieve groups by<br />
#wbinfo -g</p>
<p>Also we can test  support for ntlm with<br />
# wbinfo -a  user%password<br />
plaintext password authentication succeeded<br />
challenge/response   password authentication succeeded</p>
<p><strong>Squid</strong><br />
The only thing left to do is  tell squid to use the right helper. Add these lines to  /etc/squid/squid.conf<br />
auth_param ntlm program /usr/bin/ntlm_auth   &#8211;helper-protocol=squid-2.5-ntlmssp<br />
auth_param ntlm children 10<br />
auth_param   basic program /usr/bin/ntlm_auth &#8211;helper-protocol=squid-2.5-basic<br />
auth_param   basic children 5<br />
auth_param basic realm Domain Proxy Server<br />
auth_param   basic credentialsttl 2 hours<br />
auth_param basic casesensitive off<br />
authenticate_cache_garbage_interval   10 seconds<br />
##<br />
# Credentials past their TTL are removed from   memory<br />
authenticate_ttl 0 seconds<br />
##<br />
## acl entries to require   authentication:<br />
acl AuthorizedUsers proxy_auth REQUIRED<br />
http_access   allow all AuthorizedUsers</p>
<p>One last problem may occur: squid has  to have permissions on the <code>/var/lib/samba/winbindd_privileged  directory. </code><br />
You should check the following:</p>
<ul>
<li>if the  line  cache_effective_group is commented out or set to None in  squid.conf: by default the group with permissions on this directory is  wbpriv and squid is a member of this group.</li>
<li>if the above is not  true make sure that squid has permissions on this directory. To my  experience though, changing the group owner on this directory can make  winbind fail to start.</li>
</ul>
<p>Now we are all done: fire up squid and  check /var/log/squid/access.log for the usernames. Sweet</p>
<p>References:<br />
<a href="http://adam.breidenbaugh.net/tech/Linux-AD-VMWare-Authentication_Howto.htm">http://adam.breidenbaugh.net/tech/Linux-AD-VMWare-Authentication_Howto.htm</a><br />
<a href="http://tom.knaupp.com/2007/12/12/howto-single-sign-on-with-squid-proxy-and-active-directory/">http://tom.knaupp.com/2007/12/12/howto-single-sign-on-with-squid-proxy-and-active-directory/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=5&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2010/05/30/squid-single-sign-on-with-active-directory/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
		<item>
		<title>Hello world!</title>
		<link>http://janaps.wordpress.com/2008/01/21/hello-world/</link>
		<comments>http://janaps.wordpress.com/2008/01/21/hello-world/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 08:11:18 +0000</pubDate>
		<dc:creator>janaps</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Welcome to WordPress.com. This is your first post. Edit or delete it and start blogging!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=1&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Welcome to <a href="http://wordpress.com/">WordPress.com</a>. This is your first post. Edit or delete it and start blogging!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/janaps.wordpress.com/1/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/janaps.wordpress.com/1/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janaps.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janaps.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janaps.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janaps.wordpress.com&amp;blog=2574465&amp;post=1&amp;subd=janaps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janaps.wordpress.com/2008/01/21/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/efefa49db0b9577dba0c3d281a296355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janaps</media:title>
		</media:content>
	</item>
	</channel>
</rss>
