Re: [squid-users] Squid 3.3.3 is available

2013-03-14 Thread Jose-Marcio Martins
Brett Lymn wrote: On Thu, Mar 14, 2013 at 01:23:40PM +1300, Amos Jeffries wrote: ... CFLAGS=-m32 export CFLAGS I guess this works around the ELFCLASS32 problem but it does have the side effect of limiting the amount of memory squid can use, no? This is a something left from some old

[squid-users] Dynamic SSL

2013-03-14 Thread Hasanen AL-Bana
Hi, I have successfully installed squid 3.3 compiled with ssl support Interception SSL traffic is working fine with browsers loaded with my self created .DER file. But without it , I keep getting browser warningings , chrome doesn't work at all with gmail in this case. My SSL settings are :

[squid-users] Squid 3.3.3 issues...

2013-03-14 Thread John Doe
Hi, I replaced my old 2.7.STABLE9 reverse proxy with a 3.3.3. I tried smp but found out that aufs does not support it, right?   BUG 3279: HTTP reply without Date: I saw that you can set a cache_dir per worker; but is it some kind of consistent hashing with objects going always going to the same

Re: [squid-users] Dynamic SSL

2013-03-14 Thread Guy Helmer
On Mar 14, 2013, at 7:22 AM, Hasanen AL-Bana hasa...@gmail.com wrote: Hi, I have successfully installed squid 3.3 compiled with ssl support Interception SSL traffic is working fine with browsers loaded with my self created .DER file. But without it , I keep getting browser warningings ,

Re: [squid-users] Dynamic SSL

2013-03-14 Thread Guy Helmer
On Mar 14, 2013, at 9:23 AM, Hasanen AL-Bana hasa...@gmail.com wrote: I thought Squid can fetch the original certificate for a website and pass it to the browser instead of the one created by me, Isn't that how dynamic ssl generation should work ? No, there are two parts for the asymmetric

[squid-users] assertion failed: client_side.cc:3584: !switchedToHttps_

2013-03-14 Thread Sébastien WENSKE
Hi List, I just install from sources the last 3.2.9 squid with ssl-bump feature. It works fine, except that I get random crashes as you can see below: [...] 2013/03/14 16:48:45 kid1| assertion failed: client_side.cc:3584: !switchedToHttps_ 2013/03/14 16:48:48 kid1| Starting Squid Cache version

Re: [squid-users] Re: Re: kerberos auth failing behind a load balancer

2013-03-14 Thread Sean Boran
Markus, The klist outputs are further below, but I have the feeling that is not the problem, that the solution needs to be different (after reading the following articles). See for example: the thing to watch out for is that AD will fail to return a ticket if the SPN requested is found on more

Re: [squid-users] Dynamic SSL

2013-03-14 Thread Hasanen AL-Bana
Thank you Guy for your clarification, So you are saying that the only way to achieve squid https interception is to force users to upload our squid certificate to their browser, or they will have to deal with the browser warnings On Thu, Mar 14, 2013 at 5:29 PM, Guy Helmer

[squid-users] Dynamic content caching in Squid 3.2 vs 3.1

2013-03-14 Thread Jon Schneider
I have setup squid 3.2.7 in a test environment in preparation to roll it out to production, however I have noticed a difference in caching behavior that I have as of yet been unable to resolve. The squid config files are almost identical with the exception of two config lines that are now

RE: [squid-users] Dynamic SSL

2013-03-14 Thread Sébastien WENSKE
Hi Hasanen, All certificates are generated on-the-fly by your Squid CA - who is sefl-signed. So you have to install/deploy this self-signed Root CA on all your clients. Cheers! Sebastien WENSKE -Message d'origine- De : Hasanen AL-Bana [mailto:hasa...@gmail.com] Envoyé : jeudi 14 mars

Re: [squid-users] Dynamic content caching in Squid 3.2 vs 3.1

2013-03-14 Thread Amos Jeffries
On 15/03/2013 6:59 a.m., Jon Schneider wrote: I have setup squid 3.2.7 in a test environment in preparation to roll it out to production, however I have noticed a difference in caching behavior that I have as of yet been unable to resolve. The squid config files are almost identical with the

Re: [squid-users] Squid 3.3.3 issues...

2013-03-14 Thread Amos Jeffries
On 15/03/2013 2:59 a.m., John Doe wrote: Hi, I replaced my old 2.7.STABLE9 reverse proxy with a 3.3.3. I tried smp but found out that aufs does not support it, right? Right. BUG 3279: HTTP reply without Date: I think we have a good idea what is causing that one now, but no good fix

Re: [squid-users] Re: Re: kerberos auth failing behind a load balancer

2013-03-14 Thread Brett Lymn
On Thu, Mar 14, 2013 at 05:10:23PM +0100, Sean Boran wrote: See for example: the thing to watch out for is that AD will fail to return a ticket if the SPN requested is found on more than one account (because it doesn't know which account to use). So be careful that you do not accidentally