Hello,
does Squid 2.5STABLE5 support native NTLM authentication with Samba 3
through its own ntlm_auth helper or does it still need the helper provided
by Samba?
Is there an external acl in this new version that matches NT group
membership with Samba 3 (wb_group, etc) and not only with Samba
I get the following error message when I run squid -NCd1 and try to log on
the the internet. Any ideas why?
FATAL: The basicauthenticator helpers are crashing too rapidly, need help!
This email and any file transmitted with it is confidential and may also be legally
privileged. It is intended
I have used the wbinfo_group.pl that comes with Redhat Linux Enterprise
v3.
I have modified the debug section to get the output on the screen.
If I type in ./wbinfo_group.pl from the command line, then
Type in domain/user
I get
Got USER from squid
Then it just sits there.
I would
I get the following error message when I run squid -NCd1 and
try to log on
the the internet. Any ideas why?
FATAL: The basicauthenticator helpers are crashing too
rapidly, need help!
What's in cache.log when this happens ?
M.
Hi
I configured ntlm-auth and basic-auth in my squid proxy, and I´m unable to
download any applet, via http or https. I searched the archives and could
not find anything about this problem.
Did I do something wrong in my config files?
The relevant part of my squid.conf is
auth_param ntlm
Hi,
How can i check if my squid version supports winbind.
Thanks.
Hello there,
I was wondering if NTLM was the only way to do Single Sign On with Squid ?
Thx for any answer.
--
Stephane DESMET
Responsable produits de sécurité
All Computing SAS
17, rue du Colisée - 75008 Paris
France
(+33)1 49 53 90 36
(+33)6 88 82 55 87
internet: www.allcomputing.fr
On Mon, 15 Mar 2004, Sarky wrote:
An Example of what the line in access.log looks like
1079309099.848399 192.116.121.80 TCP_MISS/403 1468 GET
http://members.fortunecity.com/noops043a/jenna_bush002.jpg -
DIRECT/216.27.93.20 text/html
This line tells that yur Squid access controls allowed
Please upgrade. There was a number of NTLM patches after 2.5.STABLE4 and
things got stable only some weeks before 2.5.STABLE5 was released.
Regards
Henrik
On Mon, 15 Mar 2004, Andrej G. Zadorozhnyj wrote:
My Squid 2.5 Stable 4 port revision 10 for FreeBSD 4.9 often has crash with
next
Rename cachemgr.cgi to cachemgr.exe
Regards
Henrik
On Mon, 15 Mar 2004, Altrock, Jens wrote:
Hi Folks,
Again it's me. Got a little problem using cachemgr.cgi on an XAMPP
installation running under Win2000, also script doesn't work on IIS 5.0
using Squid 2.5STABLE5.
I first tried using
On Mon, 15 Mar 2004 [EMAIL PROTECTED] wrote:
does Squid 2.5STABLE5 support native NTLM authentication with Samba 3
through its own ntlm_auth helper or does it still need the helper provided
by Samba?
You SHOULD use the ntlm_auth helper provided as part of Samba.
The winbind helpers provided
On Mon, 15 Mar 2004, DeSwardt, Gert (Lyn) wrote:
I get the following error message when I run squid -NCd1 and try to log on
the the internet. Any ideas why?
FATAL: The basicauthenticator helpers are crashing too rapidly, need help!
Your auth_param basic program setting is not correct, or
On Mon, 15 Mar 2004, Martin, Neil wrote:
I have modified the debug section to get the output on the screen.
If I type in ./wbinfo_group.pl from the command line, then
Type in domain/user
group helpers expects
domain\\user groupname
as input.
Regards
Henrik
On Mon, 15 Mar 2004, Bilal Dar wrote:
Hi,
How can i check if my squid version supports winbind.
squid -v
or try to configure the ntlm scheme in your squid.conf and run squid -k
parse.
Note: What your Squid binary needs to support is the ntlm scheme. Then in
addition you need suitable
Ok, I've given up after a week and restarted squid using ufs
today at 13:30 in France.
Now, MRTG graphs are showing a lower CPU usage for our squid proxy,
as cachemgr.cgi (CPU Usage, 60 minute avg: 23.25%) and vmstat:
vmstat 1 10
Virtual Memory Statistics: (pagesize = 8192)
procs memory
Hello Christoph,
Thanks for your reply.
However, it still doesn't work.
I tried to add the subnet mask by the end of the acl line as below, but then
access is given to all IPs in the network:
acl subgroup src 120.202.200.20/255.255.255.0
Any other hint?
Thanks + Regards,
- Original Message -
From: Denis Vlasenko [EMAIL PROTECTED]
To: Jrgen Hovland [EMAIL PROTECTED]; Henrik Nordstrom [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Sent: Monday, March 15, 2004 6:39 AM
Subject: Re: [squid-users] invalid url
On Monday 15 March 2004 03:56, Jrgen Hovland wrote:
Lo all,
I seem to not understand always_direct / never_direct properly
acl local src 66.18.x.x/29
cache_peer a.a.a.a parent 3128 0 no-query no-digest no-netdb-exchange
round-robin
cache_peer b.b.b.b parent 3128 0 no-query no-digest no-netdb-exchange
round-robin
cache_peer c.c.c.c parent 3128
On Mon, 15 Mar 2004, Braden Manning wrote:
I can't for example, go to yahoo.com's email site and upload an attachment greater
than around
500k or so.
Upgrade or see squid.conf.
Squid-2.4 and earlier has a default limit of 1 MB. The default was changed
to unlimited in Squid-2.5 and later.
OK,
Nevermind, I saw my fault on the ACL and it's working nicely now :))
Thanks,
- Original Message -
From: Chris Knipe [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, March 15, 2004 4:24 PM
Subject: always/never_direct
Lo all,
I seem to not understand always_direct /
acl subgroup src 120.202.200.20/255.255.255.0
Any other hint?
Thanks + Regards,
Fernanda
===
On 14 Mar 2004, Christoph Haas wrote:
On Sun, Mar 14, 2004 at 03:06:54PM -0300, [EMAIL PROTECTED] wrote:
I have the following configuration:
Henrik Nordstrom wrote:
On Mon, 15 Mar 2004, Martin, Neil wrote:
I have modified the debug section to get the output on the screen.
If I type in ./wbinfo_group.pl from the command line, then
Type in domain/user
group helpers expects
domain\\user groupname
Besides, there is a documented bug
Hello,
I am trying to build a squid server on solaris 8 for wccp, but It doesn't
seems to work yet, here is what I did so far and I am hoping someone can
point out the problem:
1. compiled squid 2.5STABLE5 with enable-ipf-transparent, the squid is
configured so that it redirects all request
I have managed to get a stage further, and I can now use
wbinfo_group.pl from the command line.
It still gives me an access denied message from SQUID.
Any Ideas?
Thanks
-Original Message-
From: Martin, Neil
Sent: 15 March 2004 11:25
To: '[EMAIL PROTECTED]'
Subject: Squid 2.5 STABLE
On Sun, 14 Mar 2004 01:32:33 +0100 (CET)
Henrik Nordstrom [EMAIL PROTECTED] wrote:
On Sun, 14 Mar 2004, Ilya wrote:
Can squid communicate with socks-servers?
(socks-client --- socks --- squid)
Depends on the socks server. If the socks server supports
forwarding of
HTTP requests to a HTTP proxy
The network guy told me that the cisco router sees the wccp server (my squid
server) ok and they can communicate, but when I open a web browser on a
server which connects to this cisco router, it just times out every time. It
didn't get to the redirected URL as I wanted. ( I was snooping on
Hi all !!!
I have read the Squid-Mib but i cant understand the difference between
-cacheProtoClientHttpRequests
and
-cacheServerRequests
Can someone help me?
One more question, How does the cacheclients calculate the number of clients
accessing cache ?
Thanks
Diego
On Mon, 15 Mar 2004, [utf-8] Jørgen Hovland wrote:
0x00c0 352e 313b 202e 4e45 5420 434c 5220 312e5.1;..NET.CLR.1.
0x00d0 312e 3433 3232 290d 0a48 6f73 743a 20771.4322)..Host:.w
0x00e0 2e6a f872 6765 6e2e 6e75 0d0a 436fww.j.rgen.nu..Co
This is cleary an
Henrik Nordstrom wrote:
On Fri, 12 Mar 2004 [EMAIL PROTECTED] wrote:
So: is it possible, using Squid, LDAP server, and a browser that supports NTLM,
to authenticate user, so that no pop-up 'username + password' window shows up?
No, but it is fully possible to use Squid + Active Directory + a
Hi,
At 14.52 15/03/2004, Henrik Nordstrom wrote:
Rename cachemgr.cgi to cachemgr.exe
Not sure that this is the problem:
I'm running cachemgr.cgi without any problems on IIS 5.0 and Apache for
Windows.
No special configuration is needed.
Are You sure that your binaries are not corrupted ?
Hi all, I am using Squid 2.5.4-3 on linux, I am using squidguard as redirector to
block all windows executables, all is working fine except for some webs that bypass
squid, the .exe file dont show in the log files and the user can download it using
the browser.
The only log squid generates is:
My squid is really slow.
Your Squid is probably slow because the disk is a bottleneck with
UFS storage scheme.
When you switched to diskd, you allowed Squid to become much more
efficient. Response time probably went down, but CPU usage went
up. Higher CPU usage is not necessarily a bad thing.
On Mon, 15 Mar 2004, Chris Knipe wrote:
Lo all,
I seem to not understand always_direct / never_direct properly
acl local src 66.18.x.x/29
cache_peer a.a.a.a parent 3128 0 no-query no-digest no-netdb-exchange
round-robin
cache_peer b.b.b.b parent 3128 0 no-query no-digest
Henrik,
If you were getting these errors, how would you T-shoot this
I just built this box about two weeks ago. It has 4 separate diskd stores for cache. I
get about 20 - 30 WARNING: failed to unpack meta data messages per MINUTE in the
cache.log file. I have rebuilt the cache several
ipnat config file:
rdr bge0 0.0.0.0/0 port 80 - 167.206.45.99 port 8080 tcp
output for ipnat -l:
#ipnat -l
List of active MAP/Redirect filters:
rdr bge0 0.0.0.0/0 port 80 - 167.206.45.99 port 8080 tcp
List of active sessions:
The network guy told me that the cisco router sees the wccp
On Mon, 15 Mar 2004, galle wrote:
Hi all !!!
I have read the Squid-Mib but i cant understand the difference between
-cacheProtoClientHttpRequests
This is # requests received from clients
and
-cacheServerRequests
This is # requests forwarded to servers.
Their difference is
On Mon, 15 Mar 2004, Mark Pelkoski wrote:
Henrik,
If you were getting these errors, how would you T-shoot this
I just built this box about two weeks ago. It has 4 separate diskd
stores for cache. I get about 20 - 30 WARNING: failed to unpack
meta data messages per MINUTE in the
On Mon, 15 Mar 2004, Mark Pelkoski wrote:
Henrik,
If you were getting these errors, how would you T-shoot this
I just built this box about two weeks ago. It has 4 separate diskd
stores for cache. I get about 20 - 30 WARNING: failed to unpack
meta data messages per MINUTE in the
On Mon, 15 Mar 2004, Stephane DESMET wrote:
I was wondering if NTLM was the only way to do Single Sign On with Squid ?
It is about the only viable Single Sign On function available in the web
browsers.
Other options are basically to allow the browser to store the proxy
password in its key
On Mon, 15 Mar 2004 [EMAIL PROTECTED] wrote:
Hello Christoph,
Thanks for your reply.
However, it still doesn't work.
I tried to add the subnet mask by the end of the acl line as below, but then
access is given to all IPs in the network:
acl subgroup src
On Mon, 15 Mar 2004, James Zhao wrote:
I am trying to build a squid server on solaris 8 for wccp, but It doesn't
seems to work yet, here is what I did so far and I am hoping someone can
point out the problem:
Have you loaded the WCCP kernel module?
There is a WCCP kernel module for Solaris
On Mon, 15 Mar 2004, Ilya wrote:
Do you know such socks servers (with forwarding of HTTP
requests to a HTTP proxy)?
Dante is said to support this as from version 1.1.3 (2000-09-25), even
mentioning Squid in the documentation of the feature :-)
Regards
Henrik
On Mon, 15 Mar 2004, galle wrote:
Hi all !!!
I have read the Squid-Mib but i cant understand the difference between
-cacheProtoClientHttpRequests
and
-cacheServerRequests
The comment on cacheServerRequests is wrong.. it is the number of requests
forwarded by the cache server, the number
On Mon, 15 Mar 2004, Tomasz Chmielewski wrote:
Currently everyone is authenticated through squid_ldap_auth first, then
squid_ldap_group, so that everyone could match his/her own acl.
User+pass windows pops up.
In order to get rid of that pop-up windows:
1) Does that mean that I have to
On Tue, 16 Mar 2004, Henrik Nordstrom wrote:
2) Does that mean, that I have to remove squid_ldap_auth from the config
file, as authentication would be done by Samba?
squid_ldap_auth will then be replaced by the Samba helper for Basic http
authentication.
Or actually, you can keep
-Original Message-
From: Mark Pelkoski
Sent: Monday, March 15, 2004 4:35 PM
To: 'Duane Wessels'
Duane,
Thank you for your response! I have a 34% hit rate. About the same
for
the server that is not producing these errors.
We can start to narrow it down with the attached patch.
On Mon, 15 Mar 2004, Luis Miguel wrote:
Hi all, I am using Squid 2.5.4-3 on linux, I am using squidguard as redirector to
block all windows executables, all is working fine except for some webs that
bypass squid, the .exe file dont show in the log files and the user can download
it using
On Mon, 15 Mar 2004, henrique lima wrote:
Hi,
I´m a user of squid 2.5 with linux and I´d like to
know how to configure to restrict some sites between
hours.
See the time acl.
Regards
Henrik
Hi to all!
Im new in this, i want to install the squid in my network
and i have a rules like this
# ACCESS CONTROLS
#
-
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src
Hi,
I'm trying to compile the latest stable build of squid on my redhat 7 box.
Installed latest version of GCC and its associated libraries.
When I run ./configure it gives me the error message below.
[EMAIL PROTECTED] squid-2.5.STABLE5]# ./configure
loading cache ./config.cache
checking for a
- Original Message -
From: tonahtiu ramirez [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, March 16, 2004 7:10 AM
Subject: [squid-users] acl newbie
Hi to all!
Im new in this, i want to install the squid in my network
and i have a rules like this
# ACCESS CONTROLS
#
I can't find this crt1.o file on my box. I've had a browse on the innernet for some
help. They say its a lib file associated to gcc or something to that effect, and
find the libgcc rpm and install it, but I'm not convinced
Anyway, any simple ideas???
I'm not a linux expert, but it
Hi,
I am trying to configure squid_ldap_auth for my squid proxy, Before
changing the squid.conf file for LAP authentication, i want to try the
command from command prompt for its functionality.
My command as below:
squid_ldap_auth -p -R -b dc=my,dc=domain -D
cn=squid,cn=users,dc=my,dc=domain -w
Dear all,
I have a box with 2 CPU Xeon 2.4Ghz +1GB RAM. I've installed redhat 9 +squid
with wccpv2. It' s ok :) (120reqs/s). Can I install 2 instance squid with
wccpv2 on the same box and how to do that?
Please help me!!!
Thanks
Dinh
braden,
on redhat 7.3 later, crt1.o is part of glibc-devel.
you can use this command to verify (redhat 7.3):
rpm -qlp glibc-devel-2.2.5-34.i386.rpm | grep crt1.o
hope this helps.
Braden Manning wrote:
Hi,
I'm trying to compile the latest stable build of squid on my redhat 7 box.
--- Henrik Nordstrom [EMAIL PROTECTED] wrote:
On Fri, 12 Mar 2004, Mark Tinka wrote:
--- Henrik Nordstrom [EMAIL PROTECTED] wrote:
On Fri, 12 Mar 2004, Mark Tinka wrote:
this is, indeed, the case.. my cache server is
situated right between my border and core
routers..
I was sure until you mentioned that ;)
No, just kidding, I am not at all sure now. But strange is that there comes
a user/password/domain
dialog box after renaming the file to .exe and trying to access the cachemgr
via browser.. anyway
I have full permissions on that file on IIS 5...
Strange is
57 matches
Mail list logo