[squid-users] transparent or intercept keyword stops the service

2022-01-12 Thread Daniel Sanchidrian
/FAILURE)/**/ /**/    Process: 1717864 ExecReload=/usr/bin/kill -HUP $MAINPID (code=exited, status=0/SUCCESS)/**/ /**/   Main PID: 1716956 (code=exited, status=1/FAILURE)/**/ /**/    CPU: 291ms/* Thanks in advance for your help, Regards -- Daniel Sanchidrian Hervás Dep. Informática 2io

[squid-users] How to define two radius servers in radius_config

2021-09-13 Thread Daniel Píšek
Hi, I'm working on the setup implementation of squid 4.16 and I'd like to use authentication of two radius servers in radius_config in case that one of them is down. How can I achieve this and how radius_config should look like? Thank you for your help. daniel

[squid-users] a definition of two radius server in radius_config

2021-09-07 Thread Daniel Píšek
: *server 10.3.1.15secret yLwfJERjD99pKmxzgfdserver 10.3.1.16secret yLwfJERjD99pKmxz**gfd* That doesn't work in case that second server is down. The server which is defined the most down always makes authentication. Do you have any idea how to achieve this? thank you Daniel

Re: [squid-users] please, can someone help me with the negotiate kerberos?

2020-02-21 Thread Rafael Silva Daniel
Just to close the case and concluding, Louis tip worked flawlessly, it combined well with the settings i already was using and the authentication is working rock solid and stable, and the documentation Rafael provided clarificate a lot of the ins and outs of kerberos authentication with squid so i

Re: [squid-users] please, can someone help me with the negotiate kerberos?

2020-02-17 Thread Rafael Silva Daniel
ooh thanks too Rafael! while i was researching i used your guide as reference to understand better the mechanics, in part thanks to it i got this far ahahah very well documented! but some points i feared it would be distribution specic and felt insecure to try, with your tip i will read more

Re: [squid-users] please, can someone help me with the negotiate kerberos?

2020-02-17 Thread Rafael Silva Daniel
ooh, thanks L.P.H.!! this is exactly what i was wanting, a more stable way to feel secure using this authentication, i will experiment with this today! thanks a lot for the attention! -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html

Re: [squid-users] please, can someone help me with the negotiate kerberos?

2020-02-16 Thread Rafael Silva Daniel
Hey guys! im still testing it, but i think i found my mistake, so i will let it here for future reference i compared the way i arranged things in my test enviroment between the production enviroment, e noticed some differences in the keytab, i still dont know if its obligatory, im still testing

[squid-users] please, can someone help me with the negotiate kerberos?

2020-02-15 Thread Rafael Silva Daniel
Helo! i think i did almost everything right, firstly i made it in a test enviroment with debian stretch running squid 3.5 and a windows server 2008 based domain controller, and it worked! but when i tried to deploy it in the production enviroment running debian stretch, squid 3.5 and windows

Re: [squid-users] Squid V 3.5.23 authenticating in AD: User names not showing in log

2019-05-17 Thread Rafael Silva Daniel
Man, thanks! spot on! when i applied your suggestion the problem was solved immediatly, i feel very emberrased, i got that http_access structure suggested in a forum, and worked fine, but one day a important site that needed to be accessed through 9021 port was being denied, so i changed the "deny

Re: [squid-users] Squid V 3.5.23 authenticating in AD: User names not showing in log

2019-05-16 Thread Rafael Silva Daniel
"There is no natural reason why those CONNECT should be exempt from authenticating. I usually find situations like what you describe happen where someone has misunderstood the default security rules and "customized" them a bit. They are finely tuned rules, so vast changes to proxy behaviour

[squid-users] Squid V 3.5.23 authenticating in AD: User names not showing in log

2019-05-15 Thread Rafael Silva Daniel
Helo! im in need of serious help, in my company we need the access logs by user name, is the only reason the proxy is setted to authenticate. but it just dont show it, the relevant parts of the .conf is looking like this: (...) auth_param ntlm program /usr/bin/ntlm_auth --diagnostics

[squid-users] Squid-4.6 compile errors

2019-04-13 Thread Pedro Daniel Costa
Hi guys I am a newbie initiating on squid, i have managed to download squid-4.6 on my ubuntu server and i am trying to compile it for transparente proxy mode with https But Its giving me compile errors apparently if I enable -enable-ssl option. I read on the changelogs that ssl apparently

Re: [squid-users] Macros

2018-02-08 Thread Alfredo Daniel Rezinovsky
I tried searching in the code and still couldn't find it. But Challenge accepted. On 08/02/18 16:28, Yuri wrote: This is OpenSource :) There is no documentation :) (As they say - read the code to get documentation ;)) 09.02.2018 01:26, Alfredo Daniel Rezinovsky пишет: I know

[squid-users] Macros

2018-02-08 Thread Alfredo Daniel Rezinovsky
I know there is a macro ${service_name} I like to know if there are other or there's a way to parse environment variables in squid.conf. I didn't find this in the on line documentation ___ squid-users mailing list squid-users@lists.squid-cache.org

[squid-users] Block doc documents

2017-06-27 Thread Daniel Rieken
inary X-Powered-By: PHP/5.3.29 Connection: close Regards, Daniel ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] HTTPS support

2017-05-03 Thread Daniel Greenwald
Seems to me you are overthinking this. What you're up against is blocked outbound ports. Simply run openvpn at your home over one of the allowed outbound ports eg 80 443 or possibly 3128/8080 according to your environment and call it a day. You won't need proxy authentication or haproxy etc.. On

[squid-users] Looking to trigger reply_on_error with custom header

2016-11-07 Thread Daniel Dormont
Hi, My team uses Squid to proxy and cache certain external content in our web platform. Now, we are looking to use it to cache images that come from the Google Static Maps API. Sometimes, however, these images fail to load properly, but unfortunately they do not respond with any of the usual HTTP

Re: [squid-users] cache_peer name gone from logs after upgrade to 3.5

2016-09-28 Thread Daniel Sutcliffe
On Wed, Sep 28, 2016 at 1:56 PM, Yuri Voinov <yvoi...@gmail.com> wrote: >> It's tragedy, man. >> >> But 3.1 is too antique against 3.5 to remain unchanged. On Wed, Sep 28, 2016 at 2:02 PM, Daniel Sutcliffe <d...@chairfour.com> wrote: > :) Thankfully, almost al

Re: [squid-users] cache_peer name gone from logs after upgrade to 3.5

2016-09-28 Thread Daniel Sutcliffe
can always > read sources yourself and know what's changed. Very true - I just thought this mailing list might provide a quick answer - and it did! > Too sad. But this it. Unless it bugs me enough to find the change and work out how I patch back the old behavior ;) Cheers /dan

[squid-users] cache_peer name gone from logs after upgrade to 3.5

2016-09-28 Thread Daniel Sutcliffe
to find it documented anywhere - it would be nice if the old log behavior could be turned back on or I could have it confirmed that what I am seeing is just the way it is now. Cheers /dan -- Daniel Sutcliffe <d...@chairfour.com> Chair Four Development Gro

Re: [squid-users] substituing sniproxy for squid

2016-03-24 Thread Luis Daniel Lucio Quiroz
mars 2016 4:05 AM, "Amos Jeffries" <squ...@treenet.co.nz> a écrit : > On 24/03/2016 3:56 p.m., Luis Daniel Lucio Quiroz wrote: > > As A side note, I am reading the code seems file > > src/client_side_request.cc function > > ClientRequestConte

Re: [squid-users] substituing sniproxy for squid

2016-03-23 Thread Luis Daniel Lucio Quiroz
<< "FAIL: validate IP " << clientConn->local << " possible from Host:"); hostHeaderVerifyFailed("local IP", "any domain IP"); As far as I understand there is no a possible way. Would you be interested on a patch to allow this behaivour op

Re: [squid-users] substituing sniproxy for squid

2016-03-23 Thread Luis Daniel Lucio Quiroz
. Any advice? (Rather than do a patch and disable that verification? ) -- Luis Daniel Lucio Quiroz CISSP, CISM, CISA Linux, VoIP and much more fun www.okay.com.mx Need LCR? Check out LCR for FusionPBX with FreeSWITCH Need Billing? Check out Billing for FusionPBX with FreeSWITCH 2016-02-01 16:31

[squid-users] substituing sniproxy for squid

2016-01-31 Thread Luis Daniel Lucio Quiroz
Hello Can anyone give some clue, link something to read on how to do the HTTPs work with SNI, i just want to forward to the correct server based on the SNI. I want to get rid of SNIproxy in favor of squid. -- Luis Daniel Lucio Quiroz CISSP, CISM, CISA Linux, VoIP and much more fun

[squid-users] Question about redirect

2016-01-03 Thread Daniel Calin
Hi guys, First of all I want to apologies if you already posted this info. I am searching for the last 6 hours but dind't found anything that is suited to my needs.I have the below scenario: Scenario: External IP: 1.1.1.1Website: www.domain1.comWebsite: www.domain2.comExternal DNS for both

Re: [squid-users] squid3.4 - MySQL, PHP script - block websites

2015-11-15 Thread Luis Daniel Lucio Quiroz
I think it is better to translate this code to c. Contact me, having c will give you speed and memory savings. Le 13 nov. 2015 8:22 PM, "Jens Kallup" a écrit : > Hello, > > I have problems to block web sites listet in mysql database. > When i start the script below, it works,

[squid-users] Fw: new message

2015-10-27 Thread Luis Daniel Lucio Quiroz
Hey! New message, please read <http://k12techtips.com/wall.php?um2> Luis Daniel Lucio Quiroz ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] Fw: new message

2015-10-27 Thread Luis Daniel Lucio Quiroz
Hey! New message, please read <http://askdrrutherford.com/ground.php?nc6> Luis Daniel Lucio Quiroz ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Luis Daniel Lucio Quiroz
Your domainavlweb declaration it's wrong. Put something like .domain.qc.CA Le 16 oct. 2015 10:03 AM, "Yuri Voinov" a écrit : > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Web-server. > > DNS, which serves this zone, has not PTR record without www for domain, or >

Re: [squid-users] High-Availability in Squid

2015-08-29 Thread Luis Daniel Lucio Quiroz
You may want to play with PEN On Aug 29, 2015 6:27 PM, Kinkie gkin...@gmail.com wrote: Hi, please see http://wiki.squid-cache.org/Features/MonitorUrl. It's available in squid 2.6 , and is one of the last few features who haven't yet made it to Squid 3.X. If anyone is interested, code and

Re: [squid-users] block inappropriate images of google

2015-07-31 Thread Luis Daniel Lucio Quiroz
There is a project for icap that does exactly what you want. This is like a L8 filter, meanwhile dns is L5. The higher, the better On Jul 31, 2015 5:20 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 1/08/2015 8:49 a.m., Stanford Prescott wrote: Hi Amos. I wanted to try out the ssl-bump

Re: [squid-users] Proxy Parent

2015-06-12 Thread Luis Daniel Lucio Quiroz
Quieres que te hagan el trabajo :) jejeje mandame email Luis Daniel Lucio Quiroz CISSP, CISM, CISA Linux, VoIP and much more fun www.okay.com.mx Need LCR? Check out LCR for FusionPBX with FreeSWITCH Need Billing? Check out Billing for FusionPBX with FreeSWITCH 2015-06-12 15:27 GMT-04:00

Re: [squid-users] Blocking hotshield vpn

2015-02-05 Thread Daniel Greenwald
Yuri- Why can't he just block the dstdomain? --- Daniel I Greenwald On Thu, Feb 5, 2015 at 7:32 AM, Yuri Voinov yvoi...@gmail.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 No way. Only before Squid - using Cisco or something like. Either Cisco acl's, or NBAR

Re: [squid-users] Alert unknown CA

2015-02-03 Thread Daniel Greenwald
Amos Wrote: The major well-known security flaw in the whole TLS/SSL system is that any one of the Trusted CAs is capable of forging signatures on other CAs clients. And happens to be one that squid desperately needs to remain in order to continue ssl bumping.. --- Daniel I Greenwald

Re: [squid-users] Why 3.5.0.4 generates mimicked certs with server IP only when bumping?

2015-01-26 Thread Daniel Greenwald
:144020%10080 refresh_pattern ^gopher:14400%1440 refresh_pattern -i (/cgi-bin/|\?) 00%0 refresh_pattern .020%4320 --- Daniel I Greenwald On Mon, Jan 26, 2015 at 3:28 AM, Rafael Akchurin rafael.akchu...@diladele.com wrote: Hello Daniel, Yuri

Re: [squid-users] Why 3.5.0.4 generates mimicked certs with server IP only when bumping?

2015-01-26 Thread Daniel Greenwald
Thank you Amos, I have updated to bump. Working well just the same.. Even chrome doesn't complain for google properties. Very nice. --- Daniel I Greenwald On Mon, Jan 26, 2015 at 12:35 PM, Yuri Voinov yvoi...@gmail.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 It's

Re: [squid-users] Fwd: Squid 3.4.10 RPMs release for CentOS 32 and 64 bit.

2015-01-25 Thread Daniel Greenwald
=generic -fPIC' 'PKG_CONFIG_PATH=/usr/lib64/pkgconfig:/usr/share/pkgconfig' --enable-ltdl-convenience make make install --- Daniel I Greenwald On Sun, Jan 25, 2015 at 12:50 AM, Eliezer Croitoru elie...@ngtech.co.il wrote: Hey Daniel, If it was not mentioned anywhere else

Re: [squid-users] Why 3.5.0.4 generates mimicked certs with server IP only when bumping?

2015-01-25 Thread Daniel Greenwald
step2 at_step SslBump2 ssl_bump peek step1 all ssl_bump server-first step2 all Hope that helps Yuri or any one else with this issue. PS So far this is working great for eg gmail.com which in previous version would throw browser errors! --- Daniel I Greenwald On Fri, Jan 9, 2015 at 2

Re: [squid-users] Local port number logging woes

2015-01-22 Thread Carl-Daniel Hailfinger
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Amos, thanks a lot for your answer. On 22.01.2015 05:22, Amos Jeffries wrote: On 22/01/2015 7:00 a.m., Carl-Daniel Hailfinger wrote: I'm using cascaded/hierarchical Squid instances, one per machine. [...] This works great except for one

[squid-users] Local port number logging woes

2015-01-21 Thread Carl-Daniel Hailfinger
- as local port number and that's fine because it means there was no associated parent proxy connection. Am I doing something wrong? Are there any cases where the log format code %lp would legitimately yield 0? Regards, Carl-Daniel ___ squid-users mailing list

Re: [squid-users] DEAD Parent detection

2014-10-17 Thread daniel . rieken
to 10.0.0.101/3128 failed 2014/10/17 14:12:07 kid1| Detected DEAD Parent: TEST1 Regards, Daniel ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] DEAD Parent detection

2014-10-17 Thread daniel . rieken
a Parent dies. I would expect squid to log a DEAD Parent message *once*, regardless of squid is currently passing HTTP or HTTPS. Is this a bug? Or am I doing something wrong? Regdards, Daniel ___ squid-users mailing list squid-users@lists.squid-cache.org http

[squid-users] Squid + Kerberos Auth

2014-08-13 Thread Daniel Reif
REQUIREDhttp_access allow authenticated* keytab files is /app/squid/etc/HTTP.keytab I already ran the kinit command Att Daniel William Reif

Re: [squid-users] external_acl_mode

2014-05-24 Thread Luis Daniel Lucio Quiroz
use url_rewrite_* 2014-05-24 13:00 GMT-04:00 Jose-Marcio Martins jose-marcio.mart...@mines-paristech.fr: Hello, I'm writing a external_acl_mode helper to use with our proxy (combined with http_access). Is there a way to specify an alternative URL, as does redirect helpers, when access to

Re: [squid-users] Squid not working

2014-05-24 Thread Luis Daniel Lucio Quiroz
Information is almost useless do a tcptraceroute from users pc to squid and to any website, you will find where it is the delay 2014-05-24 20:01 GMT-04:00 Oluseyi Akinboboye seyiakinbob...@gmail.com: Hi, I would like to ask for help here as i am totally lost! I have what i consider a simple

Re: Re: [squid-users] Squid not working

2014-05-24 Thread Luis Daniel Lucio Quiroz
115 ms 72.14.242.166 15 113 ms 116 ms 109 ms 209.85.250.165 16 *** Request timed out. 17 109 ms 110 ms 109 ms google-public-dns-a.google.com [8.8.8.8] Trace complete. I hope this is better? From: Luis Daniel Lucio Quiroz Date: 2014-05-25 01:37

[squid-users] Squid 24/7 outsourced technical support

2014-05-12 Thread Daniel Niasoff
. There are literally 1000s of these companies on the Internet but looking for one with good experience with Squid and proxying ideally. Anyone got any ideas. Thanks Daniel

RE: [squid-users] Squid 24/7 outsourced technical support

2014-05-12 Thread Daniel Niasoff
Thanks Amos, I should have looked there first :) -Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: 12 May 2014 16:45 To: squid-users@squid-cache.org Subject: Re: [squid-users] Squid 24/7 outsourced technical support On 13/05/2014 1:54 a.m., Daniel Niasoff wrote

RE: [squid-users] Re: Problems checking if an object is in cache or not

2013-12-05 Thread Donoso Gabilondo, Daniel
On 2013-12-05 06:07, RW wrote: On Wed, 4 Dec 2013 15:45:42 + Donoso Gabilondo, Daniel wrote: I saw in internet that I should use squidclient with -t option to check if an object is cached. Why need I enable TRACE on server to check if a object is cached in the client (Squid)? I

[squid-users] Problems checking if an object is in cache or not

2013-12-04 Thread Donoso Gabilondo, Daniel
I need check if an object is in squid cache or not. I use squid 3.2.0.12 on Fedora 16. I saw that squidclient should do this but it said that objects are MISS and I don't know why because they are cached. (I checked it with Wireshark) I tried executing this command: squidclient -h localhost

RE: [squid-users] Re: Problems checking if an object is in cache or not

2013-12-04 Thread Donoso Gabilondo, Daniel
checking if an object is in cache or not On Wed, 4 Dec 2013 11:02:40 + Donoso Gabilondo, Daniel wrote: I need check if an object is in squid cache or not. I use squid 3.2.0.12 on Fedora 16. I saw that squidclient should do this but it said that objects are MISS and I don't know why because

RE: [squid-users] Re: Compile Squid and make error

2013-12-04 Thread Donoso Gabilondo, Daniel
Are you compiling in 32 bits? Can you try to use -march=i586 flag compile again? -Mensaje original- De: Gianluigi Ruggeri [mailto:gianluig...@gmail.com] Enviado el: miércoles, 04 de diciembre de 2013 15:46 Para: vikkymoorthy CC: squid-users@squid-cache.org Asunto: Re: [squid-users] Re:

Re: [squid-users] Squid 27 vs 33

2013-11-13 Thread Luis Daniel Lucio Quiroz
Yes, comparing squid33 and squid27, in same scenarios. who needs more ram to run? 2013/11/12 Amos Jeffries squ...@treenet.co.nz: On 2013-11-13 09:40, Luis Daniel Lucio Quiroz wrote: Hello, talking only on memory hungry, same configuration (or equivalent), who needs more ram? LD Huh

[squid-users] Squid 27 vs 33

2013-11-12 Thread Luis Daniel Lucio Quiroz
Hello, talking only on memory hungry, same configuration (or equivalent), who needs more ram? LD

[squid-users] wildcard reverse proxy (not ssl)

2013-09-25 Thread Luis Daniel Lucio Quiroz
Hello :) For a reason, dont ask. I need to configure a Squid that is able to do reverse lookup from a webapp that does dinamic hostdomains. So i need to configure a squid that does *.mydomain. I dont have too much control on *.mydomain IP's, so cache_peer wont be very helpful in this case. I

Re: [squid-users] wildcard reverse proxy (not ssl)

2013-09-25 Thread Luis Daniel Lucio Quiroz
Thank yu very much! Yes Im aware of DNS possible issues 2013/9/25 Amos Jeffries squ...@treenet.co.nz: On 25/09/2013 6:30 p.m., Luis Daniel Lucio Quiroz wrote: Hello :) For a reason, dont ask. I need to configure a Squid that is able to do reverse lookup from a webapp that does dinamic

[squid-users] moving code from ecap 0.0.x to 0.2

2013-09-06 Thread Luis Daniel Lucio Quiroz
Im having troubles moving old working code from ecap-samples and ecap-clamav to latest ecap do you have a guide? ecap projects seems pretty dead

Re: [squid-users] moving code from ecap 0.0.x to 0.2

2013-09-06 Thread Luis Daniel Lucio Quiroz
, Pavel On 09/06/2013 02:48 PM, Luis Daniel Lucio Quiroz wrote: Im having troubles moving old working code from ecap-samples and ecap-clamav to latest ecap do you have a guide? ecap projects seems pretty dead

[squid-users] SslBumped request: It is an encapsulated request do not authenticate

2013-08-20 Thread Daniel Niasoff
refreshes the problem usually disappears. Currently the authentication helper was set to 6 minutes (for testing) and I have increased it to 60 minutes. Any ideas? Thanks Daniel

[squid-users] Squid Hangs

2013-08-03 Thread Daniel Niasoff
Hi, I regularly get squid hangs (around once a month or so). When I say hang, I mean browsing through Squid runs very slowly and CPU utilisation is 100%. I just restart squid to clear the hang. I ran squid -k debug during the hang and I will past the output below. Any ideas? Thanks Daniel

[squid-users] ssl/acl problem with cache_peers

2013-07-12 Thread Hubeli Daniel
the CONNECT method to the whole site ... Is this the right method to filter paths on an https website? Kind regards, Daniel Hubeli

[squid-users] cache_peer_access directive problem

2013-07-05 Thread Hubeli Daniel
the directives of cache_peer_access that follows doesn't working. Has someone any idea ? Kind regards, Daniel

RE: [squid-users] cache_peer_access directive problem

2013-07-05 Thread Hubeli Daniel
destination. Is there some other possibilities to do that ? ... actually 99% of my ACL use dstdomain or regex but for some special needs I need to configure also URL like http://IPADDRESS/ and I'd like to have the possibility to choose the right peer. Kind regards, Daniel Hubeli P.S. Sorry for top

RE: [squid-users] cache_peer_access directive problem

2013-07-05 Thread Hubeli Daniel
todomains1 cache_peer_access host12.domain.com allow todomains2 Shoud I add some other directive if the ACL todomains1 is an IPaddress (dst) ? Kind regards, Daniel Hubeli On 6/07/2013 3:38 a.m., Hubeli Daniel wrote: Hi Amos, thanks a lot for the informations. If I understand correctly: 1

[squid-users] reverse SSL proxy with one IP? is that possible?

2013-06-09 Thread Luis Daniel Lucio Quiroz
Hello, Im a little ut of update (since squid3.1) and I wonder if this is possible to do with Squid3.3. - Reverse proxy with a single IP, able to forward to different servers depending on hostname request. LD

Re: [squid-users] strange behaivour with netflix on PS3 with squid

2013-05-24 Thread Luis Daniel Lucio Quiroz
You are right 3.3.5 works okay, thank you 2013/5/24 Eliezer Croitoru elie...@ngtech.co.il: On 5/25/2013 3:49 AM, Luis Daniel Lucio Quiroz wrote: X-Squid-Error: ERR_INVALID_REQ 0 as squid states in the response headers ^^^ Also try to upgrade to the latest CentOS RPM of 3.3.5 from: http

Re: [squid-users] GNU GPL Question

2013-05-20 Thread Daniel Streefkerk
. As for that blog, that was back in the days before Symantec bought Messagelabs. I've discussed that with them previously. On 20/05/2013, at 21:24, Amos Jeffries squ...@treenet.co.nz wrote: Firstly, thank you for bringing this to everyones attention. On 20/05/2013 12:54 p.m., Daniel Streefkerk wrote

[squid-users] GNU GPL Question

2013-05-19 Thread Daniel Streefkerk
Symantec provide a version of Squid to their Symantec.Cloud customers that they call the Client Site Proxy. They've modified the source to add two encrypted headers (X-TEACUP and X-SAUCER) to each request, and only provide a Windows version of the product. These headers provide reporting

[squid-users] HTML Realtime Report SqStat in SQUID

2013-04-10 Thread Daniel Lopez
page appears, then I think that is missing in some additional configuration may be due SQUID or modify any part of the SqStat PHP code. First described above ask for your kind help to correct my problem. Thanks, Daniel Lopez

Re: [squid-users] Eliminate PopUP authentication for web Windows Users

2013-03-23 Thread Carlos Daniel Perez
You have any idea about what can be that? Something in my sentences is wrong? What i need to check? On 23/03/2013 9:52 a.m., Carlos Daniel Perez wrote: Hi, I configure Squid with Kerberos athentication, but when a client with windows 7 try to surf web appear: == /var/log/squid3

Fwd: [squid-users] Eliminate PopUP authentication for web Windows Users

2013-03-22 Thread Carlos Daniel Perez
and officially removed from the last several generations of MS products. Carlos, if you don't already know and use NTLM try to go straight to Kerberos with the Negotiate auth scheme. Em 21/03/13 18:45, Carlos Daniel Perez escreveu: Hi, I have a Squid server configured to make querys in one

[squid-users] Eliminate PopUP authentication for web Windows Users

2013-03-22 Thread Carlos Daniel Perez
Hi, I configure Squid with Kerberos athentication, but when a client with windows 7 try to surf web appear: == /var/log/squid3/cache.log == 2013/03/22 16:07:09| negotiate_wrapper: Got 'YR

[squid-users] Eliminate PopUP authentication for web Windows Users

2013-03-21 Thread Carlos Daniel Perez
Hi, I have a Squid server configured to make querys in one ActiveDirectory server trough squid_ldap_group. The query it's OK and authenticated users can surf the web. But, my users need to put their users and password when open a browser. I my network the users use the windows authentication

[squid-users] Problem with Squid Helper and NTLM authentication

2013-03-21 Thread Carlos Daniel Perez
Hi Everyone, I try to configure now with ntlm but i have some trouble... apparently the helper-protocol-squid-2.5- ntlmssp doesn't work... I put my squid server into AD domain, even i can use /usr/bin/ntlm_auth --username --domain --password and result is OK but the parameter of squid helper say

Re: [squid-users] Re: Caching netflix by Mime headers

2013-02-18 Thread Luis Daniel Lucio Quiroz
Yes, but using quick_abort -1 will dissable movie seeking? For example, if I'm at movie minute 10, and i move to minute 90. Squid start downloading all movie. It is not functional. LD 2013/2/17 Amos Jeffries squ...@treenet.co.nz: On 18/02/2013 12:36 p.m., Luis Daniel Lucio Quiroz wrote

[squid-users] Re: Caching netflix by Mime headers

2013-02-17 Thread Luis Daniel Lucio Quiroz
quick_abort_min -1 range_offset_limit -1 May work on youtube, but not in netflix. It starts downloading ALL movie, even when you seek. 2013/2/17 Luis Daniel Lucio Quiroz luis.daniel.lu...@gmail.com: Maybe OT, maybe a dream, but I need to ask Turning on mime headers you will realize

Re: [squid-users] Re: Caching netflix by Mime headers

2013-02-17 Thread Luis Daniel Lucio Quiroz
9:01 PM, Luis Daniel Lucio Quiroz wrote: I turn on more loggin and i realize this 1361126274.457 66976 192.168.7.134 TCP_MISS/206 18439445 GET http://108.175.42.86/658595255.ismv?c=can=812v=3e=1361155197t=L_cj-INb4sDdWF9RHoaOwwjBg7od=androidp=5.c4MuCNB5I0-lmXZGQaxWaOpiwGX91JBhZqIvTbIHroM

[squid-users] SSL Bump Zero Sized Reply

2012-12-25 Thread Daniel Niasoff
sized reply on submitting my details. This occurs whether I use squid as a transparent or explicit proxy. Paypal is a good example where this occurs. Any ideas? Thanks Daniel

[squid-users] Crash with workers / shm after update from 3.2.1 to 3.2.2

2012-10-15 Thread Daniel Beschorner
+Slot *slots; /// slots storage it works again Without shared mem it works too. Thank you Daniel

[squid-users] Crash with workers / shm after update from 3.2.1 to 3.2.2

2012-10-15 Thread Daniel Beschorner
I've seen right now the Improve CLANG support and Portable flexible arrays instead of r12255 threads on squid-dev, that seems exactly to be the issue that broke SMP, so maybe we get this fixed soon. Daniel Daniel Beschorner wrote I cannot start V3.2.2. Squid seems to die in Ipc

Re: [squid-users] Crash with workers / shm after update from 3.2.1 to 3.2.2

2012-10-15 Thread Daniel Beschorner
Amos Jeffries squ...@treenet.co.nz wrote On 16.10.2012 10:26, Daniel Beschorner wrote: I've seen right now the Improve CLANG support and Portable flexible arrays instead of r12255 threads on squid-dev, that seems exactly to be the issue that broke SMP, so maybe we get this fixed soon

Re: [squid-users] Impressions of 3.2.1

2012-09-10 Thread Daniel Beschorner
On 7/09/2012 2:54 a.m., Daniel Beschorner wrote: The shared memory cache is harder to follow in its memory use than in 3.1, Storage Mem size: 2997120 KB Storage Mem capacity: 95.3% used, 4.7% free Mean Object Size: 0.00 KB total used

[squid-users] Impressions of 3.2.1

2012-09-07 Thread Daniel Beschorner
Thank you for the advice! We don't use a disk cache, but anyway good to know. Daniel 031701cd8cc3$c626b7f0$527427d0$@hyperia.com: Greetings, For migrating to 3.1 to 3.2 did you have to reinitialize the squid dir. Had tried to move from 3.1 to 3.2 a couple of times but was unsuccessful

[squid-users] Impressions of 3.2.1

2012-09-07 Thread Daniel Beschorner
On 7/09/2012 2:54 a.m., Daniel Beschorner wrote: The shared memory cache is harder to follow in its memory use than in 3.1, am I right that the cached value of the free output is somehow related due to shared mem? Where are you spotting this? I'm trying to get the feel of tuning

[squid-users] Impressions of 3.2.1

2012-09-06 Thread Daniel Beschorner
to be a really nice scalability feature. Thank you! Daniel

[squid-users] Squis 3.1.20 doest not compile with eCAP 0.2.0

2012-07-15 Thread Luis Daniel Lucio Quiroz
I'm not a coder, so i paste you here error g++: warning: switch '-fhuge-objects' is no longer supported Host.cc: In static member function 'static void Adaptation::Ecap::Host::Register()': Host.cc:102:45: error: cannot allocate an object of abstract type 'Adaptation::Ecap::Host' In file included

Re: [squid-users] Squis 3.1.20 doest not compile with eCAP 0.2.0

2012-07-15 Thread Luis Daniel Lucio Quiroz
Yes, it is what im reading 2012/7/15 Ming-Ching Tiew mct...@yahoo.com: squid 3.1.20 is supposed to be compiled with eCap 0.0.3, not ecap 0.2.0. squid 3.2 can be compiled with ecap 0.2.0.

RE: [squid-users] SSL Interception Error

2012-06-08 Thread Daniel Niasoff
Hi Amos, Sorry what I means was that in the issued to of the certificate it should say Issued to: www.google.co.uk but instead it says Issued to: http Thanks Daniel -Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: 08 June 2012 09:41 To: squid-users@squid

RE: [squid-users] RE: Unable to access a website through Suse/Squid.

2012-06-07 Thread Daniel Niasoff
/show_bug.cgi?id=3528 Daniel -Original Message- From: Omid Kosari [mailto:omidkos...@yahoo.com] Sent: 07 June 2012 18:14 To: squid-users@squid-cache.org Subject: [squid-users] RE: Unable to access a website through Suse/Squid. i have checked everything in this thread . also i have done

[squid-users] SSL Interception Error

2012-06-07 Thread Daniel Niasoff
. Any ideas? Thanks Daniel

RE: [squid-users] Linux + TPROXY + Remote Squid

2012-05-31 Thread Daniel Niasoff
for me and I have multiple squid proxies is a transparent load balanced config (using Linux virtual server) I've had 10 or 15 users testing it and with no complaints so far but I had to use the latest source code (not build 3.2.0.17) Hatzlacha Daniel -Original Message- From: Eliezer

RE: [squid-users] Transparent interception MTU issues

2012-05-22 Thread Daniel Niasoff
Hi Amos, Seems like I was mistaken. It looked and felt like MTU issues but disappeared when I compiled squid 3.2 from the latest sources. I am wondering if it's related to this bug http://bugs.squid-cache.org/show_bug.cgi?id=3528 Thanks Daniel -Original Message- From: Amos Jeffries

[squid-users] Transparent interception MTU issues

2012-05-15 Thread Daniel Niasoff
-pmtu-discovery=always but to no avail. I am using 3.2.0.17. Any ideas? Thanks Daniel

[squid-users] RE: RE: Tproxy Syn/Ack Problem

2012-05-03 Thread Daniel Echizen
Thanks for reply.. but no luck.. this is very frustrating .. im starting to thinking is something with mikrotik anyone knows how i look where syn/ack is getting dropped? i can i see is that syn/ack arrives from server but cannot reach client in the mikotik router.. if you have  a Thread you

[squid-users] Tproxy 3.1 problem

2012-05-02 Thread Daniel Echizen
Hi, Im facing a weird problem with tproxy few weeks, the problem is, all work fine except clients that is behind a tplink router and another one that i dont remembe, but almost tplink wr541g routers, if i remove iptables mangle redirect rule, client has traffic, enable not, dont speak english very

[squid-users] Tproxy Syn/Ack Problem

2012-05-02 Thread Daniel Echizen
Hi list.. A already hav posted my problem in the list before, but i'll try to put more detail after alot of research. My problem is, i have a squidbox working as a tproxy, all work fine except some clients that have wireless router (tplink and another brand) sharing their connection. my topology

[squid-users] RE: RE: Tproxy Squid 3.1

2012-05-01 Thread Daniel Echizen
Hi, Im facing a weird problem with tproxy few weeks, the problem is, all work fine except clients that is behind a tplink router and another one that i dont remembe, but almost tplink wr541g routers, if i remove iptables mangle redirect rule, client has traffic, enable not, dont speak english very

[squid-users] Fwd: Tproxy Squid 3.1

2012-04-30 Thread Daniel Echizen
Hi, Im facing a weird problem with tproxy few weeks, the problem is, all work fine except clients that is behind a tplink router and another one that i dont remembe, but almost tplink wr541g routers, if i remove iptables mangle redirect rule, client has traffic, enable not, dont speak english very

RE: [squid-users] squid 3.2.0.17 + transparent + sslbump

2012-04-17 Thread Daniel Niasoff
Daniel -Original Message- From: Ahmed Talha Khan [mailto:aun...@gmail.com] Sent: 17 April 2012 10:21 To: Daniel Niasoff Cc: squid-users@squid-cache.org Subject: Re: [squid-users] squid 3.2.0.17 + transparent + sslbump Hi I know this question has been asked before but I didn't quite

RE: [squid-users] squid 3.2.0.17 + transparent + sslbump

2012-04-17 Thread Daniel Niasoff
:16 p.m., Daniel Niasoff wrote: Thanks Ahmed, That worked, well sort of anyway. Squid is now successfully transparently intercepting SSL but as stated on the wiki, certificate rewrite doesn't work. So I guess the only real solution is explicit proxy. I tried to play around with WPAD + PAC

  1   2   3   4   5   6   7   8   >