[squid-users] Ubuntu 18 LTS repository for Squid 4.6 (rebuilt with sslbump support from sources in Debian unstable)

2019-02-26 Thread Rafael Akchurin
Greeting all, The online repository with latest Squid 4.6 (rebuilt from Debian unstable with sslbump support) for Ubuntu 18 LTS 64-bit is available at squid46.diladele.com. Github repo at https://github.com/diladele/squid-ubuntu contains the scripts we used to make this compilation. Hope you w

[squid-users] Disable tls1.3 support , can't get SNI / cert details when it's used

2019-02-26 Thread Stilyan Georgiev
Hi, Squid 4.5 with openssl support here. SSL bumping can't obtain SNI / cert domain to perform filtering when tls1.3 is used. I want to disable support for tls1.3 in config but don't find way to do so. There's the outdated sslproxy_options config directive which doesn't appear to be supported

[squid-users] [squid-announce] Squid 4.6 is available

2019-02-26 Thread Amos Jeffries
The Squid HTTP Proxy team is very pleased to announce the availability of the Squid-4.6 release! This release is a security and bug fix release resolving several issues found in the prior Squid releases. The major changes to be aware of: * Fix several cases of rock cache corruption Several

Re: [squid-users] ICAP and 403 Encapsulated answers (SSL denied domains)

2019-02-26 Thread FredB
Yes, here my usage case 1- Squid as explicit proxy connected to e2guardian with ICAP 2 - E2guardian block a SSL website (no bump) a 403 header is returned -> I tried 302, 307, 200, without more success 3 - With IE or chrome the connection is well dropped but with FF (61 -> next 67) the conne

Re: [squid-users] Disable tls1.3 support , can't get SNI / cert details when it's used

2019-02-26 Thread Alex Rousskov
On 2/26/19 4:55 AM, Stilyan Georgiev wrote: > Squid 4.5 with openssl support here. > SSL bumping can't obtain SNI / cert domain to perform filtering when > tls1.3 is used. > I want to disable support for tls1.3 in config but don't find way to do > so. There's the outdated sslproxy_options config d

[squid-users] /64 ipv6

2019-02-26 Thread mzgmedia
hello it will be nice if will be possible to specify an entire /64 range on the squid config -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html ___ squid-users mailing list squid-users@lists.squid-cache.org htt

Re: [squid-users] /64 ipv6

2019-02-26 Thread Amos Jeffries
On 27/02/19 10:27 am, mzgmedia wrote: > hello > > it will be nice if will be possible to specify an entire /64 range on the > squid config > Squid uses CIDR for settings where ranges are relevant. If you are having a particular problem. Please state what that problem is, what you have tried doin

Re: [squid-users] /64 ipv6

2019-02-26 Thread mzgmedia
we want to add the entire /64 something like this acl A myip a::b:c/64 tcp_outgoing_address A a::b:c/64 -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html ___ squid-users mailing list squid-users@lists.squid

Re: [squid-users] /64 ipv6

2019-02-26 Thread Amos Jeffries
On 27/02/19 11:10 am, mzgmedia wrote: > we want to add the entire /64 > > something like this > > acl A myip a::b:c/64 > tcp_outgoing_address A a::b:c/64 > That directive is for selecting a src-IP address of IP packets that form a TCP connection. There can only ever be one src-IP per connecti

Re: [squid-users] Squid for Windows Repeatedly Crashing

2019-02-26 Thread Eliezer Croitoru
It depends on the hardware in the server grade Windows. It can take more then 3k conn's for 100%. It's possible that squid was not designed for windows 2k16 Eliezer On 2019-02-24 15:47, Rafael Akchurin wrote: As far as I know the internal FD limit for Windows build is around 3K - might be