Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-19 Thread Victor Sudakov
Eugene M. Zheganin wrote: On 18.10.2014 16:11, Victor Sudakov wrote: I thought as much. This error seems suspicious. But why does a second request not cause the same error? No idea. Hopefully I can interest our Windows admin to enable Kerberos event logging per KB262177. But for the

Re: [squid-users] windowsupdate and ssl_bump

2014-10-19 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 18/10/2014 8:56 p.m., Josep Borrell wrote: Hi, We are using a 3.4.8 squid Proxy in intercept mode via wccp. Squid intercepts HTTP and HTTPS via ssl_bump. All is working fine except that Windows Machines can't do a Windows Update. It is not

Re: [squid-users] Negotiate bug in squidclient ?

2014-10-19 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 That is a bug. Please add to bugzilla. Amos -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.22 (MingW32) iQEcBAEBAgAGBQJURCItAAoJELJo5wb/XPRjtgkIAKyGuSZQnpfofxeH5VggQ/sJ 2coDiglI/rVFjO4UAaCIu3e8Vhzst7cDmWaCbY9Gre6pemlliHuX2+64TmlzPcNv

Re: [squid-users] Question squid on centos 6.5 and poodle

2014-10-19 Thread Alexander Samad
Hi Thanks for clearing that up. so when i do a openssl ciphers and select the ciphers i want including the PFS enables oned, i take the list and try and use it in ciphers= and the list seems to be dissregarded and only 1 cipher is available. atleast from online checking and with nmap. I have

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-19 Thread Eugene M. Zheganin
Hi. On 19.10.2014 13:32, Victor Sudakov wrote: Hopefully I can interest our Windows admin to enable Kerberos event logging per KB262177. But for the present I have found an ugly workaround. In squid's keytab, I created another principal called 'squiduser' with the same hex key and kvno as

Re: [squid-users] TCP_DENIED/403 after Upgrading from 3.4.4 to 3.4.7 (ssl_bump enabled)

2014-10-19 Thread Tom Tom
Hi Amos Do you have new findings? Should I open a bug for better tracking? Kind regards, Tom On Mon, Oct 13, 2014 at 8:16 AM, Amos Jeffries squ...@treenet.co.nz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 13/10/2014 6:26 p.m., Tom Tom wrote: Hi Does anyone have some