Re: [squid-users] Squid 3.5.1 intercept / Forwarding loop detected for

2015-02-14 Thread naser sonbaty
Hi, thx, if I change this: http_port 127.0.0.1:3128 http_port 192.168.15.2:3129 intercept to this: http_port 192.168.15.2:3129 then its working On Sun, Feb 15, 2015 at 1:02 AM, Amos Jeffries wrote: > On 15/02/2015 12:19 p.m., naser sonbaty wrote: > > Hi, > > > > thx for support. > > > > I fo

Re: [squid-users] Squid 3.5.1 intercept / Forwarding loop detected for

2015-02-14 Thread Amos Jeffries
On 15/02/2015 12:19 p.m., naser sonbaty wrote: > Hi, > > thx for support. > > I found second running squid on same box. I shut-down the second squid. > But the problems are not gone.. > > Sorry I don't have access to the router pc :-( I can not get the rule > > I have set up web browse

Re: [squid-users] Squid 3.5.1 intercept / Forwarding loop detected for

2015-02-14 Thread naser sonbaty
Hi, thx for support. I found second running squid on same box. I shut-down the second squid. But the problems are not gone.. Sorry I don't have access to the router pc :-( I can not get the rule I have set up web browsers to use direct squid with 3129. But the result its same. I found

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I can to reproduce this with trace at Monday. My users uses that. 15.02.15 3:46, Amos Jeffries пишет: > On 15/02/2015 9:26 a.m., Jason Haar wrote: >> But this is just a hack around a problem isn't it? > > Yes. > >> ie why can't squid successfully i

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 15/02/2015 9:26 a.m., Jason Haar wrote: > But this is just a hack around a problem isn't it? Yes. > ie why can't squid successfully intercept 20M+ transfers from this > website? Well, Squid *is* intercepting them. Its what happens after that is g

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yep. This is dirty hack.:) But I guess this is site-specific limitations. Besides the fact that the bump does not work with attachments to many Webmail services and clouds. I think, this is because mail.ru uses cloud as backend of mail attachments. W

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Jason Haar
But this is just a hack around a problem isn't it? ie why can't squid successfully intercept 20M+ transfers from this website? I guess it's working for 1byte-10M transactions, so why not 20M? Jason On 14/02/15 23:22, Yuri Voinov wrote: > No problem. ;) > > 100 ip's is no problem. If they in one

Re: [squid-users] squid authentication to remote sql server

2015-02-14 Thread Amos Jeffries
On 15/02/2015 8:25 a.m., snakeeyes wrote: > Hi Amos , > > Shoudnt the user tested is the user that I gave him the grant ??? The 'user' who got a SQL "GRANT" is the software user whch is allowed to acccess the DB contents. That should only be Squid and/or your sysadmin who changes users records.

Re: [squid-users] benefits ofusingext_kerberos_ldap_group_aclinstead of ext_ldap_group_acl

2015-02-14 Thread Markus Moeller
On 12.02.2015, at 17:58, Amos Jeffries wrote: On 13/02/2015 5:41 a.m., Simon Stäheli wrote: hmh, HAVE_KRB5 seems not to be set in include/autoconf.h What is the correct way to provide squid the path to the kerberos header files? ./configure —help doesn’t show a useful option as --with-k

Re: [squid-users] Kerberos authentication problem - squid 3.4.11

2015-02-14 Thread Markus Moeller
Hi Ludovit, Yes the client determines the encryption strength and squid needs to have all of them in the keytab (You can disallow DES or other weak encryption by not adding these encryptions to the keytab). Regards Markus "Ludovit Koren" wrote in message news:86lhk0j2xe@gmail.com...

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Dima Ermakov
Yes! No problem;) Thank you!!! On Feb 14, 2015 1:22 PM, "Yuri Voinov" wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > No problem. ;) > > 100 ip's is no problem. If they in one subnet, you can pass only this > sublet with one row in acl. Overall *.mail.ru is much more networks, > so 1

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 No problem. ;) 100 ip's is no problem. If they in one subnet, you can pass only this sublet with one row in acl. Overall *.mail.ru is much more networks, so 100 ip's no matter. ;) But bumping remains can give your better hit rate. 14.02.15 16:20, Di

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Dima Ermakov
Now i can upload, after adding ip addresses from my previous message to ssl_bump none acl. Thank you. On Feb 14, 2015 1:15 PM, "Yuri Voinov" wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I.e, you want to say you cannot upload file above 25 megabytes? > > 14.02.15 12:55, Dima Ermako

Re: [squid-users] intercept squid 3.5.1, http://mail.ru

2015-02-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I.e, you want to say you cannot upload file above 25 megabytes? 14.02.15 12:55, Dima Ermakov пишет: > I think, that it's not good solution too, but > uploadXXX.files.mail.ru has about 100 servers. > > Now i write small script on python, that creates

Re: [squid-users] squid authentication to remote sql server

2015-02-14 Thread snakeeyes
Hi Amos , Shoudnt the user tested is the user that I gave him the grant ??? I mean I gave grant for user/pwd ==>squid/squid Now how to test it ? Shoudnt I test with squid/squid ?? or test with user in db ??? I mean I used : /lib/squid/basic_db_auth --dsn "DBI:mysql:database=squid:xx189.177" --

Re: [squid-users] logfileHandleWrite: daemon:/var/logs/access.log: error writing ((32) Broken pipe)

2015-02-14 Thread Amos Jeffries
On 14/02/2015 6:13 p.m., Priya Agarwal wrote: > > I had also set the permission of '/usr ' to nobody. I can reboot my system > with the default permissions if I have screwd up my system way too much. If Okay. Do that. Then let me know what the output is from: ls -la /var ls -la /var/logs

Re: [squid-users] Kerberos authentication problem - squid 3.4.11

2015-02-14 Thread Ludovit Koren
> Markus Moeller writes: > It could be the new AD server is setup to be backward compatible > meaning it use RC4 despite being able to use AES. I suggest you crate > an additional keytab entry for RC4. How did you create the keytab ? Now it seems to work: # /usr/local/libex