Re: [squid-users] keep data after delete swap.state

2015-03-11 Thread Amos Jeffries
On 12/03/2015 6:15 p.m., HackXBack wrote: > if there is error in swap.state file and want to recreate it what is the > option to do that without losing data on hdd ? 1) stop Squid 2) manually erase the broken swap.state file(s) 3) run squid -z 4) start Squid NOTE: squid -z is just to ensure the d

[squid-users] keep data after delete swap.state

2015-03-11 Thread HackXBack
if there is error in swap.state file and want to recreate it what is the option to do that without losing data on hdd ? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/keep-data-after-delete-swap-state-tp4670344.html Sent from the Squid - Users mailing list a

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread HackXBack
are you talking about radius server like free radius ? or like dmasoftlab.com ? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/One-Time-Password-with-squid-exists-tp4670337p4670343.html Sent from the Squid - Users mailing list archive at Nabble.com.

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread Amos Jeffries
On 12/03/2015 4:22 p.m., Daniel Greenwald wrote: > Amos- Where can i get the per message pki authentication you describe.!? I saw it on a forum somewhere shortly after the Sony DRM/rootkit issue came out. It was a proposal for non-intrusive DRM in music/video streams with a custom client and serve

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread Amos Jeffries
On 12/03/2015 3:25 p.m., Eliezer Croitoru wrote: > Thanks Amos, > > So NTLM has "two steps" authentication which means that there is a basic > negotiation over the http connection to the proxy which makes it less > secure then kerberos. > > (speculating) > The main reason it's less secure then ke

Re: [squid-users] assertion failed: comm.cc:769: "Comm::IsConnOpen(conn)"

2015-03-11 Thread HackXBack
please i need solution for this am using 3.4.12 and still same problem every few hour squid restart automatically maybe high traffic make this problem ? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/assertion-failed-comm-cc-769-Comm-IsConnOpen-conn-tp46698

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread Eliezer Croitoru
Thanks Amos, So NTLM has "two steps" authentication which means that there is a basic negotiation over the http connection to the proxy which makes it less secure then kerberos. (speculating) The main reason it's less secure then kerberos is that every part of the password negotiation steps

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread Amos Jeffries
On 12/03/2015 2:50 p.m., Eliezer Croitoru wrote: > Hey List, > > I was wondering about if OTP was ever implemented officially with squid? To answer that you need to define OTP. * Basic is the only scheme which delivers a password. So technically the others are all one-use-password schemes alread

[squid-users] One Time Password with squid, exists?

2015-03-11 Thread Eliezer Croitoru
Hey List, I was wondering about if OTP was ever implemented officially with squid? I have seen that most OTP works with some kind of third party system such as a radius server. I had in mind a simple setup with a mysql backend and a php\cgi\other frontend that will create a one time password

Re: [squid-users] Hostname missing in request URL

2015-03-11 Thread Amos Jeffries
On 12/03/2015 7:41 a.m., jaykbvt wrote: > Hi, I am facing a strange scenario where my users requested URL gets > truncated in request to my squid server. The setup is in transparent proxy > mode with Cisco ISG in between with L4 redirection on www traffic. > > > > It works proper only if I conf

Re: [squid-users] SquidclamAV respons modification

2015-03-11 Thread Amos Jeffries
On 12/03/2015 10:26 a.m., Grzegorz Falkowski wrote: > Hello, > I plan to use sclamav with c-icap to secure web app from malware threat. > I prepare whole configuration and it's work fine. Unfortunately in first > stage of implementation it shouldn't make any changes to the respond. Virus > detectio

Re: [squid-users] Squid Reverse Proxy to Exchange 2010 OWA

2015-03-11 Thread Amos Jeffries
On 12/03/2015 8:59 a.m., dweimer wrote: > On 03/11/2015 1:16 am, Alex Samad wrote: >> This is mine against 2008. haven't had any issues with attachments up >> to 10M >> >> >> cache_peer 127.0.0.1 parent 443 0 proxy-only no-query no-digest >> originserver login=PASS ssl sslflags=DONT_VERIFY_PEER >>

Re: [squid-users] Squid Reverse Proxy to Exchange 2010 OWA

2015-03-11 Thread Amos Jeffries
On 12/03/2015 11:15 a.m., Alex Samad wrote: > I have to admit this was built from a lot of googling for a working config. > > > On 11 March 2015 at 19:09, Amos Jeffries wrote: >> On 11/03/2015 7:16 p.m., Alex Samad wrote: > [snip] >>> # List of acceptable URLs to send to the Exchange server >>>

Re: [squid-users] 3.5 cache and “only-if-cached” directive was specified.

2015-03-11 Thread Amos Jeffries
On 12/03/2015 9:22 a.m., Tory M Blue wrote: > Wondering why I'm getting this error, what config param am I missing? > > I have 1 parent, 2 squid servers configured as siblings for each other > > http_port 80 accel vhost > > cache_peer apps-preprod.domain.net parent 80 0 no-digest no-query > orig

Re: [squid-users] Squid Reverse Proxy to Exchange 2010 OWA

2015-03-11 Thread Alex Samad
I have to admit this was built from a lot of googling for a working config. On 11 March 2015 at 19:09, Amos Jeffries wrote: > On 11/03/2015 7:16 p.m., Alex Samad wrote: [snip] >> # List of acceptable URLs to send to the Exchange server >> acl exch_url url_regex -i /exchange >> acl exch_url url_r

[squid-users] SquidclamAV respons modification

2015-03-11 Thread Grzegorz Falkowski
Hello, I plan to use sclamav with c-icap to secure web app from malware threat. I prepare whole configuration and it's work fine. Unfortunately in first stage of implementation it shouldn't make any changes to the respond. Virus detection must be logged and that it. I was looking for a solution in

[squid-users] 3.5 cache and “only-if-cached” directive was specified.

2015-03-11 Thread Tory M Blue
Wondering why I'm getting this error, what config param am I missing? I have 1 parent, 2 squid servers configured as siblings for each other http_port 80 accel vhost cache_peer apps-preprod.domain.net parent 80 0 no-digest no-query originserver no-netdb-exchange cache_peer cache01.pp.sv.domain.

Re: [squid-users] Squid Reverse Proxy to Exchange 2010 OWA

2015-03-11 Thread dweimer
On 03/11/2015 1:16 am, Alex Samad wrote: This is mine against 2008. haven't had any issues with attachments up to 10M cache_peer 127.0.0.1 parent 443 0 proxy-only no-query no-digest originserver login=PASS ssl sslflags=DONT_VERIFY_PEER sslcert=/etc/httpd/conf.d/o.crt sslkey=/etc/httpd/conf.d/o

Re: [squid-users] Whether squid 3.5.2 can support rock at wccp tproxy environment really ?

2015-03-11 Thread Eliezer Croitoru
Hey, I was left in the dark and still unsure what the situation is?? Did you made it work fine? Eliezer On 11/03/2015 11:09, johnzeng wrote: Hello Amos: Ok, I see Thanks again. Have a good day with yo

[squid-users] Hostname missing in request URL

2015-03-11 Thread jaykbvt
Hi, I am facing a strange scenario where my users requested URL gets truncated in request to my squid server. The setup is in transparent proxy mode with Cisco ISG in between with L4 redirection on www traffic. It works proper only if I configure proxy settings explicitly in user's browser.

Re: [squid-users] Ipc::Mem::Segment::attach failed to mmap(/squid-squid-page-pool.shm): (12) Cannot allocate memory

2015-03-11 Thread Amos Jeffries
On 12/03/2015 3:05 a.m., FredB wrote: > Hi, > > I'm trying workers and rock store, I missed something ? > > workers 2 > cache_dir rock /tmp/squid1 13000 max-size=1024 > cache_dir rock /tmp/squid2 13000 max-size=1024 > > > Squid Cache: Version 3.5.2-20150304-r13770 > Service Name: squid > config

[squid-users] Ipc::Mem::Segment::attach failed to mmap(/squid-squid-page-pool.shm): (12) Cannot allocate memory

2015-03-11 Thread FredB
Hi, I'm trying workers and rock store, I missed something ? workers 2 cache_dir rock /tmp/squid1 13000 max-size=1024 cache_dir rock /tmp/squid2 13000 max-size=1024 Squid Cache: Version 3.5.2-20150304-r13770 Service Name: squid configure options: '--prefix=/' '--includedir=${prefix}/include' '

Re: [squid-users] i hope to build web Authentication portal at Tproxy environment recenty , can you give me some advisement .

2015-03-11 Thread johnzeng
Hello Steve: Thanks for your clear detail and advisement . John On 11.03.15 10:22, johnzeng wrote: whether php or jquery need send user ip address to squid ? otherwise i worried whether squid can confirm user info and how to identify and controll h

Re: [squid-users] i hope to build web Authentication portal at Tproxy environment recenty , can you give me some advisement .

2015-03-11 Thread Steve Hill
On 11.03.15 10:22, johnzeng wrote: whether php or jquery need send user ip address to squid ? otherwise i worried whether squid can confirm user info and how to identify and controll http traffic ? I'd do this with an external ACL - when processing a request, Squid would call the external AC

[squid-users] i hope to build web Authentication portal at Tproxy environment recenty , can you give me some advisement .

2015-03-11 Thread johnzeng
Hello Dear all: i hope to build web Authentication portal at Tproxy environment recenty , but i don't have experience about the Authentication, Which Authentication mode will be best direction between Ldap and My sql or other (ncsa ) for web Athentication portal ? my thought is : When Htt

Re: [squid-users] Whether squid 3.5.2 can support rock at wccp tproxy environment really ?

2015-03-11 Thread johnzeng
Hello Amos: Ok, I see Thanks again. Have a good day with you . Hello Amos: --- For

Re: [squid-users] Authentication help

2015-03-11 Thread Amos Jeffries
On 6/03/2015 9:49 a.m., Informatico Neurodesarrollo wrote: > Hi list, > I am new in the list and I want to solve a problem with the > authentication process in the factory that I worked some years ago and > in this place I began work with Linux. > They use openSuSE 13.2 (64bits) with squid 3.4.4, t

[squid-users] Squid Bugzilla attachment problems FIXED

2015-03-11 Thread Amos Jeffries
For those of you trying add attachments to our bugzilla, we believe the issue that has been coming up over the last few weeks is now fixed. The problem was a mismatch between recent Perl versions and our ancient bugzilla code modules. As usual with this type of problem, an upgrade of the affected

Re: [squid-users] Squid Reverse Proxy to Exchange 2010 OWA

2015-03-11 Thread Amos Jeffries
On 11/03/2015 7:16 p.m., Alex Samad wrote: > This is mine against 2008. haven't had any issues with attachments up to 10M > > Small audit with things to look at fixing to improve your security when you have some time. > cache_peer 127.0.0.1 parent 443 0 proxy-only no-query no-digest > originser