[squid-users] NULL characters in Header - how to get which sites generate this?

2012-09-13 Thread x-man
Hi, my cache.log file is full of this kind of messages: Content-Type: application/x-www-form-urlencoded 2012/09/13 17:39:35| WARNING: HTTP header contains NULL characters {Accept: */* Content-Type: application/x-www-form-urlencoded} NULL {Accept: */* Content-Type: application/x-www-form-urlencode

[squid-users] Re: error:invalid-request

2012-09-13 Thread x-man
Hi, I have similar issue, the question is how to identify the Sites that are using such "unknown to squid" protocols so I can bypass them on firewall level. >From the LOG i cannot get the dst IP or dst domain? Then how to get this info? -- View this message in context: http://squid-web-pro

[squid-users] Squid with LDAP digest error

2012-09-13 Thread Bijoy Lobo
Hello all, I am trying to make Squid + LDAP work with MD5 digest. Ive tried this command, echo '"usuario1":"Squid proxy-caching web server"' | /usr/lib/squid3/digest_ldap_auth -b "ou=people,dc=paladion,dc=com" -u "uid=%s" -A "userPassword" -D "cn=admin,dc=test,dc=com" -w "test@123" -e -v 3 -h 127

Re: [squid-users] FATAL: The ssl_crtd helpers are crashing too rapidly, need help!

2012-09-13 Thread Alex Crow
I have occasionally seen a couple of different problems with the SSL certificate database. One is where invalid certificates are generated somehow, such as when the signing certificate is no longer valid, and another is where the size file is empty. I think the problem with the size file has

Re: [squid-users] FATAL: The ssl_crtd helpers are crashing too rapidly, need help!

2012-09-13 Thread Alex Crow
On 13/09/12 14:33, Alex Crow wrote: I have occasionally seen a couple of different problems with the SSL certificate database. One is where invalid certificates are generated somehow, such as when the signing certificate is no longer valid, and another is where the size file is empty. I think

Re: [squid-users] Re: error:invalid-request

2012-09-13 Thread Eliezer Croitoru
On 09/13/2012 03:25 PM, x-man wrote: Hi, I have similar issue, the question is how to identify the Sites that are using such "unknown to squid" protocols so I can bypass them on firewall level. From the LOG i cannot get the dst IP or dst domain? Then how to get this info? you better monito

[squid-users] Log entry in access_log cut off when exceeding a certain length..

2012-09-13 Thread Essad Korkic
Hi All, I have an issue with the access_log of squid. It seems that a standard access_log entry cannot exceed a certain length. During some logfile analysis I noticed I had similar usernames, but not quite, as if they were not complete. After digging a bit deeper I found that if users browse to

[squid-users] Segfault on squid 3.1.X on Ubuntu 12.04 with external_acl_type

2012-09-13 Thread Marcio Merlone
Greetings, I am setting up a squid server on Ubuntu 12.04. It works fine except when I try to use external_acl_type, either squid_ldap_group and squid_unix_group. I was using stock 3.1.19 ubuntu package and also tried 3.1.20 from some ppa around. It looks very similar to http://www.squid-cach

Re: [squid-users] Segfault on squid 3.1.X on Ubuntu 12.04 with external_acl_type

2012-09-13 Thread Marcio Merlone
Em 13-09-2012 11:46, Marcio Merlone escreveu: I am setting up a squid server on Ubuntu 12.04. It works fine except when I try to use external_acl_type, either squid_ldap_group and squid_unix_group. I was using stock 3.1.19 ubuntu package and also tried 3.1.20 from some ppa around. It looks very

[squid-users] Squid Tproxy in Bridge Mode - Static Routes

2012-09-13 Thread Ulises Nicolini
Hello, I have a transparent proxy squid server work in bridge mode and tproxy with two interfaces : LAN and WAN. My clients are reachable by LAN interface by a group of gateways (Router 1, Router 2..Router(n)) CLIENTS (Network1)<>ROUTER1<

Re: [squid-users] Users cannot sign in to windows live messenger

2012-09-13 Thread Rafael Gomes
It happens here too :( On Mon, Dec 12, 2011 at 6:22 AM, Roland RoLaNd wrote: > > Some users cannot sign in to windows live messenger even though others can. > > here's my relevant config: > > #Msn messenger > acl msn urlpath_regex -i gateway.dll > acl msnd dstdomain acl msn dstdomain 64.4.13.0/2

Re: [squid-users] Squid Tproxy in Bridge Mode - Static Routes

2012-09-13 Thread Eliezer Croitoru
On 9/13/2012 6:17 PM, Ulises Nicolini wrote: Is possible create this routes dynamically when for example intercept the incoming traffic with iptables to redirect this to squid? Use static routes is very dificult to support, being necessary add or remove networks form squid server when my distribu

Re: [squid-users] Segfault on squid 3.1.X on Ubuntu 12.04 with external_acl_type

2012-09-13 Thread Eliezer Croitoru
On 9/13/2012 5:58 PM, Marcio Merlone wrote: Sorry, forgot this :) Sep 13 10:01:57 (pam_auth): pam_unix(squid:auth): authentication failure; logname= uid=13 euid=13 tty= ruser= rhost= user=marcio.merlone Sep 13 10:01:57 kernel: [ 711.170108] squid3[11856]: segfault at 40 ip 7f2aae7c43b7 sp

Re: [squid-users] Segfault on squid 3.1.X on Ubuntu 12.04 with external_acl_type

2012-09-13 Thread Marcio Merlone
Em 13-09-2012 14:55, Eliezer Croitoru escreveu: On 9/13/2012 5:58 PM, Marcio Merlone wrote: Sep 13 10:01:57 (pam_auth): pam_unix(squid:auth): authentication failure; logname= uid=13 euid=13 tty= ruser= rhost= user=marcio.merlone Sep 13 10:01:57 kernel: [ 711.170108] squid3[11856]: segfault at 4

Re: [squid-users] Segfault on squid 3.1.X on Ubuntu 12.04 with external_acl_type

2012-09-13 Thread Eliezer Croitoru
On 9/13/2012 10:28 PM, Marcio Merlone wrote: We can try to help you figure out some basics and to move on from there. What exactly do you need? LDAP or PAM? See above. PAM is required for auth, LDAP is not needed if squid_unix_group works - pam_ldap is working fine for users and auth. Complied l

[squid-users] Redirect https to http

2012-09-13 Thread David Touzeau
Dear I would like to create acl in order to redirect requests to https://www.youtube.com to http://www.youtube.com some firefox browsers go directly to youtube using ssl mode has the http mode is not a problem on youtube. Can anybody helps me about creating this kind of acls best regards