[squid-users] ICAP: fake user and new icap header X-Authenticated-Groups

2008-04-04 Thread Arno _
one) have a mix environment with authenticated pr= oxy and some other not ((can be for automated system or whatever you want) regards, arno _ Connect to the next generation of MSN Messenger  http://imagine-msn.com/messenger/launch

[squid-users] wbinfo_group.pl not finding group of user,but wbinfo -g working

2005-10-14 Thread Arno . STREULI
fo_group.pl acl webuser external NT_global_group D-BI1\SurfeursWebCH D-BI1\SurfeursWebCH-T http_access allow ci-src auth webuser http_access deny all any clue what is not working ? Arno Streuli ** DISCLAIMER - E-MAIL

[squid-users] Problem when trying to authenticate to a remote http server for download

2005-10-13 Thread Arno . STREULI
the code: TCP_MISS/401 What is wrong ? squid 2.5S11 on Solaris 8 and Samba 3.0.20a thanks regards, Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient

[squid-users] access denied with 2.5S11, but ok wiht 2.5S9 same config

2005-10-04 Thread Arno . STREULI
Hello, I juste create a new proxy with squid 2.5S11 on solaris 8, I take the same config (exceopt of the name of the server) that the one is running in production on another server. But I get an access denied. here is the cache.log (I don0't know why I got that on log, i didn't ask for any debug or

[squid-users] Error on ntlm_ssp

2005-10-03 Thread Arno . STREULI
Anyone got that on squid 2.5Stable 10 on solaris 8? [2005/10/03 14:16:06, 1] libsmb/ntlmssp.c:ntlmssp_update(252) got NTLMSSP command 3, expected 1 that hang most of my ntlm auth ! thanks Arno Streuli ** DISCLAIMER - E-MAIL

Re: [squid-users] Error in ntlm_auth

2005-10-02 Thread Arno . STREULI
No solution was given before. But Now I have one. As you said access right is a step to look for. My squid user did have the correct right that why I was unable to access the smb.conf. Quite strange the error message that as nothing to do about access rigth. anyway thanks. regards Arno Streuli

[squid-users] Error in ntlm_auth

2005-09-30 Thread Arno . STREULI
level = 1 wins server = 10.17.12.9, 10.17.17.8 idmap uid = 1-2 idmap gid = 1-2 winbind use default domain = Yes not that mutch, and every wbinfo test are working. I'm deperated, anyone can help ? thanks in advance, regards, Arno St

Re: [squid-users] error in the test with wbinfo but authentication working with squid

2005-09-29 Thread Arno . STREULI
lient plaintext auth = No name resolve order = wins host wins server = 10.17.12.9, 10.17.17.8 idmap uid = 1-2 idmap gid = 1-20000 Arno St

[squid-users] error in the test with wbinfo but authentication working with squid

2005-09-29 Thread Arno . STREULI
sword authentication failed error code was NT_STATUS_TRUSTED_DOMAIN_FAILURE (0xc18c) error messsage was: Trusted domain failure Could not authenticate user domain\\bj% with plaintext password but if I use squid and ntlm_auth every thing is working fine !??! Any one can explain ? thanks regards,

Re: [squid-users] record domain\\username without doing any kind of authentication

2005-09-21 Thread Arno . STREULI
the username is who is logged on the computer. I don't see what is funny, that can help to trace who access what on the net !?! Since a computer can be used by many person. I was thinking about doing a kind of ntlm excahnge without testing the the result with the Windows DC (or LDAP)

[squid-users] record domain\\username without doing any kind of authentication

2005-09-21 Thread Arno . STREULI
Hello, is it possible to record the username (with domain) of all request made through squid, but without doing any kind of authnetication ? how can I do that ? (on squid 2.5S10 on Solaris 8) thanks for the info, regards, Arno Streuli

Re: [squid-users] Re: can't start squid 10 latest compile

2005-08-24 Thread Arno . STREULI
lue for me ? regards Arno Streuli Sera

Re: [squid-users] Re: can't start squid 10 latest compile

2005-08-23 Thread Arno . STREULI
ry to recompile samba with thie GCC to see if that change anything. Arno Streuli Serassio

[squid-users] warining in HTTP header

2005-08-22 Thread Arno . STREULI
Hello, anyone know whta that mean ? (squid 2.5stable9 on solaris 8) 2005/08/22 03:05:37| WARNING: unparseable HTTP header field {GET /scripts/autore fresh/GetTechnicalAppletData.asp?command=fetchIntraday&Days=1¤cyPair=EURUS D HTTP/1.1} thanks Arno Streuli Crédit Agricole (Suisse) SA Chemi

[squid-users] Re: can't start squid 10 latest compile

2005-08-22 Thread Arno . STREULI
pt/ssl/lib" export CPPFLAGS="-I/opt/include -I/opt/ssl/include" export LD_LIBRARY_PATH=/lib:/opt/lib:/opt/ssl/lib export LD_RUN_PATH=/lib:/opt/lib:/opt/ssl/lib the bind I have installed is 9.2.3 Arno Streuli Crédit Agricole (Suisse) SA Chemin de Bérée 46-48, ch

[squid-users] Re: can't start squid 10 latest compile

2005-08-21 Thread Arno . STREULI
descriptors available 2005/08/22 07:53:14| Performing DNS Tests... 2005/08/22 07:53:14| Successful DNS name lookup tests... Illegal Instruction have you more infot to try for me ? regards Arno Streuli Crédit Agricole (Suisse) SA Chemin de Bérée 46-48, ch-1010 Lausanne 10 Tél. +41 58 321.5215 - Fax

Re: [squid-users] can't start squid 10 latest compile

2005-08-19 Thread Arno . STREULI
2005/08/18 23:26:40| Adding nameserver 127.0.0.1 from /etc/resolv.conf 2005/08/18 23:26:40| helperStatefulOpenServers: Starting 64 'ntlm_auth' processes 2005/08/18 23:26:46| helperOpenServers: Starting 40 'wbinfo_group.pl' processes Arno Streuli Crédit Agricole (Suisse) SA Chemi

[squid-users] can't start squid 10 latest compile

2005-08-19 Thread Arno . STREULI
file descriptors available 2005/08/19 10:21:41| Performing DNS Tests... 2005/08/19 10:21:41| Successful DNS name lookup tests... and the dns is working fine. any clue what is wrong ? Arno Streuli ** DISCLAIMER - E-MAIL

Re: [squid-users] Need help on error with ntlm_auth processs

2005-08-03 Thread Arno . STREULI
142.9, 10.137.167.8 idmap uid = 1-2 idmap gid = 1-2 any other clue !! Arno Streuli Crédit Agricole (Suisse) SA Chemin de Bérée 46-48, ch-1010 Lausanne 10 Tél. +41 58 321.5215 - Fax +41 58 321.5251 http://www.ca-suiss

Re: [squid-users] Need help on error with ntlm_auth processs, MORE INFO

2005-08-02 Thread Arno . STREULI
= squid4 server string = squid4 proxy %v encrypt passwords = Yes client ntlmv2 auth = yes preferred master = No local master = No domain master = No name resolve order = wins host bcast wins server = 10.137.142.9 10.137.167.8 Arno Streuli

[squid-users] Need help on error with ntlm_auth processs

2005-08-02 Thread Arno . STREULI
can you tell me what is wrong with my instalation, I'm always getting this error: ntlm_auth: error opening config file /usr/local/samba/lib/smb.conf. Error was Illegal byte sequence Thanks for any tips, regards,

Re: [squid-users] Problem with squid 2.5 S10

2005-07-07 Thread Arno . STREULI
hmm can be. I'm gona check that option ! Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain certain privilege

[squid-users] Problem with squid 2.5 S10

2005-07-07 Thread Arno . STREULI
skdSend: msgsnd: (11) Resource temporarily unavailable 2005/07/07 09:19:07| storeDiskdSend UNLINK: (11) Resource temporarily unavailable 2005/07/07 09:19:07| ctx: exit level 0 Any clue why how to fix it ? (the last time I had that the server crash after a while) thanks for any

[squid-users] Now squid crash du to a Resource temporarily unavailable !?!?

2005-07-06 Thread Arno . STREULI
0 # cache log file path cache_store_log none cache_access_log /opt/squid/logs/access.log cache_log /opt/squid/logs/cache.log pid_filename /opt/squid/logs/squid.pid redirect_children 20 coredump_dir /usr/local/squid/var forwarded_for off hierarchy_stoplist cgi-bin ?

Re: [squid-users] Problem on Authentication !??!

2005-07-06 Thread Arno . STREULI
Well it's on basic auth, and it's setup to 2hours so ? Arno Streuli

Re: [squid-users] Problem on Authentication !??!

2005-07-06 Thread Arno . STREULI
webuserAutre external NT_global_group D-CH-BAM1\SurfeursWebBAMCH D-CH-HCI1\SurfeursWebHCICH acl auth proxy_auth REQUIRED acl ca-src src 10.137.0.0/255.255.0.0 http_access deny ftp !techuser http_access allow ca-src auth webuserCA http_access allow !ca-src auth webuserAutre http_access deny all Arno

[squid-users] Problem on Authentication !??!

2005-07-06 Thread Arno . STREULI
Hello, My squid 2.5S9 is working fin, whel almost, once in a while it ask me fot my username/password via a prompt !? and I can't trace why is that ? anyone have anyidea how/where I can track trace that problem ? thanks for your help Arno Streuli PS: it's running on Solaris 8 and sam

RE: [squid-users] Run 2 squids on same computer

2005-07-04 Thread Arno . STREULI
yes you can create 2 squid.conf with 2 squid.pid and 2 different ports look on google I'm sure you will find it. many many time this question comme out ! regards,

[squid-users] sometime I've got a popup asking for username password !?! Why

2005-06-30 Thread Arno . STREULI
y ftp !techuser http_access allow cai-auth webuser http_access deny all Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain ce

[squid-users] How can I avoid of that httpReadReply: Excess data from

2005-06-29 Thread Arno . STREULI
7C%252a%7Cv%253B10668346%253B0-0%253B0%253B6024445%253B1-468%7C60%253B6847486%7C6865382%7C1%253B%253B%257Esscs%253D%253fhttp%3A//www.zannonces.ch"; how can avoid that ? I'm runing squid 25S9 on Solaris 8 thanks Arno Streuli **

Re: [squid-users] problem when un-taring of squid-3.0-PRE3-20050628 same with squid-3.0-PRE3-20050629 !?!

2005-06-29 Thread Arno . STREULI
can I do a checksum of the file to see if it match the one on the site ? (but if I have the wrong file I'm not suppose to be able to do a gunzip right ?) thanks for the info, regards, Arno Streuli ** DISCLAIME

[squid-users] problem when un-taring of squid-3.0-PRE3-20050628

2005-06-29 Thread Arno . STREULI
do a checksum of the file to see if it match the one on the site ? (but if I have the wrong file I'm not suppose to be able to do a gunzip right ?) thanks for the info, regards, Arno Streuli ** DISCLAIME

[squid-users] cachmgr: how to read it ?

2005-06-28 Thread Arno . STREULI
other is some Reserved or Deferred request in the NTLM authenticator statistic menu the avg request is 1700/min, is that ok ? where can I look for other info ? Arno Streuli ** DISCLAIMER - E-MAIL --- The inform

Re: [squid-users] cachemanager.cgi on a web server other than Squid

2005-06-28 Thread Arno . STREULI
Oups sorry the port is suppose to be the port of the proxy not the default 3128. regards, Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s

Re: [squid-users] cachemanager.cgi on a web server other than Squid

2005-06-28 Thread Arno . STREULI
squid box, but nothing is listening on that port ! what I'm missing ? ho by the way the ACl allow everyone to have access to cache manager for now. thanks regards, arno ** DISCLAIMER - E-MAIL --- The informati

[squid-users] cachemanager.cgi on a web server other than Squid

2005-06-28 Thread Arno . STREULI
Hi, I try to setup cachemgr.cgi on a web server other than my squid box. anyone know what should I do to make it works ? how did you setup cachmrg.cgi to speak with the squid box ? Is the option of configure --enable-cachemgr-hostname thanks for any help Arno Streuli

[squid-users] cachemgr.cgi

2005-06-27 Thread Arno . STREULI
Hello, How can I use cachemgr.cgi if I don't have (wan't ) a web server in my proxy ? Any other solution ? thanks regards, Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is in

[squid-users] Anyone using the feature to test a group wuith NTLM or I'm the only one ? is that a bug ?

2005-06-21 Thread Arno . STREULI
ke it work ? thanks for any help Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain certain privileged and confidential informatio

Re: [squid-users] group authentication with ntlm

2005-06-20 Thread Arno . STREULI
if the domain of your user is mydomain, then try the folowing command: wbinfo -r mydomain\\zef don't forget the 2 backslash otherwise wbinfo will remove one and it will fail. Arno Streuli Crédit Agricole (Suisse) SA Chemin de Bérée 46-48, ch-1010 Lausanne 10 Tél. +41 58 321.5215 - Fax +

Re: [squid-users] group authentication with ntlm

2005-06-20 Thread Arno . STREULI
oblem. regards, Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain certain privileged and confidential information, or inform

Re: [squid-users] Problem with wb_ntlmauth

2005-06-20 Thread Arno . STREULI
Hi, its look like the user right is no correct on the winbindd_privileged look under samba/var/lock and give the right r-x to the group of squid and change the group member ot the directory winbindd_privileged should work then regards, Arno Streuli Crédit Agricole (Suisse) SA Chemin de

[squid-users] Need help on group authentication on a multi-domain

2005-06-20 Thread Arno . STREULI
. Anyonw know how I can make this procedure to work ? thanks for your help if you can ! regards, Arno Streuli Crédit Agricole (Suisse) SA Chemin de Bérée 46-48, ch-1010 Lausanne 10 Tél. +41 58 321.5215 - Fax +41 58 321.5251 http

[squid-users] group authentication with NTLM more info

2005-06-16 Thread Arno . STREULI
User: -d-ch\clob- Group: -D-CH\SurfeursWebCH- SID: -S-1-5-21-907243726-1387878072-1859928627-9560 Domain Group (2)- GID: -10013- Sending ERR to squid ok maybe I'm not in the group 10013 but I'm in the 10001 (d-ch\\SurfeursWebCH-T) why it dosen test this one ? Arno Streuli Crédi

[squid-users] group authentication with NTLM

2005-06-16 Thread Arno . STREULI
squid nothing had change on the NT side, but is somehint wrong about the '-' on the SurfeurWebCH-T ? thanks for any help regards Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this

Re: [squid-users] Problems with ntlm authentication

2004-09-01 Thread Arno . STREULI
Hmm I think you can't forward NTLM authetication because of a miss use on windows NT I think it's on the faq of Squid (11.14 proxy of cache). " Why we cannot proxy NTLM even though we can use it. Quoting from summary at the end of the browser authentication section in this a

[squid-users] crash of squid 2.5Stable 5

2004-08-23 Thread Arno . STREULI
to do with this crash ? any help welcome. regards, Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain certain privileged and confiden

RE: [squid-users] crahs of squid stable 2.5 stable 5

2004-08-18 Thread Arno . STREULI
Harg I'm stupid, of curse. I was sure I did it on the test server too. Okay okay, it's only setup on the production squid. Thanks Marc, sorry for this stupid question !! Regards, Arno Crédit Agricole Indosuez (Suisse) SA Chemin de Bérée 46-48, ch-1010 Lausanne 10 Tél. +41 21 651.

[squid-users] crahs of squid stable 2.5 stable 5

2004-08-18 Thread Arno . STREULI
2| Validated 44956 Entries 2004/08/18 12:57:32| store_swap_size = 395604k 2004/08/18 12:57:33| storeLateRelease: released 0 objects a . (point) indicated the same group of messages repeting a lot of time. Any clue ? (since it was working niceley with 2.5S1) thanks, Arno *

[squid-users] squid_ldapauth

2004-06-16 Thread Arno Seidel
rd => 'x' squid_ldapauth[3222]: ldap_bind failed my ldap says: Jun 13 14:43:03 xxx slapd[3008]: conn=43 op=0 RESULT tag=97 err=2 text=requested protocol version not allowed my questions now are: Do i something wrong in the configuration? is there a way to specify the protokoll version? regards Arno

AW: AW: [squid-users] squid_ldapauth

2004-06-14 Thread Arno Seidel
Hi List, -Ursprungliche Nachricht- >Von: Emilio Casbas [mailto:[EMAIL PROTECTED] >Gesendet: Montag, 14. Juni 2004 13:00 >An: [EMAIL PROTECTED] >Cc: [EMAIL PROTECTED] >Betreff: Re: AW: [squid-users] squid_ldapauth > > >Arno Seidel wrote: > >>Hi,

AW: [squid-users] squid_ldapauth

2004-06-14 Thread Arno Seidel
quid_ldapauth -v 2 | 3 or >similar. squid_ldapauth -h gives me: -h this help test -v verbose mode - default is off -q log queries - default is off -l togle usage of syslog - default is on so i would do it if there where a option or any setting for the config file. regards Arno

[squid-users] squid_ldapauth

2004-06-14 Thread Arno Seidel
rd => 'x' squid_ldapauth[3222]: ldap_bind failed my ldap says: Jun 13 14:43:03 xxx slapd[3008]: conn=43 op=0 RESULT tag=97 err=2 text=requested protocol version not allowed my questions now are: Do i something wrong in the configuration? is there a way to specify the protokoll version? regards Arno

[squid-users] squid ldapauth

2004-06-13 Thread Arno Seidel
rd => 'x' squid_ldapauth[3222]: ldap_bind failed my ldap says: Jun 13 14:43:03 xxx slapd[3008]: conn=43 op=0 RESULT tag=97 err=2 text=requested protocol version not allowed my questions now are: Do i something wrong in the configuration? is there a way to specify the protokoll version? regards Arno

Re: [squid-users] Winbind authentication

2004-06-04 Thread Arno . STREULI
to solve it, I will gratfull if you can share it with me. Best regards, Arno Streuli ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain

Re: [squid-users] Squid ACL

2004-05-17 Thread Arno . STREULI
Your first ACL allow full access from local network (192.168.1.0/24) if your user arre inthis range squid will never go furher on the ACL check. Move the first line at the end. So squid will proceed your deny first. Ragards, Arno

RE: [squid-users] error in policy config

2004-05-13 Thread Arno . STREULI
Thanks, that's my problem. I have to recompile it. So will upgrade in the same time. regards, Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s

[squid-users] error in policy config

2004-05-13 Thread Arno . STREULI
heap If I use: cache_replacement_policy LFUDA I got: May 13 13:50:53 squid2 squid[18032]: [ID 702911 user.alert] ERROR: Unknown policy LFUDA So what should I put ! thanks for the help Arno ** DISCLAIMER - E-MAIL

[squid-users] building the cache while squid is running

2004-05-11 Thread Arno . STREULI
256 but I always get the message that squid is already running !?!? bash-2.05# ../sbin/squid -z 2004/05/11 09:52:34| Squid is already running! Process ID 317 Is their a way to build a cache dir without interrupting squid ? Thanks, Arno

Re: [squid-users] squid cache_dir problem

2004-02-24 Thread Arno . STREULI
maybe the problen is not on the cache part of the disk but on the squid_store.log and swap.log who is on the same disk. try to remove some old squid_store.log and/or swap.log to see how it' hanlde it. Regards,

[squid-users] new error show up on my cache.log, and segmentation violation

2004-02-10 Thread Arno . STREULI
bexec/wb_group acl webuser external NT_global_group SurfeursWeb # http_access allow java_jvm http_access allow cai-auth webuser http_access deny all it's squid 2.5stable1 on solaris 8 1Gb ram (please don't ask me to upgrade to stable5, so m

[squid-users] Authentication with Java plug-in change !?!?

2004-01-21 Thread Arno . STREULI
(1.3.x) Any chance that I can disable the authentication for the java content ? Or any other solution ? thanks for any help, regards, Arno PS: I would like to say that it's because now it's a sun applet and before it was the micro$oft one !??!? But I

[squid-users] Multi-domain (or multi-forest) authentication

2004-01-08 Thread Arno . STREULI
aking a trust to the other domain(tree in the forest). thanks for the tips, Arno PS: I'm using Samba 3.0.1, Squid 2.4STABLE4 on Solaris 8, and NTLM authentication ** DISCLAIMER - E-MAIL --- The information

[squid-users] Crash of Squid during authentication !! NEWS NEWS NEWS

2004-01-07 Thread Arno . STREULI
no=0 (Error 0) Any more clue ? is that a bug ? thanks for the help. Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named recipient(s). It may contain certain p

[squid-users] Crash of Squid during authentication !!

2004-01-07 Thread Arno . STREULI
Internet access control Lausanne auth_param basic credentialsttl 2 hours any clue what is wrong ? thanks for th help, Arno ** DISCLAIMER - E-MAIL --- The information contained in this E-Mail is intended for the named

Re: [squid-users] agin Samba3 Win 2003 and Squid 2.5 stable4

2003-11-28 Thread Arno . STREULI
454 10.137.138.117 TCP_DENIED/407 1614 GET http://www.cisco.com/ - NONE/- text/html 1070014293.690862 10.137.138.117 TCP_DENIED/407 1684 GET http://www.cisco.com/ - NONE/- text/html Will keep you inform if I find something... Regards, Arno Crédit Agricole Indosuez (Suisse) SA Chemin de

Re: [squid-users] agin Samba3 Win 2003 and Squid 2.5 stable4

2003-11-28 Thread Arno . STREULI
e not supported by Samba. But I >am sure the Samba people can give a clear explanation. Not on the samba log, it's on squid log what is the relation of squid and sqmba other than for authentication ! I'm able to get the list of user and group from my w2003 serveur. And so far squid dosen'

[squid-users] agin Samba3 Win 2003 and Squid 2.5 stable4

2003-11-27 Thread Arno . STREULI
01:20, 1] utils/ntlm_auth.c:manage_squid_request(1042) [2003/11/27 17:01:20, 1] utils/ntlm_auth.c:manage_squid_request(1042) fgets() failed! dying. errno=0 (Error 0) any clue ? tahnks for your help. regards, Arno PS: can you tell me why I have that in my cache.log: [2003/11/27 1

[squid-users] authentication failed, and ok 1 or 2 hours later !?!?

2003-10-08 Thread Arno . STREULI
to 2 hours ? And why not alll user on this domain ? How can I fix this ? How can I debug this ? I'm using squid 2.5stable 1 and samba 2.2.7 on Solaris 2.8 Thanks for your tips, Arno ** DISCLAIMER - E-MAIL --