Re: [squid-users] can't access javascript enable website

2009-08-11 Thread Amos Jeffries
Jon Tim wrote: Hi Squid Support, I'm using squid squid-2.6.STABLE22-1.fc8 from Fedora 8. I can use squid and SquidGuard without having any problems. But, today, one of the user complaints that she can't browse http://www.sdf.gov.sg website. I try without using squid proxty and it works OK.

Re: [squid-users] [suiqd-2.7STABL E6-1]Problem RPC via HTTPS‏ [SOLVED]

2009-08-11 Thread Amos Jeffries
hdyugoplastika hdyugoplastika wrote: I have solved!!! There was one error in rpc client side(mine stupid type of error on user) and this is the final configuration(with loadbalance on cache_peer): acl all src all acl manager proto cache_object acl localhost src 127.0.0.1/32 acl to_localhost

Re: [squid-users] prevent exe downloads from https sites

2009-08-11 Thread Amos Jeffries
Jakob Curdes wrote: Henrik Nordstrom schrieb: tis 2009-08-11 klockan 14:17 +0200 skrev Jakob Curdes: - use a (commercial) product that intercepts https Or Squid-3.1 which does the same (with some limitations). Ouch, I again missed importand developments. Is there a configuration e

Re: [squid-users] rewriter/redirector question

2009-08-11 Thread Amos Jeffries
Leonardo Carneiro wrote: Luis Daniel Lucio Quiroz escreveu: Le mardi 11 août 2009 12:33:26, Leonardo Carneiro a écrit : Hello everyone, Sometime ago i blocked some popular social network sites. However, some users manage to access those sites using sites like atunnel and others. Since bloc

Re: Fw: Re: [squid-users] squid error message

2009-08-11 Thread Amos Jeffries
Jigar Raval wrote: Hello, In continutation to my previous mail about squid cache error log, We have observed that this is happend due to port 80 forwarding to 3128 using iptables. We removed the line from iptables and the error is now not in cache log fine. We have blocked all the port 80 reques

Fw: Re: [squid-users] squid error message

2009-08-11 Thread Jigar Raval
Hello, In continutation to my previous mail about squid cache error log, We have observed that this is happend due to port 80 forwarding to 3128 using iptables. We removed the line from iptables and the error is now not in cache log fine. We have blocked all the port 80 request through iptables.

Re: [squid-users] Problem with Squid + Tproxy and Rapdishare

2009-08-11 Thread Carlos Botejara
The problem is the http header. check the traffic and saw that x_forwarded header has the following format: x_forwarded: client-ip, ip-proxy1, ip-proxy2. In my header, the client ip is there, but there is also the ip of the squid. the question is: How do I only see the ip of the client and remove t

Re: [squid-users] Squid and YahooMail

2009-08-11 Thread Rick Chisholm
we are using squid 2.7-Stable6 and SquidGuard 1.4 I think the URLs that are causing trouble are similar to this one: https://us.bc.yahoo.com/b?P=gCsrUUWTcKCpTelyRrdJFADzGDkKtUqCE48AAiib&T=14uar0mrg%2fX%3d1250038671%2fE%3d150001456%2fR%3dregst%2fK%3d5%2fV%3d1.1%2fW%3dJ%2fY%3dYAHOO%2fF%3d3502946160

Re: [squid-users] rewriter/redirector question

2009-08-11 Thread Leonardo Carneiro
Luis Daniel Lucio Quiroz escreveu: Le mardi 11 août 2009 12:33:26, Leonardo Carneiro a écrit : Hello everyone, Sometime ago i blocked some popular social network sites. However, some users manage to access those sites using sites like atunnel and others. Since blocking every single proxy s

Re: [squid-users] rewriter/redirector question

2009-08-11 Thread Luis Daniel Lucio Quiroz
Le mardi 11 août 2009 12:33:26, Leonardo Carneiro a écrit : > Hello everyone, > > Sometime ago i blocked some popular social network sites. However, some > users manage to access those sites using sites like atunnel and others. > Since blocking every single proxy site on the web is a invencible tas

[squid-users] view cache contents

2009-08-11 Thread Hanxhi
Hi, I wanted to know if it's possible to view the contents of the cache directory. For example, browse the /var/spool/squid_cache_dir to search for (mostly), images. Thanks in advance, Regards. Hanxhi -- View this message in context: http://www.nabble.com/view-cache-contents-tp24924551p2492455

Re: [squid-users] Squid load incorrectly one site

2009-08-11 Thread aba3k
Kinkie wrote: > > A reload from any browser using the proxy (ctrl-r under firefox, > ctrl-f5 under MSIE) will cause a new request to the origin server, and > the old copy will be replaced with the new if that's what the server > instructs to do. > Sadly not solved the problem. -- View this

[squid-users] Re: Kerberos Authentication - Squid 3.1.0.13

2009-08-11 Thread Markus Moeller
Hi Daniel, Did you see any configure errors for gssapi.h ? Markus "Daniel" wrote in message news:001301ca19fe$9f450a50$ddcf1e...@com... Good afternoon, In my attempt to get Squid on our SLES 11 box authenticating with Kerberos (negotiate), I used the following to re-configure: ./configure

[squid-users] Problem with squid 3.0.STABLE18 installation

2009-08-11 Thread Aleksey Samostrelov
Hello. I'm trying to install squid-3.0.STABLE18 on AIX 5300-10-01-0921. I've configured it with ./configure --prefix=/opt/squid --enable-xmalloc-statistics --enable-icmp --enable-delay-pools --enable-default-err-language=English --with-large-files Configuration process completes successfully, but

Re: [squid-users] Squid and YahooMail

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 12:53 -0400 skrev Rick Chisholm: > We are using squidGuard. Then make sure you do not block CONNECT requests with a URL rewrite, trying to rewrite the CONNECT host into a HTTP URL... Blocking CONNECT requests with a browser redirect is sometimes fine, but browsers are start

Re: [squid-users] squid 3.1: How to setup a Squid SSL reverse proxy for a parent SSL Squid proxy?

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 08:47 -0700 skrev chrischni: > am i getting this wrong, or does that mean, that we don´t need to specify a > sslcert in the cache_peer line? Only if you want Squid to authenticate to the webserver using a client side certificate. > should he connect to the sharepoint with

[squid-users] rewriter/redirector question

2009-08-11 Thread Leonardo Carneiro
Hello everyone, Sometime ago i blocked some popular social network sites. However, some users manage to access those sites using sites like atunnel and others. Since blocking every single proxy site on the web is a invencible task, i chose to teach the users a little funny lesson, like redirec

RE: [squid-users] "moved permanently" loop detection

2009-08-11 Thread Mike Mitchell
He got hit with another one today. The access log fills to the maximum file size, then squid dies. Having squid return a reasonable error to the client may be a problem. It would probably be sufficient if squid did not cache the 301/302 return if the Location: field points to the requested URL.

Re: [squid-users] Squid and YahooMail

2009-08-11 Thread Rick Chisholm
We are using squidGuard. Henrik Nordstrom wrote: > mån 2009-08-10 klockan 22:01 -0400 skrev Rick Chisholm: > >> Our marketing dept. at work needs access to Yahoo Analytics, but they >> have to login via Yahoo! regular login. Squid complains about a DNS >> resolution issue but names the link as >

Re: [squid-users] Squid and YahooMail

2009-08-11 Thread Rick Chisholm
it's just redirecting to login.yahoo.com again... but with a long URL, I will do some more digging and get you a more specific answer. I will also check, but I'm pretty sure we are at the latest available squid 2.7 BSD port. I will post back more accurate details. Amos Jeffries wrote: > On Mon,

Re: [squid-users] prevent exe downloads from https sites

2009-08-11 Thread Jakob Curdes
Henrik Nordstrom schrieb: tis 2009-08-11 klockan 14:17 +0200 skrev Jakob Curdes: - use a (commercial) product that intercepts https Or Squid-3.1 which does the same (with some limitations). Ouch, I again missed importand developments. Is there a configuration example somewhere tha

Re: [squid-users] squid 3.1: How to setup a Squid SSL reverse proxy for a parent SSL Squid proxy?

2009-08-11 Thread chrischni
Henrik Nordstrom-5 wrote: > > tis 2009-08-11 klockan 02:38 -0700 skrev chrischni: >> this is our cache_peer config: >> >> cache_peer 10.xxx.xxx.xxx parent 443 0 ssl no-query originserver >> login=PASS >> front-end-https=on sslkey=//usr/newrprgate/CertAuth/sslkey.key >> sslcert=//usr/newrprgate

Re: [squid-users] Exiting due to failures

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 14:24 +0100 skrev Jorge Bastos: > Howdy, > For the 1st time something like this happened to me. > What can be this failures? I mean, what type of failures? See your cache.log for further details. Regards Henrik

Re: [squid-users] prevent exe downloads from https sites

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 14:17 +0200 skrev Jakob Curdes: > - use a (commercial) product that intercepts https Or Squid-3.1 which does the same (with some limitations). Regards Henrik

Re: [squid-users] squid 3.1: How to setup a Squid SSL reverse proxy for a parent SSL Squid proxy?

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 02:38 -0700 skrev chrischni: > this is our cache_peer config: > > cache_peer 10.xxx.xxx.xxx parent 443 0 ssl no-query originserver login=PASS > front-end-https=on sslkey=//usr/newrprgate/CertAuth/sslkey.key > sslcert=//usr/newrprgate/CertAuth/sslcert.cert name=*.*.com Proba

Re: [squid-users] Squid crashes abnormally

2009-08-11 Thread Henrik Nordstrom
tis 2009-08-11 klockan 11:46 +0700 skrev Nyamul Hassan: > Hi, > > I've been using Squid.2.7.STABLE6 quite well till now. However, for the > past 4 - 5 days, it started crashing everytime it finished loading the store > directories (aufs + coss). Looking through the "cache.log", the following

Re: [squid-users] Squid and YahooMail

2009-08-11 Thread Henrik Nordstrom
mån 2009-08-10 klockan 22:01 -0400 skrev Rick Chisholm: > Our marketing dept. at work needs access to Yahoo Analytics, but they > have to login via Yahoo! regular login. Squid complains about a DNS > resolution issue but names the link as > > http://443 > > It's quite odd. Are you using an url

RE: [squid-users] [s uiqd-2.7STABLE6-1]Pr oblem RPC via HTTPS‏ [SOLVED]

2009-08-11 Thread hdyugoplastika hdyugoplastika
I have solved!!! There was one error in rpc client side(mine stupid type of error on user) and this is the final configuration(with loadbalance on cache_peer): acl all src all acl manager proto cache_object acl localhost src 127.0.0.1/32 acl to_localhost dst 127.0.0.0/8 acl SSL_ports port 443

[squid-users] Exiting due to failures

2009-08-11 Thread Jorge Bastos
Howdy, For the 1st time something like this happened to me. What can be this failures? I mean, what type of failures? Jorge, -- Aug 11 12:57:01 cisne squid[28669]: Squid Parent: child process 9216 exited due to signal 6 Aug 11 12:57:04 cisne squid[28669]: Squid Parent: child process 9448

Re: [squid-users] prevent exe downloads from https sites

2009-08-11 Thread Jakob Curdes
Werner Müller schrieb: Hi all, I want to prevent downloads with extension .exe. Here the lines in my squid.conf file for windows squid version 2.6: acl downloads url_regex -i \.exe$ http_access deny downloads Now I can prevent exe-downloads from http-Sites. But it is not working for https-Sites.

Re: [squid-users] Polling Squid with OpenNMS

2009-08-11 Thread Kinkie
On Wed, Aug 5, 2009 at 2:16 AM, James Zuelow wrote: > A while back (as in a few months) I mentioned monitoring Squid with OpenNMS. > > I received two requests offline for my configuration information, but I've > been too busy to document it. > > I just put partial docs up at > http://www.opennms.

[squid-users] can't access javascript enable website

2009-08-11 Thread Jon Tim
Hi Squid Support, I'm using squid squid-2.6.STABLE22-1.fc8 from Fedora 8. I can use squid and SquidGuard without having any problems. But, today, one of the user complaints that she can't browse http://www.sdf.gov.sg website. I try without using squid proxty and it works OK. I look into more

[squid-users] prevent exe downloads from https sites

2009-08-11 Thread Werner Müller
Hi all, I want to prevent downloads with extension .exe. Here the lines in my squid.conf file for windows squid version 2.6: acl downloads url_regex -i \.exe$ http_access deny downloads Now I can prevent exe-downloads from http-Sites. But it is not working for https-Sites. How can I adjust my confi

Re: [squid-users] Squid crashes - Create Bugreport?

2009-08-11 Thread axe
Hi, thank you very much. That was the information I searched all the time. I am going to report this to the Debian Maintainer. On Tue, 11 Aug 2009 11:29:28 +0200, Silamael wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Thomas Jackowski wrote: >> Hi, >> >> Squid crashes with this

Re: [squid-users] squid 3.1: How to setup a Squid SSL reverse proxy for a parent SSL Squid proxy?

2009-08-11 Thread chrischni
fulanpeng wrote: > > Hi, > > I have a Squid reverse proxy running with SSL support. People can > access it with https://domainA.com. No problem. > Now I want to set up another Squid proxy server to proxy it with SSL > support. > That means https://domainA --> https://domainB. > > My configu

Re: [squid-users] Squid crashes - Create Bugreport?

2009-08-11 Thread Silamael
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thomas Jackowski wrote: > Hi, > > Squid crashes with this message in cache.log: > > 2009/08/11 06:54:31| assertion failed: store_client.cc:430: > "STORE_DISK_CLIENT == getType()" > 2009/08/11 06:54:35| Starting Squid Cache version 3.0.STABLE8 for > x

RE: [squid-users] [s uiqd-2.7STABLE6-1]Pr oblem RPC via HTTPS‏

2009-08-11 Thread hdyugoplastika hdyugoplastika
Hi Amos I have "cleared" the configuration: acl all src all acl manager proto cache_object acl localhost src 127.0.0.1/32 acl SSL_ports port 443 acl Safe_ports port 80 acl Safe_ports port 443 acl CONNECT method CONNECT http_access allow manager localhost http_access deny manager http_access deny

AW: [squid-users] Squid crashes - Create Bugreport?

2009-08-11 Thread Zeller, Jan
Hi, i am actually using 3.0.STABLE18 in a production environment and it does very well. No such 'assertion failed' problems. You should upgrade... regards, Jan > -Ursprüngliche Nachricht- > Von: Thomas Jackowski [mailto:a...@hadiko.de] > Gesendet: Dienstag, 11. August 2009 08:56 > An: