Re: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Milen Pankov
On 19.03.2012 07:35, Amos Jeffries wrote: > Tried the current 3.1.19 release? > > Is the second HTTPS request even going through the proxy? > > What is the rest of the config look like? > The partial piece of config you posted has no holes which this could be > using. > > Amos Hi, Thank you for

[squid-users] Unable to open HTTP Socket in syslog

2012-03-19 Thread zozo zozo
That's what I get in syslog. squid starts, then dies after a few seconds. Cache log doesn't show anything about exit reasons. userdemo@ubuntu-demo:~$ sudo cat /var/log/syslog |tail Mar 19 16:01:01 ubuntu-demo (squid-1): Unable to open HTTP Socket Mar 19 16:01:01 ubuntu-demo squid[1173]: Squid Par

Re: [squid-users] Unable to open HTTP Socket in syslog

2012-03-19 Thread Fried Wil
Hi Igor, Any same port is open ? Squid works on 3128/tcp or other ? Could you netstat -anop | grep PORT to know if u have any other software tooks the same port. On Mon, Mar 19, 2012 at 04:18:07PM +0400, zozo zozo wrote: > That's what I get in syslog. squid starts, then dies after a few secon

Re: [squid-users] Unable to open HTTP Socket in syslog

2012-03-19 Thread Helmut Hullen
Hallo, zozo, Du meintest am 19.03.12: > userdemo@ubuntu-demo:~$ sudo cat /var/log/syslog |tail > Mar 19 16:01:01 ubuntu-demo (squid-1): Unable to open HTTP Socket > Mar 19 16:01:01 ubuntu-demo squid[1173]: Squid Parent: (squid-1) > process 1193 exited with status 1 Please try to start "squid" ag

[squid-users] whitelisted IP problem

2012-03-19 Thread Vijay S
Hi I have a my server box hosting apache and squid on centos machine. When I send my request for clients feeds it works as they have whitelisted my IP address, and when I make the call via squid its give me invalid IP. I checked the access log for more information and found out instead of sending

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Edmonds Namasenda
Vijay, Just a quick look has shown me you did not specify your network and there are a few typo errors. Re-adjust, test, and fill us in some more. I.P.N Edmonds Systems | Networks | ICTs UgM: +256 71 227 3374 | TzM: +255 68 422 1561 # 22249, Kampala Uganda. -Original Message- From: Vijay

Re: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Matus UHLAR - fantomas
On 19.03.2012 07:35, Amos Jeffries wrote: Tried the current 3.1.19 release? Is the second HTTPS request even going through the proxy? What is the rest of the config look like? The partial piece of config you posted has no holes which this could be using. On 19.03.12 11:53, Milen Pankov wrote:

RE: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay
I am still a beginner, I googled some site and found this configuration initially it was this # # Recommended minimum configuration: # acl manager proto cache_object acl server src 192.168.1.10 acl localhost src 192.168.1.0/32 ::1 acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1 # Example rule a

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay S
DO i have to do any IP tables configurations for this as well? On Mon, Mar 19, 2012 at 10:57 PM, Vijay wrote: > I am still a beginner, I googled some site and found this configuration > initially it was this > > > # > # Recommended minimum configuration: > # > acl manager proto cache_object > acl

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Edmonds Namasenda
You might need a firewall of sorts. And, you need to specify your LAN's network (s) in Squid conf. I.P.N Edmonds Systems | Networks | ICTs UgM: +256 71 227 3374 | TzM: +255 68 422 1561 # 22249, Kampala Uganda. -Original Message- From: Vijay S Date: Mon, 19 Mar 2012 23:22:30 To: ; Subje

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay S
I have mentioned my LAN network as 192.168.1.0/32 was that not enough, am i missing something in below configuration? On Mon, Mar 19, 2012 at 11:28 PM, Edmonds Namasenda wrote: > You might need a firewall of sorts. > And, you need to specify your LAN's network (s) in Squid conf. > > I.P.N Edmond

Re: [squid-users] Fwd: Forwarding Integrated Authentication for Terminal Server / Citrix users.

2012-03-19 Thread Chris Waters
On 1/10/12 4:48 PM, "Amos Jeffries" wrote: >On 11.01.2012 02:55, Jason Fitzpatrick wrote: >> Hi all >> >> We are in the process of replacing an ISA cluster with a Squid >> Cluster >> (Squid Cache: Version 3.1.14) and have run into some issues with the >> forwarding of credentials to an upstream

Re: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Milen Pankov
On 19.03.2012 19:09, Matus UHLAR - fantomas wrote: > > it's impossible for the proxy to pass error page to the browser, when > the user bypasses the proxy and connects to the website directly. > > You must deny direct access to HTTPS (port 443) sites by a firewall and > force browsers to use the

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Eliezer Croitoru
On 19/03/2012 18:58, Vijay S wrote: Hi I have a my server box hosting apache and squid on centos machine. When I send my request for clients feeds it works as they have whitelisted my IP address, and when I make the call via squid its give me invalid IP. I checked the access log for more informa

Re[2]: [squid-users] Unable to open HTTP Socket in syslog

2012-03-19 Thread zozo zozo
OK, if anyone encounters this, the interface that had the IP wasn't up at the moment (it's wireless and is cfg-ed via hostapd) So running ifup first solved the problem. Thank you for answers anyway. Sorry for posting a dumb question, if anyone runs into similar dumb problem, hope it helps :)

Re[3]: [squid-users] Unable to open HTTP Socket in syslog

2012-03-19 Thread zozo zozo
Anyway, squid.pid isn't cleared in case of such exit, and squid -k ... complains on non-existent process Tue, 20 Mar 2012 01:57:37 +0400 от zozo zozo : > OK, if anyone encounters this, the interface that had the IP wasn't up at the > moment (it's wireless and is cfg-ed via hostapd) > So running

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay S
Sorry i cannot share the url and hence im replacing the feed as http://feeds.example.com/newsfeeds.xml On Tue, Mar 20, 2012 at 1:37 AM, Eliezer Croitoru wrote: > On 19/03/2012 18:58, Vijay S wrote: >> >> Hi >> >> I have a my server box hosting apache and squid on centos machine. >> When I send my

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay S
Hi Eliezer I did access your url and it gave me the output as Your IP address is : 122.166.1.184 I also tried doing request_header_access X-Forwarded-For deny Safe_ports Still no luck, log is as follows 1332199742.075 2 192.168.1.117 TCP_DENIED/403 3481 CONNECT feeds.example.com:80 - NONE/

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Eliezer Croitoru
On 20/03/2012 00:36, Vijay S wrote: Sorry i cannot share the url and hence im replacing the feed as http://feeds.example.com/newsfeeds.xml On Tue, Mar 20, 2012 at 1:37 AM, Eliezer Croitoru wrote: On 19/03/2012 18:58, Vijay S wrote: Hi I have a my server box hosting apache and squid on cento

Re: [squid-users] whitelisted IP problem

2012-03-19 Thread Eliezer Croitoru
On 20/03/2012 01:40, Vijay S wrote: Hi Eliezer I did access your url and it gave me the output as Your IP address is : 122.166.1.184 I also tried doing request_header_access X-Forwarded-For deny Safe_ports Still no luck, log is as follows 1332199742.075 2 192.168.1.117 TCP_DENIED/403 348

Re: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Amos Jeffries
On 20.03.2012 08:46, Milen Pankov wrote: On 19.03.2012 19:09, Matus UHLAR - fantomas wrote: it's impossible for the proxy to pass error page to the browser, when the user bypasses the proxy and connects to the website directly. You must deny direct access to HTTPS (port 443) sites by a firew

[squid-users] Transparent proxy and ppp

2012-03-19 Thread zozo zozo
Hi all I've setup squid and it works if I forward network from eth0 to wlan0 (ap mode) But if instead of ethernet I try to use ppp0 packets, squid doesn't forward stuff, and in access log entries were something like 0_ABORTED (don't have those logs at hand, will provide more info tomorrow) Ports

[squid-users] trying to debug 3.2.0.16 behavier with workers.

2012-03-19 Thread Eliezer Croitoru
i have a small Gentoo X86_64 with kernel 3.2.1 with squid 3.2.0.16 that is crashing after a while when using workers. i'm trying to debug it but have no clue on what debug flags to use in order to get some data on it. i have the cache logs stored so i can extract some basic data but i dont kno

Re: [squid-users] trying to debug 3.2.0.16 behavier with workers.

2012-03-19 Thread Amos Jeffries
On 20.03.2012 15:34, Eliezer Croitoru wrote: i have a small Gentoo X86_64 with kernel 3.2.1 with squid 3.2.0.16 that is crashing after a while when using workers. i'm trying to debug it but have no clue on what debug flags to use in order to get some data on it. i have the cache logs stored so i

Re: [squid-users] Transparent proxy and ppp

2012-03-19 Thread Amos Jeffries
On 20.03.2012 15:30, zozo zozo wrote: Hi all I've setup squid and it works if I forward network from eth0 to wlan0 (ap mode) But if instead of ethernet I try to use ppp0 packets, squid doesn't forward stuff, and in access log entries were something like 0_ABORTED (don't have those logs at hand

Re: [squid-users] trying to debug 3.2.0.16 behavier with workers.

2012-03-19 Thread Eliezer Croitoru
On 20/03/2012 04:50, Amos Jeffries wrote: On 20.03.2012 15:34, Eliezer Croitoru wrote: i have a small Gentoo X86_64 with kernel 3.2.1 with squid 3.2.0.16 that is crashing after a while when using workers. i'm trying to debug it but have no clue on what debug flags to use in order to get some da

Re: [squid-users] Transparent proxy and ppp

2012-03-19 Thread Benjamin E. Nichols
I know this is just my opinion, but, if it was me I would use a dedicated hardware device as the vpn/ppp client and just pipe that out to a switch to make things less complicated Like you could use a DDWRT enabled router, or Many other platforms to do this dirtywork for you. That way your wo

[squid-users] error "Detected Dead Parent" in cache

2012-03-19 Thread milo mixy
Hi, any idea what could be causing “Detected DEAD Parent: proxy1.test.au/3128 failed”     2012/03/20 11:29:38| helperOpenServers: Starting 10 'squid_ldap_auth' processes 2012/03/20 11:29:38| helperOpenServers: Starting 5 'squid_ldap_group' processes 2012/03/20 11:29:38| Accepting proxy HTTP c

Re: [squid-users] error "Detected Dead Parent" in cache

2012-03-19 Thread Amos Jeffries
On 20.03.2012 16:25, milo mixy wrote: Hi, any idea what could be causing “Detected DEAD Parent: proxy1.test.au/3128 failed” Huge big hint right here: 2012/03/20 11:29:40| TCP connection to proxy1.test.au /3128 failed 2012/03/20 11:29:43| TCP connection to  proxy1.test.au /3128 failed 2012/

RE: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Vishal Agarwal
Hi, You require to deny the db_auto just after the allow statement (See below ). I hope that will work. Thanks/regards, Vishal Agarwal -Original Message- From: Milen Pankov [mailto:m...@milen.pankov.eu] Sent: Monday, March 19, 2012 5:34 AM To: squid-users@squid-cache.org Subject: [squi

RE: [squid-users] whitelisted IP problem

2012-03-19 Thread Vishal Agarwal
The LAN network should be 192.168.1.0/24 , not /32. Thanks/regards, Vishal Agarwal -Original Message- From: Vijay S [mailto:vi...@reactmedia.com] Sent: Tuesday, March 20, 2012 12:02 AM To: namase...@gmail.com Cc: squid-users@squid-cache.org Subject: Re: [squid-users] whitelisted IP prob

Re: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Amos Jeffries
On 20/03/2012 5:26 p.m., Vishal Agarwal wrote: Hi, You require to deny the db_auto just after the allow statement (See below ). I hope that will work. That should be meaningless: if logged in will allow, else if logged in will deny. Missing a '!' ? The final diagnosis of this problem is t

RE: [squid-users] SSL sites bypass authentication

2012-03-19 Thread Vishal Agarwal
Hi Amos, You are right. Will this work with transferring all the traffic to http port from iptables ? Iptables -t nat -A PREROUTING -s 192.168.1.0/24 -p tcp --dport 80 -j REDIRECT --to-destination serverip:3128 And further checking the traffic in squid Acl safe_ports port 443 # Secure port

RE: [squid-users] whitelisted IP problem

2012-03-19 Thread Vijay
Hi Everyone Thanks for your help, I got it working now. but now a new problem has come up when I use squidclient it works perfectly whereas when I try using the php it does not.. If anybody can help me decode the below cache.log it will be of great help 2012/03/20 10:14:23.889| aclCheckFast: li