Re: [squid-users] Problem with HAProxy + Squid 4.11 + Kerberos authentication

2020-07-26 Thread Brett Lymn
bad). You merge the keytab for the machine with the keytab for the HA user. This way the clients are able to both auth to the HA and to the the underlying machine. It is what we do, it works fine. -- Brett Lymn This email has been sent on behalf of one of the following companies within the

Re: [squid-users] Problem with HAProxy + Squid 4.11 + Kerberos authentication

2020-07-23 Thread Brett Lymn
or header into the http traffic and then modified the logging to log both the loadblancer and client IP. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of companies: BAE Systems Australia Limited - Australian Company N

Re: [squid-users] whats wrong with this url regex line

2020-01-19 Thread Brett Lymn
an the whole string for a match. So if you know that the string you are looking for must be right at the start of the string then it is much better to use the ^ anchor to let the regex library know that. -- Brett Lymn This email has been sent on behalf of one of the following companies within the

Re: [squid-users] Squid 3.5.20 compile issue

2016-09-19 Thread LYMN
does a "ldd squid" output? You have built your openssl libraries to a non-standard place so perhaps squid cannot find them at run time? If this was the case then you either need to use LD_LIBRARY_PATH at run time or set LDFLAGS="-L/opt/openssl/lib -Wl,-R/opt/openssl/lib" at

Re: [squid-users] Squid 3.5.20 compile issue

2016-09-19 Thread LYMN
to me -- the linker > does not know that your OpenSSL library depends on another system > library that provides those [dynamic linking] functions. > At a guess add this to the libraries list after openssl: -ldl -- Brett Lymn This email has been sent on behalf of one of the follo

Re: [squid-users] kerberos authentication with a machine account doesn't work

2016-01-13 Thread LYMN
vide answers to all the questions that L.P.H. van Belle asked, this will give people a good picture of what your set up is like and where the problem may be. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of companies:

Re: [squid-users] kerberos authentication with a machine account doesn't work

2016-01-11 Thread LYMN
On Mon, Jan 11, 2016 at 09:06:27PM +1300, Amos Jeffries wrote: > On 11/01/2016 2:48 p.m., LYMN wrote: > > > > I did manage to get this working, you did mention the correct solution > > right down the end of your message. > > > > Correct for you yes. That can happ

Re: [squid-users] kerberos authentication with a machine account doesn't work

2016-01-10 Thread LYMN
quid-service user. You kan add all you squid > hosts/services in that user. > > I have 1 user for this and 3 proxy servers. > It does mean that one password change invalidates the keytab on 3 proxies... > > Optionaly, start the auth progrom on command line, with the debugging

[squid-users] kerberos authentication with a machine account doesn't work

2016-01-06 Thread LYMN
that this should not matter but clearly something is not agreeing with me. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of companies: BAE Systems Australia Limited - Australian Company Number 008 423 005 BAE

Re: [squid-users] Ssl-Bump and revoked server certificates

2015-10-20 Thread Brett Lymn
erating systems not conforming to Linux; > Only for linux sounds a bit specious - I can understand not for Windows but other unix operating systems should be close enough. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of c

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-15 Thread Brett Lymn
process demands do not exceed physical RAM then all will be fine, the file cache size will shrink and grow depending on process demands. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of companies: BAE Systems Australia

Re: [squid-users] Problems with squid 3.5.1

2015-02-11 Thread Brett Lymn
Though if you have a large cache then it will take a very long time to remove the files. If your cache is on a separate file system then it may be quicker and simpler just to unmount the file system and reinitialise it. -- Brett Lymn This email has been sent on behalf of one of the following

Re: [squid-users] squid rotating between many ips

2014-12-16 Thread Brett Lymn
the user to log in again. -- Brett Lymn This email has been sent on behalf of one of the following companies within the BAE Systems Australia group of companies: BAE Systems Australia Limited - Australian Company Number 008 423 005 BAE Systems Australia Defence Pty Limited - Australian Company