Re: [squid-users] Problems with Squid Authentication

2016-08-19 Thread Marcio Demetrio Bacci
Hi, 1) Here is the result of the command-line: /usr/lib/squid/negotiate_kerberos_auth -s HTTP/ proxy.empresa.com...@empresa.com.br –d –i mary abc@12345 negotiate_kerberos_auth.cc(258): pid=1421 :2016/08/19 23:44:33| negotiate_kerberos_auth: DEBUG: Got 'mary abc@12345' from squid (length: 14).

Re: [squid-users] squid shutdown or reconfigure in Multi-instance environment 3.5.2

2016-08-19 Thread --Ahmad--
O man , me too i miss you . > On Aug 20, 2016, at 2:51 AM, Benjamin E. Nichols > wrote: > > We miss you! > > Benjamin E. Nichols > http://www.squidblacklist.org > > 1-405-397-1360 > > -- Original message-- >

[squid-users] squid shutdown or reconfigure in Multi-instance environment 3.5.2

2016-08-19 Thread --Ahmad--
Hi Squid-users == I’m using squid 3.5.2 as multi instances . i have it great i have many instances like squid -n s1 squid -n s2 squid -n s3 squid -n s4 . . . etc but the problem that i have is sometimes i need to reconfigure only 1 instance or reload 1 instance alone if i try to

Re: [squid-users] DENIED and ALLOWED at once?

2016-08-19 Thread Antony Stone
On Friday 19 August 2016 at 20:41:11, Jok Thuau wrote: > On Fri, Aug 19, 2016 at 9:33 AM, Sergio Belkin wrote: > > /var/log/squid/access.log > > 192.168.50.41 - - [19/Aug/2016:12:19:45 -0300] "CONNECT > > beap-bc.yahoo.com:443 HTTP/1.1" 407 4634 "-" "Mozilla/5.0 (Windows NT > >

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread erdosain9
For eg., in all the config that i read is necessary a file call something like squid.keytab... its possible just make a user in AD like "squid", and then just log the squid in the Ad??? or is mandatory generating this file??? thanks -- View this message in context:

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sorry, this is not to me. My setups works without any authentication, just transparent interception. :) 20.08.2016 0:16, erdosain9 пишет: > :-) > lol > > This is the krb5.conf in the AD. > [libdefaults] > default_realm = EPRUEBA.LAN >

[squid-users] communication with parent proxy using ssl

2016-08-19 Thread Jānis
Hi! may someone suggest some solution for traffic encryption between the parent and "child" proxy based on squid's own functionality? Solution involving stunnel is clear. Janis ___ squid-users mailing list squid-users@lists.squid-cache.org

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread erdosain9
:-) lol This is the krb5.conf in the AD. [libdefaults] default_realm = EPRUEBA.LAN dns_lookup_realm = false dns_lookup_kdc = true ~ just that. the admin of the AD, tell me that squid need to authenticate with Kerberos to have all other

[squid-users] DENIED and ALLOWED at once?

2016-08-19 Thread Sergio Belkin
Hi, I've configured squid 3.5.19 to allow only AD authenticated users, the strange thing I've found is that the same domain is both denied and allowed. In some browsers I had problem with yahoo.com that won't load correctly the pages. Besides that, I used squidanalyzer, and it's a problem that

Re: [squid-users] HTTPS - THE PROXY SERVER IS REFUSING CONNECTIONS

2016-08-19 Thread adego70
Thank you VERY MUCH L.P.H. van Belle ! I tried with or without changes but I don't have good result : I still have " THE PROXY SERVER IS REFUSING CONNECTIONS" for https websites... I can't understand why it doesn't work. Is it working on your side ? Another information, maybe it's

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 https://www.google.com/search?q=Kerberos+%28Heimdal%29+configuring 19.08.2016 21:20, erdosain9 пишет: > Kerberos (Heimdal) -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXtykTAAoJENNXIZxhPexG3yUH/3wOl8nd6OAtfWVcCKYvDqFS

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread erdosain9
Hi. Could give me a link for configuring Kerberos (Heimdal) ???. I can not find tutorials about it. Thanks! -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/AD-Ldap-automatically-take-the-user-that-is-logging-on-PC-tp4678994p4679045.html Sent from the Squid

Re: [squid-users] HTTPS - THE PROXY SERVER IS REFUSING

2016-08-19 Thread adego70
Thank you for your help (both L.P.H. van Belle & Amos Jeffries). I changed my squid.conf but now, I don't obtain any url deny... In fact, any http & https url are allowed even if they not in whitelist_primaire. I made many tests but I can't find the good way... Please find enclosed the conf for

Re: [squid-users] Rock store status

2016-08-19 Thread Steve Hill
On 19/08/16 08:45, FredB wrote: Please can you describe your load and configurations ? We supply Squid based online safety systems to schools across the UK, utilising Rock store for caching and peek/splice, external ACLs and ICAP for access control/filtering/auditing. Typically I think our

Re: [squid-users] Squid 2.7.s9 HTTPS-proxying - hint welcome

2016-08-19 Thread Torsten Kuehn
Hi, On 18/08/2016 6:32 a.m., Amos Jeffries wrote: >> I imagine layouts where the encrypted traffic itself gets stored > no way for Squid to know if a previous encrypted stream is reusable. > To squid it is just a random stream of opaque bytes. Enlightening! The idea was that omitting decryption

Re: [squid-users] Problems with Squid Authentication

2016-08-19 Thread L . P . H . van Belle
Hai,   Yes, all new things are hard.. I need some extra info because there are lots of things that can be wrong.   post what you see here : /usr/lib/squid/negotiate_kerberos_auth -s HTTP/proxy.empresa.com...@empresa.com.br ?d ?i     >> kinit and klist are ok >> /etc/krb5.keytab and

Re: [squid-users] Squid automatically deleted the Proxy-Authenticate header

2016-08-19 Thread John Akhaice
Thank you for appling the patch to squid-4. I look forward to new version of the squid-3.5. And thank you very much for your prompt response. ___ squid-users mailing list squid-users@lists.squid-cache.org

Re: [squid-users] Rock store status

2016-08-19 Thread FredB
> > We use SMP and Rock under the 3.5 series without problems. But I > don't > think any of our sites have as high req/sec load as you. Thanks for your answer Please can you describe your load and configurations ? No crash ? Fred ___ squid-users

[squid-users] training

2016-08-19 Thread sallo baloch
dear sir how to learn squid proxy from scratch ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users