[squid-users] Squid not following 302

2015-09-21 Thread Ashish Mukherjee
Hello, Squid does not follow 302 and sends back the 302 header to the client. I am aware it is so as it would be bad to hide the ultimate url from the client and for reasons of cache poisoning etc. However, I have a scenario where I need to implement a proxy browsing pattern for a controlled audi

[squid-users] Database dilema

2015-09-21 Thread Mumin Coder
I want to make some kind of safe transparent proxy using ubuntu, squid, icap or ecap, database (MongoDB or MySql) and XSS prevention module. I want to be able to inspect URL and javascript/xml inside web page with my sandboxed module (javascript engine) which will be connected to squid and data

Re: [squid-users] Database dilema

2015-09-21 Thread Eliezer Croitoru
Hey Mumin, What do you need from the db? If you need a blacklist I can offer you to use SquidBlocker which I wrote: http://ngtech.co.il/squidblocker/ The DB is not fully documented but it works under a very heavy load and seems to give good results. Eliezer On 15/09/2015 12:23, Mumin Coder wr

Re: [squid-users] Squid not following 302

2015-09-21 Thread Antony Stone
On Monday 21 September 2015 at 11:20:56, Ashish Mukherjee wrote: > Squid does not follow 302 and sends back the 302 header to the client. I am > aware it is so as it would be bad to hide the ultimate url from the client > and for reasons of cache poisoning etc. > > However, I have a scenario wher

Re: [squid-users] Lots of "Vary object loop!"

2015-09-21 Thread Eliezer Croitoru
Is it happening also with ram cahce only? no disk cache? Eliezer On 04/09/2015 00:02, Sebastián Goicochea wrote: But still seeing all those Vary loops all the time :( Thanks, Sebastian ___ squid-users mailing list squid-users@lists.squid-cache.org

Re: [squid-users] Squid not following 302

2015-09-21 Thread Amos Jeffries
On 21/09/2015 9:20 p.m., Ashish Mukherjee wrote: > Hello, > > Squid does not follow 302 and sends back the 302 header to the client. I am > aware it is so as it would be bad to hide the ultimate url from the client > and for reasons of cache poisoning etc. Then why do you expect Squid would be al

[squid-users] Squid as reverse proxy with EC private key

2015-09-21 Thread Johannes Engel
Dear all, I would like to run squid 3.5.8 as a reverse proxy for our webserver. I already have a certificate which is currently in use by the Apache Webserver 2.4 itself. It is based upon an EC (elliptic curve) private key of length 384. Until now I have not managed to fire up squid with by specif

Re: [squid-users] Squid as reverse proxy with EC private key

2015-09-21 Thread Amos Jeffries
On 22/09/2015 2:09 a.m., Johannes Engel wrote: > Dear all, > > I would like to run squid 3.5.8 as a reverse proxy for our webserver. I > already have a certificate which is currently in use by the Apache > Webserver 2.4 itself. It is based upon an EC (elliptic curve) private key > of length 384. >

Re: [squid-users] user agent

2015-09-21 Thread Amos Jeffries
On 20/09/2015 9:04 p.m., Amos Jeffries wrote: > On 19/09/2015 5:53 a.m., joe wrote: >> mmm >> any answer amosalizar guys ?? >> if the code work once let me know if there is a way let me know >> if the code not complete in source code let me know better then waiting for >> >> !!a

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Amos Jeffries
On 17/09/2015 10:07 p.m., Yuri Voinov wrote: > If I disable SSL bump for tunneled sites, I've got an error SSL: > > ssl_error_rx_record_too_long > If you "disabled" ssl_bump by removing its config, or using "ssl_bump none" for that traffic then the error is strictly a problem between the client

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Can't understand, why it is not work. Tor Browser works ok itself. The similar config via Squid 3.5.7+Privoxy - don't. CONNECT to torproject.org:443 goes directly, whenever config changes. 21.09.15 23:56, Amos Jeffries пишет: > On 17/09/2015 10

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Amos Jeffries
On 22/09/2015 6:00 a.m., Yuri Voinov wrote: > > Can't understand, why it is not work. > > Tor Browser works ok itself. > > The similar config via Squid 3.5.7+Privoxy - don't. > > CONNECT to torproject.org:443 goes directly, whenever config changes. I suspect some detail is being removed during

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This is dig result: ;; ANSWER SECTION: torproject.org. 3600IN A 93.95.227.222 torproject.org. 3600IN A 154.35.132.70 torproject.org. 3600IN A 86.59.30.40 torproject.org.

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The torproject.org is just an example. This is not so important like, for example, google docs, google mail, google drive (all web interface at minimum), archive.org. All of this uses HSTS now and, if banned by IP by ISP (note: dns is not spoofed

Re: [squid-users] user agent

2015-09-21 Thread joe
is it possible to have at least 2 pls it will solve some problem between mobile and windows browser having same Ua i guess all squid user will be happy tks -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/user-agent-tp4673284p4673328.html Sent from the Sq

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I'm in a coffin seen all purulent politics. But when suddenly my customers lose access to their documents on Google documents - I pick up instruments. And I want them to work. At the same time, I can not put everything and everyone Tor Browser. A

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Amos Jeffries
On 22/09/2015 6:25 a.m., Yuri Voinov wrote: > > This is dig result: > > ;; ANSWER SECTION: > torproject.org. 3600IN A 93.95.227.222 > torproject.org. 3600IN A 154.35.132.70 > torproject.org. 3600IN A 86.59.30.40 > torproject.org

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 22.09.15 1:15, Amos Jeffries пишет: > On 22/09/2015 6:25 a.m., Yuri Voinov wrote: >> >> This is dig result: >> >> ;; ANSWER SECTION: >> torproject.org. 3600IN A 93.95.227.222 >> torproject.org. 3600IN A

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Antony Stone
On Monday 21 September 2015 at 21:20:19, Yuri Voinov wrote: > 22.09.15 1:15, Amos Jeffries пишет: > > > HSTS is opt-out. Strip the *response* header on the first contact and it > > disappears. > > I can't. Because first connection can't occur during ISP ban by IP. > First contact is never occurs.

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 22.09.15 1:23, Antony Stone пишет: > On Monday 21 September 2015 at 21:20:19, Yuri Voinov wrote: > >> 22.09.15 1:15, Amos Jeffries пишет: >> >>> HSTS is opt-out. Strip the *response* header on the first contact and it >>> disappears. >> >> I can'

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Here is access log when using IE: 1442863815.068785 127.0.0.1 TCP_MISS/302 506 GET http://torproject.org/ - FIRSTUP_PARENT/127.0.0.1 text/html 1442863816.542 105231 127.0.0.1 TAG_NONE/200 0 CONNECT www.torproject.org:443 - HIER_DIRECT/2001:41b

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Finally it ends up by this one: http://i.imgur.com/izWY1cc.png Antony, how it can be explained? ;) 22.09.15 1:23, Antony Stone пишет: > On Monday 21 September 2015 at 21:20:19, Yuri Voinov wrote: > >> 22.09.15 1:15, Amos Jeffries пишет: >> >>> H

Re: [squid-users] Squid as reverse proxy with EC private key

2015-09-21 Thread Johannes Engel
Thanks a lot for the swift reply, Amos! Much appreciated. Best regards, Johannes 2015-09-21 19:36 GMT+02:00 Amos Jeffries : > On 22/09/2015 2:09 a.m., Johannes Engel wrote: > > Dear all, > > > > I would like to run squid 3.5.8 as a reverse proxy for our webserver. I > > already have a certificat

Re: [squid-users] Is it possible to send the connection, starting with the CONNECT, to cache-peer?

2015-09-21 Thread Amos Jeffries
On 22/09/2015 7:33 a.m., Yuri Voinov wrote: > > Here is access log when using IE: > > 1442863815.068785 127.0.0.1 TCP_MISS/302 506 GET > http://torproject.org/ - FIRSTUP_PARENT/127.0.0.1 text/html > 1442863816.542 105231 127.0.0.1 TAG_NONE/200 0 CONNECT > www.torproject.org:443 - HIER_DIRECT/

[squid-users] need help for using squid

2015-09-21 Thread ????????????
Hi: I am a developer from Beijing of China, these Days, when using squid(version 3.5.8),I met some problems,my goal of program is making the computer(system of ubuntu 14.04) as a cache server ( only ipa and apk files can be saved),my computer has two network cards ,one is wired ,the other is

Re: [squid-users] ETA for Bug 3775

2015-09-21 Thread Nicolaas Hyatt
Recent Backtrace: Squid Cache: Version 3.5.9 Service Name: squid configure options: '--prefix=/usr' '--exec-prefix=/usr' '--includedir=/usr/include' '--datadir=/usr/share' '--libdir=/usr/lib64' '--libexecdir=/usr/lib64/squid' '--localstatedir=/var' '--sysconfdir=/etc/squid' '--sharedstatedir=/

Re: [squid-users] ETA for Bug 3775

2015-09-21 Thread Alex Rousskov
On 09/21/2015 07:40 PM, Nicolaas Hyatt wrote: > Recent Backtrace: > Squid Cache: Version 3.5.9 > Service Name: squid > #0 0x773e3210 in ssl23_put_cipher_by_char () from > /lib64/libssl.so.10 > #1 0x0078734c in Ssl::Bio::sslFeatures::parseV23Hello > (this=this@entry=0xac01b2a8, he