[squid-users] Re: SQUID3 and https: Error negotiating SSL connection

2013-02-21 Thread skylab
Hi, thank you for your replies. How can I verify my ca-certificate list? And how can I update it? Thank you very much. Skylab -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/SQUID3-and-https-Error-negotiating-SSL-connection-tp4658592p4658602.html Sent from

[squid-users] DNS Queue Remains Filled Issue!

2013-02-21 Thread Arshan Awais
Hi, I have a query regarding DNS Returned Timeout issue. I have searched over various forums regarding this issue but the solutions described there does not fit my need. Now coming to the issue, I have configured squid for web caching and allowed just 100MB disk space for caching. When i

[squid-users] Question about proxy_auth REQUIRED and the case of flushing the authentication-cache

2013-02-21 Thread Tom Tom
Hi With squid 3.2.7, I have the following curiosity: SCENARIO 1 squid.conf acl AUTHENTICATED proxy_auth REQUIRED external_acl_type SQUID_KERB_LDAP ttl=7200 children-max=20 children-startup=5 children-idle=1 negative_ttl=7200 %LOGIN /usr/local/squid/libexec/ext_kerberos_ldap_group_acl -g XXX acl

[squid-users] HAVP alternative for traffic scanning?

2013-02-21 Thread Henri Wahl
Hello world, does anybody know a good solution as replacement for the HTTP AntiVirus Proxy HAVP? We want to do online virus scanning, where HAVP does a good job, both there seems to be no much development (e.g. IPv6) and some performance issues. Therefore I am looking for an alternative. Thanks +

Re: [squid-users] HAVP alternative for traffic scanning?

2013-02-21 Thread Ralf Hildebrandt
* Henri Wahl h.w...@ifw-dresden.de: Hello world, does anybody know a good solution as replacement for the HTTP AntiVirus Proxy HAVP? We want to do online virus scanning, where HAVP does a good job, both there seems to be no much development (e.g. IPv6) and some performance issues. Therefore I

Re: [squid-users] HAVP alternative for traffic scanning?

2013-02-21 Thread Tom Tom
Hi We made good experience with Avira WebGate (Scanning only) and Avira WebGate-Suite (Scanning + URL-Filtering). But it's not open source... Regards, Tom On Thu, Feb 21, 2013 at 10:43 AM, Henri Wahl h.w...@ifw-dresden.de wrote: Hello world, does anybody know a good solution as replacement

Re: [squid-users] HAVP alternative for traffic scanning?

2013-02-21 Thread C. Pelissier
Le jeu. 21/02/2013 à 10:43, Henri Wahl a écrit : Hello world, does anybody know a good solution as replacement for the HTTP AntiVirus Proxy HAVP? We want to do online virus scanning, where HAVP does a good job, both there seems to be no much development (e.g. IPv6) and some performance

[squid-users] Re: ipv6 support for 3.1.16

2013-02-21 Thread anita
Hi Amos, Thanks for a very quick reply. I have a couple of more questions. 1. What is a WCCP setting? 2. How can I check if the ipv4-mapping feature is disabled or not available in my kernel? I am using Red Hat Linux 6.2 flavour with a GNU/Linux OS. Thanks in advance. Regards, Anita --

Re: [squid-users] Re: ipv6 support for 3.1.16

2013-02-21 Thread Alex Crow
Kaspersky do an icap server as well, and they are one of the best (obviously not gratis or libre but as it's ICAP it will work with Squid). Alex On 21/02/13 10:39, anita wrote: Hi Amos, Thanks for a very quick reply. I have a couple of more questions. 1. What is a WCCP setting? 2. How can I

[squid-users] Squid 3.1.8 and Kerberos authentication

2013-02-21 Thread Francesco
hello, i am trying Squid kerberos authentication instead of NTLM authentication due to resolve compatibility issue with latest version of windows. Only two things if i can: 1) in squid.conf, i have to specify windows user with the first capital letter. Ex: user = User@DOMAIN. If i specify

Re: [squid-users] HAVP alternative for traffic scanning?

2013-02-21 Thread Alex Rousskov
On 02/21/2013 03:21 AM, C. Pelissier wrote: Le jeu. 21/02/2013 à 10:43, Henri Wahl a écrit : Hello world, does anybody know a good solution as replacement for the HTTP AntiVirus Proxy HAVP? We want to do online virus scanning, where HAVP does a good job, both there seems to be no much

Re: [squid-users] Squid 3.1.8 and Kerberos authentication

2013-02-21 Thread Amos Jeffries
On 22/02/2013 5:06 a.m., Francesco wrote: hello, i am trying Squid kerberos authentication instead of NTLM authentication due to resolve compatibility issue with latest version of windows. Only two things if i can: 1) in squid.conf, i have to specify windows user with the first capital

Re: [squid-users] Re: ipv6 support for 3.1.16

2013-02-21 Thread Amos Jeffries
On 21/02/2013 11:39 p.m., anita wrote: Hi Amos, Thanks for a very quick reply. I have a couple of more questions. 1. What is a WCCP setting? Since you don't know it is probably not relevant. WCCP is a router protocol for controlling HTTP traffic interception by proxies. 2. How can I

Re: [squid-users] DNS Queue Remains Filled Issue!

2013-02-21 Thread Amos Jeffries
On 21/02/2013 9:06 p.m., Arshan Awais wrote: Hi, I have a query regarding DNS Returned Timeout issue. I have searched over various forums regarding this issue but the solutions described there does not fit my need. Now coming to the issue, I have configured squid for web caching and allowed

Re: [squid-users] Question about proxy_auth REQUIRED and the case of flushing the authentication-cache

2013-02-21 Thread Amos Jeffries
On 21/02/2013 9:47 p.m., Tom Tom wrote: Hi With squid 3.2.7, I have the following curiosity: SCENARIO 1 squid.conf acl AUTHENTICATED proxy_auth REQUIRED external_acl_type SQUID_KERB_LDAP ttl=7200 children-max=20 children-startup=5 children-idle=1 negative_ttl=7200 %LOGIN

Re: [squid-users] squid kerberos authenticators spamming AD and locking out users

2013-02-21 Thread Amos Jeffries
On 21/02/2013 7:20 p.m., Brett Lymn wrote: Folks, I am running 4 proxy servers with squid 3.1.19 (yes, I know it is old, will update soon) with kerberos authentication behind a F5 load balancer for a user community of about 2000 people using Windows/I.E.. Normally, this all works fine, people

RE: [squid-users] Redirect Youtube out second ISP

2013-02-21 Thread Stinn, Ryan
I ended up putting a second proxy up and using cache peer to redirect all traffic to it. Not the best solution but it's just a tiny VM fetching youtube. Ryan -Original Message- From: Pieter De Wit [mailto:pie...@insync.za.net] Sent: Wednesday, February 20, 2013 10:57 AM To:

[squid-users] tproxy configuration

2013-02-21 Thread Roman Gelfand
Please, find below the network topology, squid.conf and rc.local configuration files. It appears that the squid is not routing the http requests. I am not sure what I am doing wrong here Please note, the same squid.conf works on transparent proxy (non tproxy), for the exception of tproxy

Re: [squid-users] SQUID3 and https: Error negotiating SSL connection

2013-02-21 Thread Guy Helmer
On Feb 21, 2013, at 2:04 AM, skylab skyla...@gmail.com wrote: Hi, thank you for your replies. How can I verify my ca-certificate list? And how can I update it? Thank you very much. Skylab It depends on your O/S. Linux and *BSDs keep the certs updated through packages. If you have

Re: [squid-users] Squid 3.3.1 Compiler Error

2013-02-21 Thread Amos Jeffries
FTR: please report this type of problem to bugzilla in future. On 21/02/2013 2:50 a.m., Adam W. Dace wrote: OS: Mac OS X v10.7.5 Xcode: Xcode v4.6 GCC: GCC v4.2.1 Configure Command: ./configure I've tried a few things and squid just won't compile for me. Here's the relevant make output:

Re: [squid-users] tproxy configuration

2013-02-21 Thread Amos Jeffries
On 22/02/2013 11:03 a.m., Roman Gelfand wrote: Please, find below the network topology, squid.conf and rc.local configuration files. It appears that the squid is not routing the http requests. I am not sure what I am doing wrong here Please note, the same squid.conf works on transparent

Re: [squid-users] Redirect Youtube out second ISP

2013-02-21 Thread Amos Jeffries
On 22/02/2013 11:02 a.m., Stinn, Ryan wrote: I ended up putting a second proxy up and using cache peer to redirect all traffic to it. Not the best solution but it's just a tiny VM fetching youtube. Ryan Why did you avoid the TOS methods? much simpler than double-proessing all the HTTP

[squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-21 Thread Markus Moeller
I don't think this has to do with squid and Kerberos. This is a Windows client only issue. Usually the user should be prompted by Windows to update the password. If the user does not update the password the client won't get a Kerberos ticket and will fallback to NTLM if that also doesn't work

Re: [squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-21 Thread Brett Lymn
On Thu, Feb 21, 2013 at 11:23:32PM +, Markus Moeller wrote: I don't think this has to do with squid and Kerberos. Reasonably sure it does - for a start the machine that AD says is causing the errors is one of the proxy servers and if we restart squid on that particular machine the problem

Re: [squid-users] Squid 3.1.8 and Kerberos authentication

2013-02-21 Thread Francesco
Hello Amos, happy to hear from you! 1) in squid.conf, i have to specify windows user with the first capital letter. Ex: user = User@DOMAIN. If i specify user@DOMAIN i have no authentication to surf Case sensitivity has nothing to do with Squid. The user details are part of the encrypted

Re: [squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-21 Thread Amos Jeffries
On 22/02/2013 12:34 p.m., Brett Lymn wrote: On Thu, Feb 21, 2013 at 11:23:32PM +, Markus Moeller wrote: I don't think this has to do with squid and Kerberos. Reasonably sure it does - for a start the machine that AD says is causing the errors is one of the proxy servers and if we restart

Re: [squid-users] Squid 3.1.8 and Kerberos authentication

2013-02-21 Thread Amos Jeffries
On 22/02/2013 12:58 p.m., Francesco wrote: Hello Amos, happy to hear from you! 1) in squid.conf, i have to specify windows user with the first capital letter. Ex: user = User@DOMAIN. If i specify user@DOMAIN i have no authentication to surf Case sensitivity has nothing to do with Squid. The

Re: [squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-21 Thread Brett Lymn
On Fri, Feb 22, 2013 at 01:18:53PM +1300, Amos Jeffries wrote: What happens if you leave Squid running but terminate the TCP connections open between Squid and the AD server? We have not tried doing that, I will give it a try if I get a chance. Or just the TCP connections client-Squid

Re: [squid-users] tproxy configuration

2013-02-21 Thread Roman Gelfand
On Thu, Feb 21, 2013 at 6:10 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 22/02/2013 11:03 a.m., Roman Gelfand wrote: Please, find below the network topology, squid.conf and rc.local configuration files. It appears that the squid is not routing the http requests. I am not sure what I

Re: [squid-users] tproxy configuration

2013-02-21 Thread Amos Jeffries
On 22/02/2013 5:07 p.m., Roman Gelfand wrote: On Thu, Feb 21, 2013 at 6:10 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 22/02/2013 11:03 a.m., Roman Gelfand wrote: Please, find below the network topology, squid.conf and rc.local configuration files. It appears that the squid is not