RE: [squid-users] POST + NTLM Authentica

2008-07-10 Thread bill . allison
Hi I think this may be the same as I reported as bug 2176 (http://www.squid-cache.org/bugs/show_bug.cgi?id=2176) against 2.6 STABLE17. Is it known to be fixed in 2.7 or 3.0?. Apologies for asking - I haven't had time yet to go through changes logs for subsequent versions. Bill A.

Re: [squid-users] How does squid choose the ICAP service into more than two configured.

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 14:56 +0900, S.KOBAYASHI wrote: Hello everyone, Let me ask to you a favor. Now I configured for ICAP as below. icap_service service_1 respmod_precache 0 icap://192.168.10.231:1344/respmod icap_service service_2 respmod_precache 0 icap://192.168.10.232:1344/respmod

RE: [squid-users] Re: FW: Squid Authentication using Windows 2003 AD

2008-07-10 Thread Tejpal Amin
Hi, Thanks a ton for your help. I was using Squid 3.0 Stable 2, have upgraded to Squid 3.0 Stable 7 which has solved the issue Tejpal Amin -Original Message- From: Henrik Nordstrom [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 09, 2008 3:16 PM To: [EMAIL PROTECTED] Cc:

[squid-users] FW: Problems with LDAP on Windows XP

2008-07-10 Thread Duncan Peacock
Hi There, I have recently installed Squid 2.6.STABLE21 for i686-PC-winnt. The proxy server is currently acting as a chained Proxy and will send all client HTTP request to an online web filtering site. I have managed to configure this correctly but I am having problems with LDAP. I have put

[squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Duncan Peacock
Hi There, I have recently installed Squid 2.6.STABLE21 for i686-PC-winnt. The proxy server is currently acting as a chained Proxy and will send all client HTTP request to an online web filtering site. I have managed to configure this correctly but I am having problems with LDAP. I have put

RE: [squid-users] How to configure URLs list to bypass the squid cache??

2008-07-10 Thread Saurabh Agarwal
Jamie/Henrik Thanks a Lot! This was very helpful Regards, Saurabh -Original Message- From: Jamie Learmonth [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 09, 2008 4:31 PM To: Saurabh Agarwal Cc: squid-users@squid-cache.org Subject: Re: [squid-users] How to configure URLs list to bypass

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Tejpal Amin
Hi Duncan, It seems that the squid_ldap_auth file is not at the location pointed out in the auth_param directive. Regards Tejpal Amin -Original Message- From: Duncan Peacock [mailto:[EMAIL PROTECTED] Sent: Thursday, July 10, 2008 2:53 PM To: squid-users@squid-cache.org Subject:

[squid-users] squid and check_ad_group multidomain

2008-07-10 Thread Cornaggia
Hi, I have a big problem and, after reading the guidelines for configuration and manuals, I thought to write here to have any kind of advice. Squid2.7 is running in windows environment, as reverse proxy on a machine before the web server in a domain xy. With the external helper

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Duncan Peacock
Hi Tejpal, I have tried every possible file path combination and I am still unable to get squid to recognise it. I have tried the following locations: /squid/libexec/squid_ldap_auth c:/squid/libexec/squid_ldap_auth /usr/lib/squid/squid_ldap_auth The strange thing about this error code is

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Tejpal Amin
Hi, Try using c:/squid/libexec/squid_ldap_auth.exe I am not an expert but just trying to help you out. Tejpal Amin -Original Message- From: Duncan Peacock [mailto:[EMAIL PROTECTED] Sent: Thursday, July 10, 2008 3:33 PM To: [EMAIL PROTECTED]; squid-users@squid-cache.org Subject: RE:

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 11:02 +0100, Duncan Peacock wrote: Hi Tejpal, I have tried every possible file path combination and I am still unable to get squid to recognise it. I have tried the following locations: /squid/libexec/squid_ldap_auth c:/squid/libexec/squid_ldap_auth

[squid-users] squid and check_ad_group multidomain

2008-07-10 Thread Cornaggia
Hi, I have a big problem and, after reading the guidelines for configuration and manuals, I thought to write here to have any kind of advice. Squid2.7 is running in windows environment, as reverse proxy on a machine before the web server in a domain xy. With the external helper

Re: [squid-users] POST + NTLM Authentica

2008-07-10 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: Hi I think this may be the same as I reported as bug 2176 (http://www.squid-cache.org/bugs/show_bug.cgi?id=2176) against 2.6 STABLE17. Is it known to be fixed in 2.7 or 3.0?. Apologies for asking - I haven't had time yet to go through changes logs for

[squid-users] squid and check_ad_group multidomain

2008-07-10 Thread Cornaggia
Please, any kind of advice!? -- Forwarded message -- From: Cornaggia [EMAIL PROTECTED] Date: 2008/7/10 Subject: squid and check_ad_group multidomain To: squid-users@squid-cache.org Hi, I have a big problem and, after reading the guidelines for configuration and manuals, I

[squid-users] never_direct + https site access problem in sandwich setup!!!

2008-07-10 Thread Shiva Raman
Hi all I am running a squid1-DG-squid2 sandwich setup and i am facing the following problem. When i give never_direct allow all in squid1.conf , i am not able to access any https sites. Without the above configuration line , all users can access https sites and even sites denied in the Content

RE: [squid-users] POST + NTLM Authentica

2008-07-10 Thread bill . allison
Thanks. Pressure of work means that it will be a few days before I can upgrade, but I will let you know when done. What should I consider when deciding whether to go 3.0 or 2.7? -Original Message- From: [EMAIL PROTECTED] Sent: 10 July 2008 12:44 To: Bill Allison Cc: [EMAIL

Re: [squid-users] never_direct + https site access problem in sandwich setup!!!

2008-07-10 Thread Amos Jeffries
Shiva Raman wrote: Hi all I am running a squid1-DG-squid2 sandwich setup and i am facing the following problem. When i give never_direct allow all in squid1.conf , i am not able to access any https sites. Without the above configuration line , all users can access https sites and even sites

Re: [squid-users] POST + NTLM Authentica

2008-07-10 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: Thanks. Pressure of work means that it will be a few days before I can upgrade, but I will let you know when done. What should I consider when deciding whether to go 3.0 or 2.7? Starting from 2.5, it comes down to speed these days. As a guesstimate, I think 2.7

RE: [squid-users] POST + NTLM Authentica

2008-07-10 Thread Joe Tiedeman
Bill, If you want to test upgrading to 3.0 if you don't have a preference either way, I'll test 2.7 (I'm currently using 2.6 Stable 20) as I can't move to 3 yet because of some of the reverse proxy limitations. Here's hoping! :) Joe -Original Message- From: [EMAIL PROTECTED]

Re: [squid-users] Too many queued ntlmauthenticator requests

2008-07-10 Thread Amos Jeffries
David Jiménez Peris wrote: On a linux ubuntu 8.04 server with squid 3.0.STABLE1 and samba 3.0.28a configured to authenticate against a windows 2003 server active directory with samba winbind ntlm-auth, the ntlm-auth processes keep slowly getting locked in RESERVED state until squid emits the

Re: [squid-users] adding a parameter to a URL / Problem in the url_redirect program

2008-07-10 Thread Amos Jeffries
Shaine wrote: Hi Henrik, First of all i would like to thank you again for all valuable informations provided to me. Those were really help full for my squid integration. But unfortunately there is a problem in sqlite. SO i thought its really waste of hanging with such a data base , switched to

RE: [squid-users] POST + NTLM Authentica

2008-07-10 Thread bill . allison
Joe thanks, that's helpful and appreciated - we'll go 3.0. Fingers crossed. -Original Message- From: [EMAIL PROTECTED] Sent: 10 July 2008 14:53 To: squid-users@squid-cache.org Subject: RE: [squid-users] POST + NTLM Authentica

[squid-users] helperOpenServers: -s is not supported on this resolver

2008-07-10 Thread Rhino
Running squid-2.7.STABLE1-20080528 on Debian linux 2.6.19.7 kernel using wccp2 and iptables for transparency. Squid was configured with --disable-internal-dns and have dns_children 96 dns_defnames off and dns_nameservers xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx in my squid.conf file. Put into

[squid-users] fqdn blocking by...

2008-07-10 Thread Robin Clayton
Hi Guys. IF I enable log_fqdn and it actualy worked ( which so far I don;t seem to have any reverse lookup working.. ) would squidGuard be able to block by the c

[squid-users] empty core files

2008-07-10 Thread Rhino
Running squid-2.7.STABLE1-20080528 on Debian linux 2.6.19.7 kernel using wccp2 and iptables for transparency. Put into production approx. 2 weeks ago, approx. 10k customers are browsing transparently without any complaints of latency, and we're seeing a measurable incoming bandwidth savings on

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Duncan Peacock
Hi Tejpal, Thanks for you help this seems to have stopped the error coming up. I am now getting another problem. I have a windows login box that pops up everytime I try to access a website and I am unsure what the username password could be. I have attached a screenshot of the login box

Re: [squid-users] helperOpenServers: -s is not supported on this resolver

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 09:30 -0500, Rhino wrote: Running squid-2.7.STABLE1-20080528 on Debian linux 2.6.19.7 kernel using wccp2 and iptables for transparency. Squid was configured with --disable-internal-dns and have dns_children 96 dns_defnames off and dns_nameservers xxx.xxx.xxx.xxx

Re: [squid-users] fqdn blocking by...

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 15:31 +0100, Robin Clayton wrote: Hi Guys. IF I enable log_fqdn and it actualy worked ( which so far I don;t seem to have any reverse lookup working.. ) would squidGuard be able to block by the c I do not know SquidGuard that well, but the client FQDN is sent to

Re: [squid-users] empty core files

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 09:40 -0500, Rhino wrote: Running squid-2.7.STABLE1-20080528 on Debian linux 2.6.19.7 kernel using wccp2 and iptables for transparency. Put into production approx. 2 weeks ago, approx. 10k customers are browsing transparently without any complaints of latency, and

Re: [squid-users] Too many queued ntlmauthenticator requests

2008-07-10 Thread Henrik Nordstrom
On tis, 2008-07-08 at 18:15 +0200, David Jiménez Peris wrote: On a linux ubuntu 8.04 server with squid 3.0.STABLE1 and samba 3.0.28a configured to authenticate against a windows 2003 server active directory with samba winbind ntlm-auth, the ntlm-auth processes keep slowly getting locked in

[squid-users] Re: Re: Re[squid-users] verse proxy to Sharepoint

2008-07-10 Thread afstcklnd
Finally resolved that issue by applying the latest fedora core 9 updates and resetting a few things - unfortunately, not sure exactly what fixed the problem. A query on squid.conf... If the http_access settings allow a connection through without ntlm authentication, it seems as though the

Re: [squid-users] Too many queued ntlmauthenticator requests

2008-07-10 Thread David Jiménez Peris
As internet navigation is not affected (users don't even notice a glitch) I'll probably wait for ubuntu to catch up with squid developers. I'll let you know as soon as I upgrade if the behavior changes with newer versions. Thanks for your answer! Best Regards David JP Amos Jeffries wrote:

[squid-users] Read Error on Squid 2.7 for Windows

2008-07-10 Thread Lazuardi Nasution
Hi, I have found so many Read Error on Squid 2.7.STABLE3 for Windows. It is happen too with Squid 2.7.STABLE2 but it is not happen with last version of Squid 2.6. My read_timeout is still default 15 minutes. What happen with Squid 2.7 for Windows ? I found some cosmetic problem on squid -O

[squid-users] Multiple hostnames passed onto backend

2008-07-10 Thread orcadk
Hi, I'm trying to setup Squid to my needs. Basically today I have a series of websites: customer1.mysite.com customer2.mysite.com customerx.mysite.com I want ot offload a lot of the static files through Squid by making a series of Squid enabled sites: customer1.squid.mysite.com

Re: [squid-users] Too many queued ntlmauthenticator requests

2008-07-10 Thread David Jiménez Peris
I've got around 300 windows 2000-sp4 and xp-sp2 clients. I have configured squid with up to 500 ntlm authenticators but it has only made the problem worse because when all the ntlm authenticators become stalled on the deferred state squid needs a lot more time to restart. Today squid with 10

Re: [squid-users] can't get squid to cache

2008-07-10 Thread Angelo Hongens
Sorry, sent this mail directly to Hendrik.. Here it is to the list. I'm still pulling my hear out :( Henrik Nordstrom wrote: On ons, 2008-07-09 at 14:32 +0200, Angelo Höngens wrote: Is there any way I can force caching if the control headers are missing?? refresh_pattern with a min age

[squid-users] Credentials not kept cross domain

2008-07-10 Thread Joseph Piché
Hi. I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I have been trying to set up authentication using ntlm_auth connecting to Active Directory. Everything works fine except I get prompted for a username and password for every single domain. The credentials are accepted, and I am

Re: [squid-users] Too many queued ntlmauthenticator requests

2008-07-10 Thread Joseph Piché
As internet navigation is not affected (users don't even notice a glitch) I'll probably wait for ubuntu to catch up with squid developers. I'll let you know as soon as I upgrade if the behavior changes with newer versions. I have been successfully using stable7 on ubuntu 8.04 using debian sid

Re: [squid-users] empty core files

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 11:06 -0500, Rhino wrote: 2008/07/10 03:07:31| storeLocateVary: Not our vary marker object, AD15713B6C28E4CE9BBEA7488 76C70B7 = 'http://x.myspacecdn.com/modules/common/static/js/apps/json001.js', 'accept-encod ing=gzip,%20deflate'/'gzip, deflate' 2008/07/10 03:07:31|

[squid-users] assertion failed

2008-07-10 Thread Pritam
Hi, My squid box was restarted with following message in cache.log. httpReadReply: Excess data from HEAD http://dl_dir.qq.com/qqfile/ims/qqdoctor/tsfscan.dat; assertion failed: forward.c:109: !EBIT_TEST(e-flags, ENTRY_FWD_HDR_WAIT) Starting Squid Cache version 2.7.STABLE3 for

Re: [squid-users] reply_body_max_size + delay_pools

2008-07-10 Thread Heinrich Harrer
On Tue, Jul 8, 2008 at 3:36 PM, Chris Robertson [EMAIL PROTECTED] wrote: [cut] Just use delay pools, and set the initial bucket size to the max object size you don't want to limit. This will have the added benefit of preventing someone from circumventing your reply_body_max_size slowdown by

Re: [squid-users] empty core files

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 13:58 -0500, Rhino wrote: the cache.log is huge - ton of entries in there starting from when it began after the previous rotation (daily). Is there anything in particular to look for? The most interesting is FATAL, assertion failed, segmentation fault, and the about

RE: [squid-users] Problems with LDAP on Windows XP

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 15:56 +0100, Duncan Peacock wrote: I am now getting another problem. I have a windows login box that pops up everytime I try to access a website and I am unsure what the username password could be. It's the proxy asking for your login password, just like you have

Re: [squid-users] Re: Re: Re[squid-users] verse proxy to Sharepoint

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 09:18 -0700, afstcklnd wrote: Having removed all http_access accept the ntlm users bit, authorisation process goes through OK, however, the security token is not getting through to sharepoint. Squid debug shows the GET followed by a reply with Unauthorised from the

Re: [squid-users] Read Error on Squid 2.7 for Windows

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 23:26 +0700, Lazuardi Nasution wrote: Hi, I have found so many Read Error on Squid 2.7.STABLE3 for Windows. It is happen too with Squid 2.7.STABLE2 but it is not happen with last version of Squid 2.6. My read_timeout is still default 15 minutes. What happen with Squid

Re: [squid-users] Multiple hostnames passed onto backend

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 09:34 -0700, orcadk wrote: Now, I can get Squid to do this for a single domain with just a couple of settings: http_port 80 accel defaultsite=customerx.mysite.com cache_peer [internal_ip] 80 0 no-query originserver=customerx_server However, I need to get this working

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 13:14 -0500, Joseph Piché wrote: Hi. I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I have been trying to set up authentication using ntlm_auth connecting to Active Directory. Everything works fine except I get prompted for a username and password for

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Joseph Piché
I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I have been trying to set up authentication using ntlm_auth connecting to Active Directory. Everything works fine except I get prompted for a username and password for every single domain. Are you doing transparent

Re: [squid-users] assertion failed

2008-07-10 Thread Henrik Nordstrom
On fre, 2008-07-11 at 00:27 +0545, Pritam wrote: Hi, My squid box was restarted with following message in cache.log. httpReadReply: Excess data from HEAD http://dl_dir.qq.com/qqfile/ims/qqdoctor/tsfscan.dat; assertion failed: forward.c:109: !EBIT_TEST(e-flags, ENTRY_FWD_HDR_WAIT)

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Jose Ildefonso Camargo Tolosa
Hi! On Fri, Jul 11, 2008 at 4:17 PM, Joseph Piché [EMAIL PROTECTED] wrote: I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I have been trying to set up authentication using ntlm_auth connecting to Active Directory. Everything works fine except I get prompted for a username

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Henrik Nordstrom
On tor, 2008-07-10 at 15:47 -0500, Joseph Piché wrote: I have iptables forwarding port 80 to port 8080 where dansguardian intercepts the request and forwards it to squid which listens on local 3128. So, there is no way to do this without configuring browsers? I would really like to get around

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Henrik Nordstrom
On fre, 2008-07-11 at 16:48 +, Jose Ildefonso Camargo Tolosa wrote: I use automatic browser configuration (via dns, dhcp ... or both ). And I think you could add an informative page, via port redirection, where you explain how to configure the browser for proxy autoconfiguration (or how

Re: [squid-users] assertion failed

2008-07-10 Thread Dave
I get this one too, sorry do not have a coredump of it though. Henrik Nordstrom wrote: On fre, 2008-07-11 at 00:27 +0545, Pritam wrote: Hi, My squid box was restarted with following message in cache.log. httpReadReply: Excess data from HEAD

[squid-users] Re: Re: Re: Re[squid-users] verse proxy to Sharepoint

2008-07-10 Thread afstcklnd
Not having a dig at you but I'm going round in circle here - has noone ever done this successfully before? Microsoft IAS is heavy, unwieldy and unfriendly so we chose to use Squid to act as reverse proxy for limited remote access to various MS Sharepoint sites (applications as they like to call

Re: [squid-users] helperOpenServers: -s is not supported on this resolver

2008-07-10 Thread Amos Jeffries
Henrik Nordstrom wrote: On tor, 2008-07-10 at 09:30 -0500, Rhino wrote: Running squid-2.7.STABLE1-20080528 on Debian linux 2.6.19.7 kernel using wccp2 and iptables for transparency. Squid was configured with --disable-internal-dns and have dns_children 96 dns_defnames off and dns_nameservers

Re: [squid-users] Re: Re: Re: Re[squid-users] verse proxy to Sharepoint

2008-07-10 Thread Michael Alger
On Thu, Jul 10, 2008 at 04:31:40PM -0700, afstcklnd wrote: login=PASS does hand off to sharepoint OK - however, sharepoint returns everything under http 1.1 with objectmoved - new target does not get replaced with external url for the site so external access suddenly finds itself pointing

[squid-users] squid in ISP

2008-07-10 Thread Siu-kin Lam
Dear all Any experience using squid as caching in ISP environment ? thanks SK

Re: [squid-users] Credentials not kept cross domain

2008-07-10 Thread Amos Jeffries
Joseph Piché wrote: Hi. I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I have been trying to set up authentication using ntlm_auth connecting to Active Directory. Everything works fine except I get prompted for a username and password for every single domain. The credentials

Re: [squid-users] squid in ISP

2008-07-10 Thread Amos Jeffries
Siu-kin Lam wrote: Dear all Any experience using squid as caching in ISP environment ? Simple answer is: Yes. Depends on what size ISP though (and which version of Squid) who will respond and with what info... Amos -- Please use Squid 2.7.STABLE3 or 3.0.STABLE7

[squid-users] After some time url_redirect program hangs.

2008-07-10 Thread Shaine
Hi Load of IM requests goes through squid proxy and most functionalities of IM handle by url_redirector program.Redirector program functioning properly. But after some times , like after 8 hours or some thing that url redirector program doesn't work. In my suid.conf url_rewrite_children 5 ,

[squid-users] Certain webpages does not get loaded

2008-07-10 Thread Geetha_Priya
I have finally integrated my proxy with squid. I wanted all the request from proxy to go through squid and responses back to proxy. Thanks to Henrick for useful advice. Now I have a very weird problem. All the company websites [for ex. www.infosys.com, www.cisco.dom etc.], bank related genuine