[squid-users] Allowing/Unblocking Skype with Squid

2006-06-06 Thread Jon Joyce
Hi all, We currently have a Squid box set up to only allow secure https traffic through a manually updated whitelist. So now, all clients must provide the name and 443 port of our Proxy server before they can access secure sites (i.e. Internet Banking, Hotmail etc.) We now have the

[squid-users] squid: ERROR: Could not send signal

2006-06-06 Thread eko rusdyanto
Dear all i've run squid on centos4.2 for several month. but by accident i remove squid.pid. i've read in squid FAQ for this issue, and run all the suggestion, but it didn't work [EMAIL PROTECTED] ~]# ps ax | grep squid You have new mail in /var/spool/mail/root [EMAIL PROTECTED] ~]#

Re: [squid-users] Allowing/Unblocking Skype with Squid

2006-06-06 Thread Emilio Casbas
Jon Joyce wrote: Hi all, We currently have a Squid box set up to only allow secure https traffic through a manually updated whitelist. So now, all clients must provide the name and 443 port of our Proxy server before they can access secure sites (i.e. Internet Banking, Hotmail etc.) We now

Re: [squid-users] squid: ERROR: Could not send signal

2006-06-06 Thread Emilio Casbas
eko rusdyanto wrote: Dear all i've run squid on centos4.2 for several month. but by accident i remove squid.pid. i've read in squid FAQ for this issue, and run all the suggestion, but it didn't work [EMAIL PROTECTED] ~]# ps ax | grep squid You have new mail in /var/spool/mail/root [EMAIL

Re: [squid-users] squid: ERROR: Could not send signal

2006-06-06 Thread Henrik Nordstrom
tis 2006-06-06 klockan 15:04 +0700 skrev eko rusdyanto: [EMAIL PROTECTED] ~]# /usr/local/squid/sbin/squid You have new mail in /var/spool/mail/root [EMAIL PROTECTED] ~]# /usr/local/squid/sbin/squid -k reconfigure squid: ERROR: No running copy [EMAIL PROTECTED] ~]# ps ax | grep squid 7039 ?

Re: [squid-users] Symptom Patch

2006-06-06 Thread Awie
Yesterday, I applied the patch of Squid 2.3S14 but Squid is dying (when loaded by rc.local) with error FATAL: Received Segment Violation...dying. However, I cannot create stack trace as I don't know how to do. After un-patching, Squid can be loaded from rc.local. Instructions on how to get

Re: [squid-users] Allowing/Unblocking Skype with Squid

2006-06-06 Thread Philipp Nyffenegger
acl N_IPS urlpath_regex ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+ acl connect method CONNECT http_access allow connect N_IPS all Why do all these tipps refer to urlpath_regex ? This is IMHO false. At least it does not match at my site. There is no URL-Path in the CONNECT-Method, iirc. This works fine

[squid-users] X-Forwarded-For Header and Rewriter

2006-06-06 Thread mickymax
Hi, does anybody know if it is possible to access the X-Forwarded-Header inside of a rewriter script (squid used as reverse proxy). AFAIK, there is only the ip-address of the requesting server available which may be the ip of another cache-server. Background: We have another external cache

Re: [squid-users] Allowing/Unblocking Skype with Squid

2006-06-06 Thread Kinkie
On Tue, 2006-06-06 at 15:13 +0200, Philipp Nyffenegger wrote: acl N_IPS urlpath_regex ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+ acl connect method CONNECT http_access allow connect N_IPS all Why do all these tipps refer to urlpath_regex ? This is IMHO false. At least it does not match at my

Re: [squid-users] permanantly caching a site/content

2006-06-06 Thread Visolve squid
On Tue, 2006-06-06 at 10:51 +1000, [EMAIL PROTECTED] wrote: is it possible to set an acl to permanently cache a site? regardless of the disk/cache size? i've looked over all of the doco and i cant find anything tia Hello Tia, You can try with the following refresh_pattern -i

[squid-users] Authentication Pop-up after Domain Controller restart

2006-06-06 Thread Rodrigo Barros
Hi everybody, I have a Squid 2.5.STABLE14 and a samba-3.0.22 running in my company with NTLM authentication, I have almost 1000 users on it today and It's running very smothly. We're very satisfied but there's one situation I could find an solution yet and I'd like your advise on it. Once in a

Re: [squid-users] Symptom Patch

2006-06-06 Thread Henrik Nordstrom
tis 2006-06-06 klockan 18:49 +0800 skrev Awie: AW Yes, I use aufs (it means I don't need to run SIGPIPE, right?) SIGPIPE needs to be ignored on all operating systems in all configurations.. so you need it. Regards Henrik signature.asc Description: Detta är en digitalt signerad meddelandedel

Re: [squid-users] X-Forwarded-For Header and Rewriter

2006-06-06 Thread Chris Robertson
[EMAIL PROTECTED] wrote: Hi, does anybody know if it is possible to access the X-Forwarded-Header inside of a rewriter script (squid used as reverse proxy). AFAIK, there is only the ip-address of the requesting server available which may be the ip of another cache-server. Background: We

[squid-users] Two security questions...

2006-06-06 Thread Bernard Barton
I've been informed by our security department that we have two vulnerabilities on a squid reverse proxy I have running. It's running squid-2.5.STABLE3 on Red Hat AS 4.0. The first issue concerns squid identifying itself on port 80. If you telnet to the squid proxy on port 80, then type get /,

Re: [squid-users] Authentication Pop-up after Domain Controller restart

2006-06-06 Thread Scott Jarkoff
On 6/6/06, Rodrigo Barros [EMAIL PROTECTED] wrote: I have a Squid 2.5.STABLE14 and a samba-3.0.22 running in my company with NTLM authentication, I have almost 1000 users on it today and It's running very smothly. We're very satisfied but there's one situation I could find an solution yet and

RE: [squid-users] Transparent proxy with tproxy

2006-06-06 Thread Steven Wilton
If you're trying to specify a port, you must use '-p tcp' to tell iptables which protocol you're referring to. So you will want a rule similar to the following: iptables -t tproxy -A PREROUTING -p tcp -j TPROXY --on-port 3128 Steven -Original Message- From: chima s [mailto:[EMAIL

[squid-users] Re: squid: ERROR: Could not send signal

2006-06-06 Thread eko rusdyanto
Dear all my squid already back to normal. Thanks a lot for your clue and suggestions [EMAIL PROTECTED] ~]# /usr/local/squid/sbin/squid -DNYCd3 2006/06/07 08:20:35| Starting Squid Cache version 2.5.STABLE13 for i686-pc-linux-gnu... 2006/06/07 08:20:35| Process ID 9420 2006/06/07 08:20:35| With

Re: [squid-users] X-Forwarded-For Header and Rewriter

2006-06-06 Thread Henrik Nordstrom
tis 2006-06-06 klockan 13:26 -0800 skrev Chris Robertson: http://devel.squid-cache.org/projects.html#follow_xff might be just what you are looking for. Be aware that development patches are not supported and may set your hair on fire. This patch has been included in the upcoming 2.6

Re: [squid-users] Two security questions...

2006-06-06 Thread Henrik Nordstrom
tis 2006-06-06 klockan 19:23 -0400 skrev Bernard Barton: I've been informed by our security department that we have two vulnerabilities on a squid reverse proxy I have running. It's running squid-2.5.STABLE3 on Red Hat AS 4.0. The first issue concerns squid identifying itself on port 80.