RE: [squid-users] squid mib file

2004-05-05 Thread Elsen Marc
> Hi, > > Where can I obtain the latest squid mib file for SNMP monitoring? > > Thanks, > Kurup Following the 'unpacked directory' : .../src/mib.txt M.

[squid-users] squid mib file

2004-05-05 Thread Hari Kurup
Hi, Where can I obtain the latest squid mib file for SNMP monitoring? Thanks, Kurup

[squid-users] squid mib file

2004-05-05 Thread Hari Kurup
Hi, Where can I obtain the latest squid mib file for SNMP monitoring? Thanks, Kurup

[squid-users] assertion failed

2004-05-05 Thread Danish Khan
My squid almost dies after every 15 mins giving the below error. assertion failed: errorpage.c:292: "mem->inmem_hi == 0" Using squid stable 5 on Sun Linux. I have found its patch kindly tell me how to apply its patch. Danish khan

Re: [squid-users] Squid + SSL CA.

2004-05-05 Thread Henrik Nordstrom
On Wed, 5 May 2004, Ivan Doitchinov wrote: > I am using squid V2.5.STABLE1 on Red Hat linux and I am trying to set up > an SSL proxy (CONNECT method). It all works fine except that I can't > figure out how to add my own CA certificate in order to prevent a TLS > Unkonwn CA fatal error. ??? CA

RE: [squid-users] Blocking Porn sites....

2004-05-05 Thread Henrik Nordstrom
On Thu, 6 May 2004, Babar Kazmi wrote: > Dear David > > In "/tmp/forbidden_url.txt" file try using > > sanggrahan.org > 66.98.190.156 You can't use IP addresses in an dstdomain ACL. See squid.conf notes. Regards Henrik

Re: [squid-users] Blocking Porn sites....

2004-05-05 Thread Henrik Nordstrom
On Thu, 6 May 2004, David Kandou wrote: > How to block porn site like : > http://sanggrahan.org > http://66.98.190.156 > > in squid conf i wrote : > > acl xxx1 dstdomian "/tmp/forbidden_url.txt" dstdomain, not dstdomian.. and this matches destination hosts, not URLs. acl xxx1 dstdomain "/tm

Re: [squid-users] Proxy.pac Port

2004-05-05 Thread Henrik Nordstrom
On Thu, 6 May 2004, Matt wrote: > Is there a way with proxy.pac file to redirect all port 80 traffic to a > proxy but not any other traffic? > > function FindProxyForURL(url, host) > { > if (url.substring(0, 5) == "http:") { try replace that line by if (url.port = 80) { Not sur

RE: [squid-users] RE: Re: HOWTO use W2K groups for access?

2004-05-05 Thread Joost Kraaijeveld
Hi Adam, Thanks for your help. With a minor adjustent it works. The final solution was to put the group name in a separate file as per the readme in the source for winbind_group (the groupname contains a space). Groeten, Joost Kraaijeveld Askesis B.V. Molukkenstraat 14 6524NB Nijmegen tel: 024

RE: [squid-users] problem startup squid

2004-05-05 Thread Elsen Marc
> > I am with big problem, when i try start the squid the following error > occurs. > > User-Agent logging is disabled. > Referer logging is disabled. > Unlinkd pipe opened on FD 14 > assertion failed: StatHist.c:73: "val_in(max - min) > 0" > > what it will be that is happening? > > Thank

RE: [squid-users] xdr_string: out of memory

2004-05-05 Thread Elsen Marc
>and squid version is an old 2.4 stable 1 Try, if at all possible, to use the latest stable release. M.

RE: [squid-users] xdr_string: out of memory

2004-05-05 Thread Elsen Marc
>hi marc >its on console. >if i type any command, i get this msg. >just before server froze up i had the following output to /var/log/messages >May 5 15:34:48 maia kernel: Unable to handle kernel NULL pointer dereference at > virtual address 0062 >May 5 15:34:48 maia kernel: printing e

Re: [squid-users] Re: VirusWall and Squid ACL

2004-05-05 Thread Henrik Nordstrom
On Wed, 5 May 2004, Norman Zhang wrote: > cache_peer 127.0.0.1 parent 80 7 default no-query > > 2004/05/05 15:51:41| Detected REVIVED Parent: 127.0.0.1/80/7 > 2004/05/05 15:54:23| TCP connection to 127.0.0.1/80 failed > 2004/05/05 15:54:23| TCP connection to 127.0.0.1/80 failed Looks like the se

Re: [squid-users] Re: command for authentification Basic

2004-05-05 Thread Henrik Nordstrom
On Wed, 5 May 2004, Adam Aube wrote: > Flavio Borup wrote: > > > How can i authenticate to my regular /etc/passwd - /etc/shadow? > > I'd prefer to use my regular user accounst crated in my passwd/shadow > > files instead another file to manage > > Try either the PAM or getpwnam basic auth helper

RE: [squid-users] Blocking Porn sites....

2004-05-05 Thread Babar Kazmi
Dear David In "/tmp/forbidden_url.txt" file try using sanggrahan.org 66.98.190.156 Please ignore www or http:// , this will block the whole site even if it starts with www or http:// or anything. Regards, Babar Kazmi >Dear all, > >How to block porn site like : >http://sanggrahan.org >http

[squid-users] Proxy.pac Port

2004-05-05 Thread Matt
Is there a way with proxy.pac file to redirect all port 80 traffic to a proxy but not any other traffic? function FindProxyForURL(url, host) { if (url.substring(0, 5) == "http:") { return "PROXY my.proxy:8080"; } else { return "DIRECT"; } } for instance

Re: [squid-users] Blocking Porn sites....

2004-05-05 Thread Murugan
Hello, in "/tmp/forbidden_url.txt" file : you simply use playboy.com penthouse.com sanggrahan.org 66.98.190.156 don't mention www or https:// this will block the site whether it starts with www or http:// or whatever it is. Regards, -Murugan. - Original Message - From: "David Kand

[squid-users] ACL Problem

2004-05-05 Thread David Kandou
Dear all, How to block porn site like : http://sanggrahan.org http://66.98.190.156 in squid conf i wrote : acl xxx1 dstdomian "/tmp/forbidden_url.txt" http_access deny xxx1 in "/tmp/forbidden_url.txt" file : www.playboy.com www.penthouse.com http://sanggrahan.org http://66

[squid-users] Blocking Porn sites....

2004-05-05 Thread David Kandou
Dear all, How to block porn site like : http://sanggrahan.org http://66.98.190.156 in squid conf i wrote : acl xxx1 dstdomian "/tmp/forbidden_url.txt" http_access deny xxx1 in "/tmp/forbidden_url.txt" file : www.playboy.com www.penthouse.com http://sanggrahan.org http://66.98.190.1

Re: [squid-users] Squid in CPAN

2004-05-05 Thread Jose Nathaniel Nengasca
I think i have not driven my question to the right road, what i want to know if theres a site or a program (now or in the future) that has the ability to update squid on-demand (other than up2date from redhat) without actually getting your hands dirty in downloading and re-compiling from the source

[squid-users] Re: VirusWall and Squid ACL

2004-05-05 Thread Norman Zhang
Hi Herman, Herman (ISTD) wrote: I have installed Interscan Viruswall and Squid on the same box. It worked perfectly though in Trial version, automatic virus pattern update cannot work. My squid is running on 3128 port, and my Interscan is running on 80 port. Just redirect squid request to Intersca

[squid-users] RE: Re: HOWTO use W2K groups for access?

2004-05-05 Thread Adam Aube
Adam Aube wrote: > Something like this should work for you: > > external_acl_type NTGroup %LOGIN /path/to/wbinfo_group.pl > acl auth_users NTGroup "Domain Admins" > http_access allow auth_users Correction - the acl line should be acl auth_users external NTGroup "Domain Admins" ...as is shown i

[squid-users] Accelerating HTTPS + SSL

2004-05-05 Thread sampei02
How Squid accelerator (with SSL patch) treat https requests ? I know when client initiates ssl connection with web server it sends SSL version and other information, server answers sending its certificate which client will' verify its authentication to detect server identity. Then it's created cry

[squid-users] Squid Accelerator + SSL

2004-05-05 Thread sampei02
About Windows Update caching with Squid acccelerator + SSL update: I'd like understanding how this SSL patch works; when client browser runs https request to Squid acc. , it's possibile to redirect request to Microsoft Windows Update in the same way as Proxy server regardless of https content ?! S

[squid-users] RE: Re: HOWTO use W2K groups for access?

2004-05-05 Thread Adam Aube
Joost Kraaijeveld wrote: > All I want is that Squid checks whether the user that wants a page is > member of a certain group (Domain Admins). I have the wbinfo_groups.pl > installed in /usr/bin. I have installed Debian Sarge, kernel 2.6.3-1-686, > Samba 3.0.2a-Debian, Winbindd version 3.0.2a-Debia

RE: [squid-users] Re: HOWTO use W2K groups for access?

2004-05-05 Thread Joost Kraaijeveld
Hi all, I have tried all sorts of things. Too many to mention, but I pretend to have read all messages relating to my problem (and than some) and have not foud the answer. All I want is that Squid checks whether the user that wants a page is member of a certain group (Domain Admins). I have the

[squid-users] Re: command for authentification Basic

2004-05-05 Thread Adam Aube
Flavio Borup wrote: > How can i authenticate to my regular /etc/passwd - /etc/shadow? > I'd prefer to use my regular user accounst crated in my passwd/shadow > files instead another file to manage Try either the PAM or getpwnam basic auth helpers. Adam

Re: [squid-users] command for authentification Basic

2004-05-05 Thread Flavio Borup
How can i authenticate to my regular /etc/passwd - /etc/shadow? I'd prefer to use my regular user accounst crated in my passwd/shadow files instead another file to manage - Original Message - htpasswd -cb /your/password/file username password htpasswd -b /your/password/file username passw

RE: [squid-users] Squid ACL's or SquidGuard

2004-05-05 Thread Angela Burrell
Hi Jerry I don't know if anyone answered your question or not but I use squidGuard, it's very easy to configure. all you'd have to do is create an allowed list containing the URLs or domains you want to allow, and deny everything but that one list. And, you can redirect to any website or custom er

[squid-users] Re: Accessing a SSL site on a different port than 443

2004-05-05 Thread Adam Aube
Mike Carpenter wrote: > I have run into an issue where Squid is not allowing an SSL connection to > be made to a diferent port than 443. This is Squid's default behavior, for good reason. SSL is used through a proxy via the CONNECT method, which (when allowed) opens an unmonitored and unrestricte

[squid-users] Accessing a SSL site on a different port than 443

2004-05-05 Thread Mike Carpenter
I have run into an issue where Squid is not allowing an SSL connection to be made to a diferent port than 443. Normally, when making a request to Squid, I am prompted for credentials (smb_auth helper) and then the web page is retrieved. This error is strange in that we can not access (for exa

RE: [squid-users] External ACL's

2004-05-05 Thread Danish Khan
assertion failed: errorpage.c:292: "mem->inmem_hi == 0" how to apply its patch Danish

[squid-users] problem startup squid

2004-05-05 Thread Claudemir Franco
I am with big problem, when i try start the squid the following error occurs. User-Agent logging is disabled. Referer logging is disabled. Unlinkd pipe opened on FD 14 assertion failed: StatHist.c:73: "val_in(max - min) > 0" what it will be that is happening? Thanks Claudemir.

RE: [squid-users] xdr_string: out of memory

2004-05-05 Thread Elsen Marc
> > hi > > has anyone seen these errors on their squid servers? > my server is running > > Linux version 2.4.7-10smp (Red Hat Linux 7.1 2.96-98) > > > xdr_string: out of memory > > rgds, > hement gopal Where is this message seen or what is the 'source' of this message : - Squid's c

RE: [squid-users] Re: HOWTO use W2K groups for access?

2004-05-05 Thread Joost Kraaijeveld
Hi Adam, Thanks for the answer. Adam Aube schreef: > Use the wbinfo_group external acl helper. I don't know if the helper is > included with the Debian Squid package; if not, just grab a source tarball > and copy the helper from that (it's just a Perl script). Got the file. Is there any readme ab

[squid-users] xdr_string: out of memory

2004-05-05 Thread Hement Gopal
hi has anyone seen these errors on their squid servers? my server is running Linux version 2.4.7-10smp (Red Hat Linux 7.1 2.96-98) xdr_string: out of memory rgds, hement gopal

RE: [squid-users] Filter ACLs with IPs

2004-05-05 Thread Lucas Beber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thank you. I have been a fool, since after sending the previous mail, something illuminates myself and I saw the solution clearly. My Squid is already working correctly. Even so, I am very grateful for their answer, since the documentation is not

[squid-users] Re: new proxy server....what OS do I install?

2004-05-05 Thread Adam Aube
Hement Gopal wrote: > Our university is currently running a PIII 866Mhz server with 1Gb RAM > and 2x 20Gb and 1 x 70Gb scsi drives. It serves about 4000 clients (max > client connections at any one time will not exceed 2000). Running squid > 2.4.stable6 > OS info is Linux version 2.4.20-28.7smp

Re: [squid-users] External ACL's

2004-05-05 Thread Henrik Nordstrom
On Tue, 4 May 2004, Rob Hartzenberg wrote: > Ok, so the question really, is how much of the load we can leave up to > squid? Quite much. What you need to consider is how quick you want Squid to react to changes in the DB, especially change from the situation that an IP is allowed to not allowe

[squid-users] Squid + SSL CA.

2004-05-05 Thread Ivan Doitchinov
Hello all, I am using squid V2.5.STABLE1 on Red Hat linux and I am trying to set up an SSL proxy (CONNECT method). It all works fine except that I can't figure out how to add my own CA certificate in order to prevent a TLS Unkonwn CA fatal error. I googled a bit and found out that this should

Re: [squid-users] Squid in CPAN

2004-05-05 Thread Henrik Nordstrom
On Wed, 5 May 2004, Jose Nathaniel Nengasca wrote: > Im just wondering if squid is available via CPAN for updates.. etc.. Not that I know of. But there is a large number of mirrors, and also a large number of vendors who maintain binary distributions if you are not comfortable with compiling fr

[squid-users] Re: HOWTO use W2K groups for access?

2004-05-05 Thread Adam Aube
Joost Kraaijeveld wrote: > I want to use W2K Global domain groups for access to the internet through > Squid, e.g. only the domain admins may use the internet through Squid. > I am using Debian Sarge, kernel 2.6.3-1-686, Samba 3.0.2a-Debian, Winbindd > version 3.0.2a-Debian and Squid Cache versio

RE: [squid-users] Filter ACLs with IPs

2004-05-05 Thread Henrik Nordstrom
On Wed, 5 May 2004, Lucas Beber wrote: > Ok. But, could you help me say I how and where I configure it so that > it works? > ¿ a mini-howto? Start by reading the Squid FAQ chapter 10 Access Controls and the Access Control chapter in the Squid Users Guide. THe configuration guide may also have

RE: [squid-users] Filter ACLs with IPs

2004-05-05 Thread Lucas Beber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ok. But, could you help me say I how and where I configure it so that it works? ¿ a mini-howto? I don't really understand too since I am newbie in this. (and english too) Thanks in advance [ Lucas Beber ] Seguridad Informática Nuevo B

[squid-users] Is there a way to measure loading time improvement?

2004-05-05 Thread Jason McNeil
Is there any way or progrmas out there that can tell you if you're squid cache has actually improved browsing speeds for your users?

[squid-users] Squid in CPAN

2004-05-05 Thread Jose Nathaniel Nengasca
Hi, Im just wondering if squid is available via CPAN for updates.. etc.. Thanks.

Re: [squid-users] filtering by file extension (was: problem with req_mime_type)

2004-05-05 Thread Henrik Nordstrom
On Tue, 4 May 2004, Tomasz Chmielewski wrote: > 2) file like http://some.server/file.zip?blah&blah&blah > > I bet it's safe to just omit "$" from 1)? Better make it ($|\?) (End-of-line or a question mark) > 3) http://some.server/file%2Ezip > > I don't know how to do a match here? The above w

[squid-users] HOWTO use W2K groups for access?

2004-05-05 Thread Joost Kraaijeveld
Hi all, I want to use W2K Global domain groups for access to the internet through Squid, e.g. only the domain admins may use the internet through Squid. I have followed the steps outlined in http://www.squid-cache.org/Doc/FAQ/FAQ-23.html#winbind. However, I changed "auth_param ntlm program /u

[squid-users] new proxy server....what OS do I install?

2004-05-05 Thread Hement Gopal
Hi all Our university is currently running a PIII 866Mhz server with 1Gb RAM and 2x 20Gb and 1 x 70Gb scsi drives. It serves about 4000 clients (max client connections at any one time will not exceed 2000). Running squid 2.4.stable6 OS info is Linux version 2.4.20-28.7smp (Red Hat Linux 7.3 2.