Re: [squid-users] cache only certain files?

2008-05-30 Thread Anton Melser
>> CacheEnable disk /these/pages >> CacheEnable disk /those/pages/there > > acl cachable_pages urlpath_regex ^/these/pages > acl cachable_pages urlpath_regex ^/these/other/pages > cache allow cachable_pages yep, that would do it! > But the content must also be cachable for this to have any effect

Re: [squid-users] Transparent proxy with DansGuardian using IDENT

2008-05-30 Thread Matus UHLAR - fantomas
> On tor, 2008-05-29 at 12:34 -0700, modulok wrote: > > I have setup a squid server with dansguardian. I also have a server setup > > with iptables acting as the default gateway. I have transparent proxy with > > dansguardian filtering working. When using transparent proxy, the squid > > server doe

Re: [squid-users] cache only certain files?

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 09:14 +0200, Anton Melser wrote: > > The app is a bit stupid now (not the original codebase, what was added > after), and it's either all or nothing. Which is the problem... but > yes, it definitely sends the all the right headers for caching, even > when it shouldn't (which

Re: [squid-users] Strange Squid problem.

2008-05-30 Thread Amos Jeffries
Henti Smith wrote: Hi all. I'm having a weirdness at a client. Squid auth using ntlm on samba thats connected to ADS. Setup was working until they replaced the ads server with new one. I have updated configs with the new ADS and re added samba. however squid auth is still not working. wbinfo

Re: [squid-users] Auto Proxy ISP & Squid questions

2008-05-30 Thread Amos Jeffries
Mr Crack wrote: How can I use squid with auto-proxy ISP Do I need to use cache_peer ? Say what? please explain better. Amos -- Please use Squid 2.7.STABLE1 or 3.0.STABLE6

Re: [squid-users] ldap_auth

2008-05-30 Thread Henrik Nordstrom
http://wiki.squid-cache.org/KnowledgeBase/LdapBackedDigestAuthentication On tor, 2008-05-29 at 20:42 -0700, Squidly wrote: > Is there a good guide detailing how to set this digest up with openLdap? > > On Thu, May 29, 2008 at 4:40 PM, Henrik Nordstrom > <[EMAIL PROTECTED]> wrote: > > On tor, 200

Re: [squid-users] ldap_auth

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 09:33 +0530, Indunil Jayasooriya wrote: > Hi, > > > Is there a good guide detailing how to set this digest up with openLdap? > > http://yajith.blogspot.com/2007/12/squid-ldap-and-active-directory.html Thats ntlm, not digest. Regards Henrik signature.asc Description: Thi

Re: [squid-users] coss && swap.state

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 11:40 +0800, liwei wrote: > I have a script which used to parse swap.state, it works well > in aufs, but I don't know whether it will be ok in coss,who can give me > some advices?thanks a lot. coss doesn't have a swap.state jounal. Regards Henrik signature.asc De

Re: [squid-users] cache manager access

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 13:21 +0800, cc wrote: > I've set it to *:*, and visually, the form looks just > like the old version. However, when I enter the manager's > password, it still gives me an Error Access Denied. That error is from your Squid http_access rules. What is said in access.log? An

Re: [squid-users] Auto Proxy ISP & Squid questions

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 12:23 +0630, Mr Crack wrote: > How can I use squid with auto-proxy ISP > Do I need to use cache_peer ? Depends on if it's a transparently intercepting proxy, or one that is autodiscovered by te browsers using WPAD. If WPAD then yes, you need to figure out the proxy host

Re: [squid-users] Transparent proxy with DansGuardian using IDENT

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 09:39 +0200, Matus UHLAR - fantomas wrote: > maybe with tproxy functionality squid sould fake server's IP in direction to > the client :) Yes, and is why I mentioned "tricks like tproxy". But keep in mind that it adds yet another complex routing requirement to the mix, and

Re: [squid-users] Auto Proxy ISP & Squid questions

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 17:04 +0630, Mr Crack wrote: > I dont know WPAD or web auto discovery But what I know is I can use > without proxy server address in Internet Explorer or Mozilla (without > any congiuration needed ) I can use Internet Your comment are highly > appriciated ... Thnz Sounds li

Re: [squid-users] Problem with some Microsoft Sites

2008-05-30 Thread Danilo Godec
Dear everybody, it seems I've been hit by that same thing as users started complaining they cannot get MS Updates. So I've compiled Squid 2.6STABLE20, but it doesn't recognize 'request_header_access' option. I've tried to use 'header_access' option instead, but I'm not sure it's the same th

[squid-users] debug ALL,1 too noisy

2008-05-30 Thread Michel (M)
Hi I think that squid's debug level ALL,1 is very noisy and does flood the log, especially with the following events squid[14086]: ctx: exit level 0 ... squid[14086]: ctx: enter level ... squid[14086]: httpProcessReplyHeader ... which do not have any value because nothing can be done so they a

[squid-users] Negative values in delay pools

2008-05-30 Thread Sergio Belkin
Hi, I configured delay pools on squid. I get the following from squidclient: Delay pools configured: 2 Pool: 1 Class: 1 Aggregate: Disabled. Pool: 2 Class: 1 Aggregate: Max: 187500 Restore: 187500 Current: -6 Memo

Re: [squid-users] Auto Proxy ISP & Squid questions

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 17:56 +0630, Mr Crack wrote: > If then so, I'd like to now my squid still do caching or not yes signature.asc Description: This is a digitally signed message part

[squid-users] Re: debug ALL,1 too noisy

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 08:32 -0300, Michel (M) wrote: > Hi > > I think that squid's debug level ALL,1 is very noisy and does flood the > log, especially with the following events > > squid[14086]: ctx: exit level 0 ... > squid[14086]: ctx: enter level ... > squid[14086]: httpProcessReplyHeader ..

Re: [squid-users] Problem with some Microsoft Sites

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 13:25 +0200, Danilo Godec wrote: > I've tried to use 'header_access' option instead, but I'm not sure it's > the same thing. Is it? Almost. In this context it is. But with 2.6.STABLE20 you don't need this setting. If you still have problems the problem is something else. R

[squid-users] IP Based ACL

2008-05-30 Thread Rahul Tidke
Hello, I have configured two files in squid; one is for allowed site and other for blocked site and configured ACL for this. At present this is working fine. Now my requirement is that I want to apply this ACL only for certain IP range and some IPs need to be excluded from this on my loc

Re: [squid-users] Negative values in delay pools

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 08:46 -0300, Sergio Belkin wrote: > I know that "-1" mean "no limits" but What does mean Current with a > negative value < -1 ? It means they have temporarily exceeded their limit, and won't get any data until the pool has been refilled and has some bytes available again...

Re: [squid-users] IP Based ACL

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 17:37 +0530, Rahul Tidke wrote: >I have configured two files in squid; one is for allowed site and > other for blocked site and configured ACL for this. At present this is > working fine. Now my requirement is that I want to apply this ACL only > for certain IP rang

Re: [squid-users] Problem with some Microsoft Sites

2008-05-30 Thread Danilo Godec
Henrik Nordstrom pravi: On fre, 2008-05-30 at 13:25 +0200, Danilo Godec wrote: I've tried to use 'header_access' option instead, but I'm not sure it's the same thing. Is it? Almost. In this context it is. But with 2.6.STABLE20 you don't need this setting. If you still have problems the probl

Re: [squid-users] Problem with some Microsoft Sites

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 14:33 +0200, Danilo Godec wrote: > I'm buffled. I changed MTU on the server running squid (from 1500 to 1496) > and > microsoft.com works now. Odd.. Are you doing transparent interception, or is the clients explicit configured to use the proxy? If transparent interceptio

[squid-users] Squid and Wpad

2008-05-30 Thread Cornaggia
Dear Squid, I have just a question reagarding some practical set up of the Squid-proxy. Knowing that the NTLM authentication and the transparent mode don´t work together, my question is: if with a wpad i set automatically the browsers to use a proxy squid to access a branch of my LAN (a subdomain

Re: [squid-users] ldap_auth

2008-05-30 Thread Squidly
Is running samba the only way for squid not to use clear text passwords? On Fri, May 30, 2008 at 2:41 AM, Henrik Nordstrom <[EMAIL PROTECTED]> wrote: > http://wiki.squid-cache.org/KnowledgeBase/LdapBackedDigestAuthentication > > On tor, 2008-05-29 at 20:42 -0700, Squidly wrote: >> Is there a good

[squid-users] Re: Transparent proxy with DansGuardian using IDENT

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 05:56 -0700, [EMAIL PROTECTED] wrote: > The whole ident setup (every client having an ident service running) > is a little bit annoying, but I haven't found any other way to log > usernames without forcing clients to enter a user/pass to access the > internet. If there is ano

Re: [squid-users] Squid and Wpad

2008-05-30 Thread Amos Jeffries
Cornaggia wrote: Dear Squid, I have just a question reagarding some practical set up of the Squid-proxy. Knowing that the NTLM authentication and the transparent mode don´t work together, my question is: if with a wpad i set automatically the browsers to use a proxy squid to access a branch of m

Re: [squid-users] Negative values in delay pools

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 10:07 -0300, Sergio Belkin wrote: > Thanks Henrik, but what is the difference betwwen "-1" and -3" (it's > just an example...) Current is just the current level in the pool. -1 means it's 1 byte below 0. -3 means it's 3 bytes below 0.. When the pool is refilled (once per

Re: [squid-users] ldap_auth

2008-05-30 Thread Henrik Nordstrom
The use of Samba in that article is just to get a clean integration of using the same password on the desktop and for browsing. It's purely optional. Regards Henrik On fre, 2008-05-30 at 06:13 -0700, Squidly wrote: > Is running samba the only way for squid not to use clear text passwords? > > On

Re: [squid-users] Squid and Wpad

2008-05-30 Thread Henrik Nordstrom
On fre, 2008-05-30 at 14:54 +0200, Cornaggia wrote: > work together, my question is: if with a wpad i set automatically the > browsers to use a proxy squid to access a branch of my LAN (a > subdomain we call N1) and to use for all the other requests our > company proxy, tha NTLM authentication wor

Re: [squid-users] ldap_auth

2008-05-30 Thread Emanuel dos Reis Rodrigues
Squidly wrote: Is running samba the only way for squid not to use clear text passwords? On Fri, May 30, 2008 at 2:41 AM, Henrik Nordstrom <[EMAIL PROTECTED]> wrote: http://wiki.squid-cache.org/KnowledgeBase/LdapBackedDigestAuthentication On tor, 2008-05-29 at 20:42 -0700, Squidly wrote:

Re: [squid-users] ldap_auth

2008-05-30 Thread Chris Riggins
No, it is possible to use digest authentication to avoid cleartext passwords. The squid wiki link Henrik sent out is a good start, but it leaves out one critical piece: how to encode the passwords! In either LDAP or a flat-file, I found only one site online with instructions, and they were

Re: [squid-users] ldap_auth

2008-05-30 Thread Amos Jeffries
Chris Riggins wrote: No, it is possible to use digest authentication to avoid cleartext passwords. The squid wiki link Henrik sent out is a good start, but it leaves out one critical piece: how to encode the passwords! In either LDAP or a flat-file, I found only one site online with instr

Re: [squid-users] Transparent proxy with DansGuardian using IDENT

2008-05-30 Thread modulok
Hmm, I can't remember if ident worked or not, but what if the squid server is on the same as iptables? Will usernames/ips be logged in access.log? Henrik Nordstrom-5 wrote: > > On fre, 2008-05-30 at 05:56 -0700, [EMAIL PROTECTED] wrote: > >> The whole ident setup (every client having an ident

[squid-users] Tproxy iptables rules issue

2008-05-30 Thread Ritter, Nicholas
What exactly are the redirection rules for wccp/iptables 1.4/squid 2.6/tproxy look like? I have browsed the Internet plus messed with it for a while now and found that the README rules don't fully work, and the examples on the Internet don't fully work. Symptomatically, I see the router redirecti

RE: [squid-users] squid , rsync and authentication

2008-05-30 Thread Jean-Jacques ROUGET
Well, as you said, I have omitted http:// in the rsync proxy setting and everything is ok. Thanks a lot. Regards Jean-Jacques -Message d'origine- De : Henrik Nordstrom [mailto:[EMAIL PROTECTED] Envoyé : mercredi 28 mai 2008 23:41 À : Jean-Jacques ROUGET Cc : Amos Jeffries; squid-users@

[squid-users] Squid Crashing on Ubuntu server

2008-05-30 Thread Mr. Issa(*)
Hello mates!, i hope you are enjoying healthy life and Great time. Well i did setup SQUID 2.6S18 on Ubuntu Hardy Heron Server edition. But when ever i start squid it shutdowns Cache.log: 2008/05/30 23:22:22| Starting Squid Cache version 2.6.STABLE18 for i386-debian-linux-gnu... 2008/05/30 23:22