Re: [squid-users] Problem with Kerberos and ext_kerberos_ldap_group_acl not being able to reach realm's KDC

2016-09-20 Thread Silamael
On 20.09.2016 15:20, Silamael wrote: > Ok, found one problem. Under OpenBSD I had some hack that the external > helper was linked against libbind (the bind resolver library) instead of > libc (as the helper uses some defines which have different names in the > OpenBSD libc). This caused that the He

[squid-users] Squid for proxy server on Google Compute Engine?

2016-09-20 Thread Chuong Hoang
Hi guys, thanks for reading this! I’m new so sorry if this is a dumb question! But I've been finding the answer for 3 days but still no sign of light. I’ve already posted the problem on GCE discussion group- this link: https://groups.google.com/forum/#!topic/gce-discussion/xwlHYhFTUtU To make i

Re: [squid-users] SSO and Squid, SAML 2.0 ?

2016-09-20 Thread Kinkie
Hi Fred, I assume that by "implicit" you mean "transparent" or "interception". Short answer, not possible: there is nothing to anchor cookies to. It could be possible to fake it by having an auxiliary website doing standard SAML and feeding a database of associations userid-ip. It will fail to ac

Re: [squid-users] Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-09-20 Thread erdosain9
Hi. I have this in cache.log Starting new ssl_crtd helpers... 2016/09/20 16:30:15 kid1| helperOpenServers: Starting 1/8 'ssl_crtd' processes 2016/09/20 16:30:15 kid1| Error negotiating SSL on FD 28: error:1409F07F:SSL routines:SSL3_WRITE_PENDING:bad write retry (1/-1/0) 2016/09/20 16:30:16 kid1| E

Re: [squid-users] Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-09-20 Thread Hardik Dangar
It looks like server failure, this could be due to isp snooping connection at upper level or google.com.ar servers are broken temporarily. see similar issue http://lists.squid-cache.org/pipermail/squid-users/2014-October/000562.html On Wed, Sep 21, 2016 at 12:12 AM, erdosain9 wrote: > Hi, > Im

[squid-users] Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-09-20 Thread erdosain9
Hi, Im having this error randomly. This is traying access google.com The following error was encountered while trying to retrieve the URL: https://www.google.com.ar/* Failed to establish a secure connection to 172.217.28.227 The system returned: (71) Protocol error (TLS code: SQUID_ERR_SSL

Re: [squid-users] SSO (kerberos)

2016-09-20 Thread erdosain9
Ok, Well i have this settings - *cat /etc/sysconfig/squid *# Kerberos autenticacion KRB5_KTNAME=/etc/squid/PROXY.keytab export KRB5_KTNAME # # default squid options SQUID_OPT

Re: [squid-users] Problem with Kerberos and ext_kerberos_ldap_group_acl not being able to reach realm's KDC

2016-09-20 Thread Silamael
On 19.09.2016 13:39, Silamael Darkomen wrote: > > > On 16.09.2016 22:11, Markus Moeller wrote: >> Hi Silamael, >> >> Can you perform a kinit u...@example.com ? Does the squid user >> have read access to krb5.conf ? >> >> Markus > > Hello Markus, > > Yes, the permissions are correctly set

Re: [squid-users] squid https intercept mode and ubuntu third party repositories issue

2016-09-20 Thread Hardik Dangar
Amos, Thank you for your reply. I have version 3.5.12 compiled with Debian rules example provided here, http://docs.diladele.com/administrator_guide_4_5/install/ubuntu14/tools.html Do you think I could patch squid from 3.5.12 to 3.5.21 via patches available at http://www.squid-cache.org/Versions/v

Re: [squid-users] squid https intercept mode and ubuntu third party repositories issue

2016-09-20 Thread Amos Jeffries
On 20/09/2016 4:42 a.m., Hardik Dangar wrote: > Hello, > > I am using squid 3.5.12(detailed version info is below) on Ubuntu 16.04.1 > LTS server. My squid config is at, http://pastebin.com/raw/b8RZ67u9 > > I have configured squid as intercept proxy bumping all SSL https > connections. Setup is w

Re: [squid-users] Squid 3.5.20 compile issue

2016-09-20 Thread Amos Jeffries
On 20/09/2016 1:35 p.m., LYMN wrote: > On Mon, Sep 19, 2016 at 07:20:14PM -0600, James Lay wrote: >> >> Well last word on this...squid starts but dies with: >> /squid: symbol lookup error: ./squid: undefined symbol: >> SSL_set_alpn_protos >> So at this point I'll just go back to linking to libressl

Re: [squid-users] Web Whatsapp, Dropbox... problem

2016-09-20 Thread Amos Jeffries
On 20/09/2016 6:12 a.m., Jok Thuau wrote: > On Mon, Sep 19, 2016 at 10:39 AM, erdosain9 wrote: > >> mm >> so... >> i think this is working for non take the certificate >> >> acl step1 at_step SslBump1 >> acl excludeSSL ssl::server_name_regex web/.whatsapp/.com >> > > wrong slashes...

Re: [squid-users] SSO and Squid, SAML 2.0 ?

2016-09-20 Thread FredB
I forgot, if possible a method without active directory ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] SSO and Squid, SAML 2.0 ?

2016-09-20 Thread FredB
Hello All, I'm searching a way to use a secure SSO with Squid, how did you implement the authenticate method with an implicit proxy ? I'm reading many documentations about SAML, but I found nothing about Squid I guess we can only do something with cookies ? Anyone know if it's possible? Tha