[squid-users] Debugging Kerberos Handshake

2014-08-25 Thread Jason Fitzpatrick
Good morning all. I have been trying to get Kerberos with nltm fall back working for a couple of days with limited success, and was wondering how to debug the Kerberos end of things. I can see a token getting to the server, running ktutil against the keytab shows all expected spns, running strace

[squid-users] Chrome as a client of Squid

2012-05-01 Thread Jason Fitzpatrick
Hi All I have a Squid Server (squid-3.2.0.16-1.fc16.x86_64) which is set to upstream to a 3rd party gateway proxy server and therefore has to authenticate all users destined for the internet (internal traffic is not required to authenticate) While this works perfectly from IE and Firefox (NTLM au

Re: [squid-users] NTLM with a fall back to anonymous

2012-02-05 Thread Jason Fitzpatrick
Hi Henrik.. it is never easy is it ;0) Looks like I will be maintaining whitelists for the foreseeable future! Thanks for the reply Jay 2012/2/4 Henrik Nordström : > lör 2012-02-04 klockan 13:23 + skrev Jason Fitzpatrick: > >> I was hoping that if a client failed to authenti

Re: [squid-users] NTLM with a fall back to anonymous

2012-02-04 Thread Jason Fitzpatrick
to authenticate then it would be forwarded to the upstream and fall under what ever the default (un authorized) ruleset is, known risky sites etc would be getting filtered there, Jay On 4 February 2012 12:02, Amos Jeffries wrote: > On 5/02/2012 12:30 a.m., Jason Fitzpatrick wrote: >> &

[squid-users] NTLM with a fall back to anonymous

2012-02-04 Thread Jason Fitzpatrick
Morning all.. I have a requirement to have my squid servers authenticate users before forwarding requests to an upstream server which does content filtering based on the X-Forwarded headers in the requests and all seems to be working quite well so far, (internal traffic is routed via the squids wi

[squid-users] Fwd: Forwarding Integrated Authentication for Terminal Server / Citrix users.

2012-01-10 Thread Jason Fitzpatrick
Hi all We are in the process of replacing an ISA cluster with a Squid Cluster (Squid Cache: Version 3.1.14) and have run into some issues with the forwarding of credentials to an upstream proxy. Our setup is as follows (names and IP addresses just for explanation purposes) Netscaller Load-ballan

[squid-users] Jason Fitzpatrick is out of the office.

2007-11-01 Thread Jason . Fitzpatrick
I will be Out of the Office Start Date: 31/10/2007. End Date: 05/11/2007. I am currently out of the office, I will respond to your message when I return. If the matter is urgent please contact a member of the LPIS Technical Services Team. ___

RE: [squid-users] squid3 WindowsUpdate failed

2007-10-31 Thread Jason . Fitzpatrick
As I said, just me being lazy,, sorry about that! -Original Message- From: Jorge Bastos [mailto:[EMAIL PROTECTED] Sent: 31 October 2007 10:43 To: squid-users@squid-cache.org Subject: RE: [squid-users] squid3 WindowsUpdate failed Not an option, at least for me. I think that is not the wa

RE: [squid-users] squid3 WindowsUpdate failed

2007-10-31 Thread Jason . Fitzpatrick
Hi all.. I know that this is not the answer that you are looking for, but why not just install a WSUS server internally? Then point all your clients to it via AD policy. (me being a lazy bugger here!) Jay -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: 31 October

[squid-users] Reverse Proxy for Multiple SSL sites

2007-09-20 Thread Jason . Fitzpatrick
Hi.. I hope that this is the correct address, if not I apologise I have a simple yes or no type of question for you.. is it possible to have a squid proxy running as a reverse proxy on one IP Address but forwarding on requests to multiple backend web servers for HTTPS requests? eg: DNS fo