[squid-users] dns_ttl positive/negative Squid 3.5.10

2015-11-02 Thread FredB
Hello all, For a specific need, I want to reduce the DNS requests, so I'm trying with positive_dns_ttl 6 hours And negative_dns_ttl 4 hours But there is something wrong If I try a false domain like test.google.com there is a response from my DNS Servail, so ok But if I retry after a short ti

Re: [squid-users] dns_ttl positive/negative Squid 3.5.10

2015-11-02 Thread Antony Stone
On Monday 02 November 2015 at 16:39:45, FredB wrote: > I want to reduce DNS requests, so I'm trying with > > positive_dns_ttl 6 hours > And > negative_dns_ttl 4 hours > If I try a false domain like test.google.com there is a response from my > DNS Servail, so ok But if I retry after a short time

Re: [squid-users] dns_ttl positive/negative Squid 3.5.10

2015-11-02 Thread FredB
> > If I try a false domain like test.google.com there is a response from > my DNS Servail, so ok > But if I retry after a short time - maybe one minute - there is again > a DNS request > test.google.com is not the best example, the domain google.com exist but not the subdomain So, same prob

Re: [squid-users] dns_ttl positive/negative Squid 3.5.10

2015-11-02 Thread FredB
> > From http://www.squid-cache.org/Doc/config/positive_dns_ttl/ > > "Upper limit on how long Squid will cache positive DNS responses." > > Note: "Upper limit" - not "lower limit", or "forced value". > > So, if the DNS response gives you a TTL of 15 minutes, and you've > specified an > upper l

[squid-users] Squit with NTLM and Kerberos auth => a error

2015-11-02 Thread Olivier CALVANO
Hi i test a authentification AD with Kerberos/Ntlm ### negotiate kerberos and ntlm authentication auth_param negotiate program /usr/local/bin/negotiate_wrapper --ntlm /usr/bin/ntlm_auth --diagnostics --helper-protocol=squid-2.5-ntlmssp --kerberos /usr/lib64/squid/squid_kerb_auth -d -s GSS_C_NO_NA

Re: [squid-users] Squit with NTLM and Kerberos auth => a error

2015-11-02 Thread Markus Moeller
Hi Olivier, Which Kerberos version do you use ? MIT or Heimdal ? Markus "Olivier CALVANO" wrote in message news:cajajpefqoygt5zsyw7fwszwrttxn-r1pd-u73xdfonax9dl...@mail.gmail.com... Hi i test a authentification AD with Kerberos/Ntlm ### negotiate kerberos and ntlm authentication auth_par

Re: [squid-users] Squit with NTLM and Kerberos auth => a error

2015-11-02 Thread Markus Moeller
Hi Olivier, If I decode a token I see /base64> hexdump -c base64_dec.out 000 ` 201 236 006 006 + 006 001 005 005 002 240 201 223 0 201 010 220 240 032 0 030 006 \n + 006 001 004 001 202 7 002 002 020 036 006 \n + 006 001 004 001 202 7 002 002 \n 242 r 004 030

Re: [squid-users] Outgoing IPv6 address with no IPv4 address access

2015-11-02 Thread Amos Jeffries
Lets rewind... *Why* do a you have this requirement at all? Why have a server connected to IPv4 which is not permitted to use IPv4 ? On 2/11/2015 11:50 p.m., Robert Conlustro wrote: > Thank you for all the great information. I understand the squid will > automatically use IPv6 before IPv4 if th