[squid-users] SQUID + TOR

2017-12-19 Thread C. L. Martinez
Hi all, As Squid's wiki shows: https://wiki.squid-cache.org/ConfigExamples/Strange/TorifiedSquid, is it really needed to install privoxy to use squid as a proxy to access .onion domains? Is not possible to install only squid+tor an put the following: cache_peer localhostparent 9040 7

Re: [squid-users] Squid with SSL-Bump on Debian testing: SSL_ERROR_RX_RECORD_TOO_LONG

2017-03-04 Thread C. L. Martinez
On Sat, Mar 04, 2017 at 04:21:19AM +0600, Yuri Voinov wrote: > > > 04.03.2017 3:29, C. L. Martinez пишет: > > Hi all, > > > > After installing Squid 3.5.24 in my Debian testing (many thanks Amos for > > your help), I am trying to configure Squid as http

[squid-users] Squid with SSL-Bump on Debian testing: SSL_ERROR_RX_RECORD_TOO_LONG

2017-03-03 Thread C. L. Martinez
ox's browsers when I visit any web using https like https://www.debian.org, https://www.redhat.com, etc.. Some time ago, I have setup same config under OpenBSD and all works ok. Where am I doing the mistake? -- Greetings, C. L. Martinez ___ squid-user

[squid-users] Build errors with Squid 3.5.24 under Debian

2017-03-01 Thread C. L. Martinez
e-files --with-default-user=proxy --enable-ssl-crtd --enable-linux-netfilter --with-openssl Where am I doing the mistake?? -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] Trying to compile Squid-4 under OpenBSD 5.9

2016-08-12 Thread C. L. Martinez
default-user="_squid" --with-filedescriptors=8192 --with-krb5-config=no --with-pidfile="/var/run/squid.pid" --with-pthreads --with-swapdir=/var/squid/cache --sysconfdir=/etc/squid --localstatedir=/var/squid --disable-pf-transparent --enable-ipfw-transparent Do I need to pass anot

Re: [squid-users] A problem with a refresh pattern rule

2016-08-11 Thread C. L. Martinez
On Thu 11.Aug'16 at 22:38:13 +1200, Amos Jeffries wrote: > On 11/08/2016 7:04 p.m., C. L. Martinez wrote: > > Hi all, > > > > I am doing some modifications in refresh_patterns rules in a squid host > > (release 3.5.20) and it seems they are working, with the

[squid-users] A problem with a refresh pattern rule

2016-08-11 Thread C. L. Martinez
terns. Is this wrong?? Thanks. -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Sometimes Squid goes to 99% CPU use

2016-07-03 Thread C. L. Martinez
On Sat 2.Jul'16 at 15:50:56 +1200, Amos Jeffries wrote: > On 1/07/2016 10:18 p.m., C. L. Martinez wrote: > > On Fri 1.Jul'16 at 21:42:23 +1200, Amos Jeffries wrote: > >> On 1/07/2016 8:39 p.m., C. L. Martinez wrote: > >>> Hi all, > >>> > >>&

Re: [squid-users] Sometimes Squid goes to 99% CPU use

2016-07-01 Thread C. L. Martinez
On Fri 1.Jul'16 at 21:42:23 +1200, Amos Jeffries wrote: > On 1/07/2016 8:39 p.m., C. L. Martinez wrote: > > Hi all, > > > > I am seeing an abnormal behavior in my squid host (OpenBSD). From time to > > time, CPU goes to 99%: > > > > load averages: 2

[squid-users] Sometimes Squid goes to 99% CPU use

2016-07-01 Thread C. L. Martinez
ssl-bump config is: acl step1 at_step SslBump1 ssl_bump peek step1 ssl_bump bump !NoSSLIntercept ssl_bump splice all Exists some "safer" ssl-bump config to avoid this behavior? Thanks. -- Greetings, C. L. Martinez ___ squid-users mailing

Re: [squid-users] Problems with ACL's using squid as intercept proxy

2016-06-29 Thread C. L. Martinez
On Wed 29.Jun'16 at 13:11:20 +1200, Amos Jeffries wrote: > On 29/06/2016 2:18 a.m., C. L. Martinez wrote: > > I have configured new PF rules in this new FreeBSD host: > > > > rdr pass on $vpnif proto tcp from $int_network to any port http tag > > intla

[squid-users] Problems with ACL's using squid as intercept proxy

2016-06-28 Thread C. L. Martinez
ww.osnews.com/favicon.ico - ORIGINAL_DST/127.0.0.1 text/html .. What is the problem?? Are ACL's wrong?? Why?? At first stage, I was thinking about a problem with the pf rules ... but, now, I am not sure because packets arrives to squid ... Any idea?? Thanks. -- Greetings, C

Re: [squid-users] Cipher suites errors

2016-06-27 Thread C. L. Martinez
Thanks Yuri. On Mon 27.Jun'16 at 19:39:20 +0600, Yuri wrote: > This is GOST-based ciphers included in LibreSSL. Don't worry about it. > > > 27.06.2016 19:30, C. L. Martinez пишет: > > Hi all, > > > > After some tunning to configure my squid's host with ssl_bump

[squid-users] Cipher suites errors

2016-06-27 Thread C. L. Martinez
?? I am using squid's wiki suggested config ... Thanks. -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Problem with certificates and SSLBump

2016-06-25 Thread C. L. Martinez
On Sun 26.Jun'16 at 5:22:31 +1200, Amos Jeffries wrote: > On 26/06/2016 4:46 a.m., C. L. Martinez wrote: > > On Sat 25.Jun'16 at 22:33:56 +0600, Yuri Voinov wrote: > >> > >> -BEGIN PGP SIGNED MESSAGE- > >> Hash: SHA256 > >> > >>

Re: [squid-users] Problem with certificates and SSLBump

2016-06-25 Thread C. L. Martinez
gt; Is this the thread: http://marc.info/?l=squid-users=146625379320785=2? -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] Problem with certificates and SSLBump

2016-06-25 Thread C. L. Martinez
phic curve (secp384r1 for CA and prime256v1 for host's certifcates). Maybe is this the problem? Why when I use self-signed certificate all works ok and not when I sign squid's certificate with my Internal CA? Thanks. -- Greetings, C. L. Martinez ___ squid-use

Re: [squid-users] Problems configuring Squid with C-ICAP+Squidclamav (SOLVED)

2016-05-12 Thread C. L. Martinez
On Thu 12.May'16 at 22:20:47 +1200, Amos Jeffries wrote: > On 12/05/2016 8:42 p.m., C. L. Martinez wrote: > > On Wed 11.May'16 at 21:14:08 +0600, Yuri Voinov wrote: > >> > >> -BEGIN PGP SIGNED MESSAGE- > >> Hash: SHA256 > >> >

Re: [squid-users] Problems configuring Squid with C-ICAP+Squidclamav (SOLVED)

2016-05-12 Thread C. L. Martinez
pass=off icap_service service_avi_resp respmod_precache icap://127.0.0.1:1344/squidclamav bypass=on all works as expected. As you can see I have changed "localhost" for "127.0.0.1" ... localhost entry exists inside my /etc/hosts file, and OpenBSD resolves correctly, but under unbound's config I have enabled "do-not-query-localhost: no" because unbound is configured to work with dnscrypt-proxy service... I am not sure about this, but it is the only answer that explains this problem ... or it is a bug (but I don't think so). What do you think?? -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Problems configuring Squid with C-ICAP+Squidclamav

2016-05-12 Thread C. L. Martinez
ver stats: Children: 3 Free servers: 30 Used servers:0 Requests served:0 I don't see any errors ... Maybe squid can't connect to ICAP service?? But all services are running in the same machine -- Greetings, C. L. Martinez __

Re: [squid-users] Problems configuring Squid with C-ICAP+Squidclamav

2016-05-11 Thread C. L. Martinez
fault version for OpenBSD 5.9 -- Greetings, C. L. Martinez ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] Problems configuring Squid with C-ICAP+Squidclamav

2016-05-11 Thread C. L. Martinez
-icap/access.log Logger file_logger Module logger sys_logger.so Service squidclamav squidclamav.so Any idea what am I doing wrong?? How can I do a simple test against c-icap server from command line?? Thanks. -- Greetings, C. L. Martinez ___ squid-users