2014-01-12 21:15:24.199343270 +0100
@@ -1,5 +1,5 @@
#ifndef SQUID_OS_HPUX_H
-#define SQUID_OS_PHUX_H
+#define SQUID_OS_HPUX_H
#if _SQUID_HPUX_
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.ch
t; > > #ifndef SQUID_OS_HPUX_H
> > > #define SQUID_OS_PHUX_H
> > >
> > > should be
> > >
> > > #ifndef SQUID_OS_HPUX_H
> > > #define SQUID_OS_HPUX_H
> > > ?
> > >
> > > (change HPUX to HPUX)
>
> second li
* Amos Jeffries :
> > icap_service service_info reqmod_precache 1 icap://127.0.0.1:1344/info
>
> I believe its talking about this one ^^^.
Oh yes. Damn.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin F
to get c-icap statistics from the web
acl infoaccess dstdomain icap.info
icap_service service_info reqmod_precache 1 icap://127.0.0.1:1344/info
adaptation_service_set class_info service_info
adaptation_access class_info allow infoaccess
adaptation_access class_info deny all
--
Ralf Hildebrandt
* Dr.x :
> well , if this is just error for lijit.com website , i can remove
> redirecting this website to squid and let my head clear.
just block them, all they do is to serve ads!
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@char
G: unparseable HTTP header field {:: }
>
> I means the response to the URL shown contains corrupted HTTP headers.
> Something outside the HTTP protool has been injected, So Squid will drop
> the header, if relaxed_header_parser is disabled then the whole response
> is dro
* Ralf Hildebrandt :
> * Amos Jeffries :
>
> > >Is this maby related to using c-icap via ICAP?
> >
> > Aha. Possibly. If the URL being changed by that component?
>
> Not intentionally. All it does is to reject requests to infected
> items, and the icons a
Maybe cache rules preventing the small icon *.png being stored?
Nope.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155
* Ralf Hildebrandt :
> Where would the icons usually go to?
Found them
/usr/share/squid3/icons/silk/arrow_up.png
and set icon_directory accordingly.
Now testing again...
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benja
c-io=6 \
--enable-storeio=aufs --enable-removal-policies=lru,heap \
--enable-underscores --enable-icap-client
--enable-follow-x-forwarded-for \
--enable-snmp --with-filedescriptors=65536 \
--with-large-files --with-default-user=proxy --enable-epoll \
--disable-ipv6
--
Ralf Hildebrandt
* Ralf Hildebrandt :
> * Ralf Hildebrandt :
>
> > 2013/10/15 10:49:59| internalStart: unknown request: GET
> > /squid-internal-static/icons/silk/arrow_up.png HTTP/1.1
> > Host: 83.172.xx.xx
> > User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0)
> > Ge
* Ralf Hildebrandt :
> 2013/10/15 10:49:59| internalStart: unknown request: GET
> /squid-internal-static/icons/silk/arrow_up.png HTTP/1.1
> Host: 83.172.xx.xx
> User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0)
> Gecko/20100101 Firefox/24.0
> Accept: text/html,app
64; rv:24.0)
Gecko/20100101 Firefox/24.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: keep-alive
The question being: Why can 83.172.86.66 query the Proxy at all?
--
Ralf Hildebrandt
G: found whitespace in HTTP header name
{JSESSIONID=AC28912A7C462A9752761882F4A31BCE; Path=/cae: }
Just for the fun of it: How do I correlate these warning to actual
requests done by clients?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.de
* Amos Jeffries :
> On 15/10/2013 1:32 a.m., Ralf Hildebrandt wrote:
> >I'm running 3.4.x with c-icap, and every now and then I'm seeing this
> >in my log:
> >
> >Oct 14 09:06:47 proxy-cvk-1 squid[12081]: internalStart: unknown
> >request:#012GET /sq
unexpected read
from redirector #1, 1 bytes '#012'
Do you have any ide what this might be?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
00 : RR Set that should exist does not
9000 : Server Not Authoritative for zone
10000 : Name not contained in zone
16000 : Bad OPT Version or TSIG Signature Failure
Search list:
charite.de
--
Ralf Hildebra
* Ralf Hildebrandt :
> Nameservers:
> IP ADDRESS # QUERIES # REPLIES Type
> -- - -
> 224.0.0.251 122256 0 multicast
Huh? The numbers
Refused
600 0 : Name Exists when it should not
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155
S responses come back form the LAN machines as unicast
> replies and would hit that known/unknown security check.
So if I set ignore_unknown_nameservers to OFF, then the numbers would
change?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.de
steps in with a
> different resolver if the domain tail matches ".local".
OK, since we didn't configure this, it won't be queried.
> What does the idns cache manager report say about #QUERIES vs
> #REPLIES on each of your NS ?
"idns cache manager"? Is that a
lver
That's what we're using.
> will send a SERVFAIL response back to Squid if there is any kind of
> Internet DNS failures. Which does get recorded as a received response
> even if it is not useful.
>
> Amos
--
Ralf Hildebrandt Charite Universitätsme
* Eliezer Croitoru :
> On 07/30/2013 05:56 PM, Ralf Hildebrandt wrote:
> > Nope. Just asking why the stats suddenly would look different.
> > I'll check the other machines in the cluster
> IS it a bind\named DNS server??
Yes
--
Ralf Hildebrandt Char
* Eliezer Croitoru :
> On 07/30/2013 05:33 PM, Ralf Hildebrandt wrote:
> > The proxy is the only program quering the local DNS server. It's bound
> > to 127.0.0.1
> >
> > I'm looking at the query.log, but I'm not seeing any queries to .local
> > na
server to bind specific port to differentiate the
> PROXY requests to the DNS requests..
The proxy is the only program quering the local DNS server. It's bound
to 127.0.0.1
I'm looking at the query.log, but I'm not seeing any queries to .local
names at all.
Maybe some new
* Amos Jeffries :
> On 30/07/2013 11:15 p.m., Ralf Hildebrandt wrote:
> >I had good results replacing 3.3.8 with 3.4.0.1 - no changes to the
> >config were needed.
> >
> >One interesting observation: The dnsreq statistics are different. With
> >3.3.8 the gra
te is the problem.
We're using a local cache on all proxies.
> This way all the tests will be done on the local network rather then
> over the INTERNET and then you can ask the next person in the chain in
> order to get a deeper response.
>
> Eliezer
--
Ralf Hildebrand
the point in time I changed the squid versions.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155
some known memory leaks which might
> be your problem here, so I suggest you upgrade to a current version
> of squid such as 3.3.3 or 3.2.9.
Amen to that. It got A LOT better.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.de
Right now I added two ACLs to block access to Zeus C&C servers, by
domain and by IP. It's working, but I cannot determine the ACL from
the logging. Is there any way of logging the ACL name in the access.log?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf
* Alex Rousskov :
> On 03/08/2013 08:11 AM, Adam W. Dace wrote:
> > Does anyone have a simple example configuration for running Squid
> > 3.3.2 with multiple workers?
>
> You can just add "workers 2" to squid.conf.default.
That's really all?
--
Ralf H
am looking for an alternative.
c-icap for example.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155
a:
> >
> > acl teamviewer-ssl url_regex ^(master|ping)[0-9]+\.teamviewer\.com
> > http_access deny teamviewer-ssl
>
> If you want to block teamviewer totally, dstdomain would be faster:
>
> acl teamviewer dstdomain .teamviewer.com
> http_access deny teamviewer
OK,
ly to CONNECT requests?
Idea:
acl teamviewer-ssl url_regex ^(master|ping)[0-9]+\.teamviewer\.com
http_access deny teamviewer-ssl
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.chari
* babajaga :
> Hi Ralf,
>
> when you have new machines to play with, first of all I would try to
> optimize a solid conf. Just to have a reference system, the potentially
> better ones can be compared to.
That was the idea :)
--
Ralf Hildebrandt Charite Univ
versus a RAM disk.
"Of course it doesn't work, but look how fast it is" (just a little
joke, no offense meant)
Anyway, maybe I'll try those in a new setup (new machines are upcoming).
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hilde
* Loïc BLOT :
> under OpenBSD i have switched from FFS2 disk cache to mfs disk cache and
> performances were massively improved.
These are OpenBSD filesystems? I'm currently using ext4, but am open
to suggestions which FS to use for the disk cache on linux.
--
Ralf
m? How big can a hot item be? Are objects transferred
from the cache_mem to the disk cache (and vice versa).
The reason for my question: WOuld a RAM disk help to speed up the proxy?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampu
1ceebd in SquidMainSafe (argv=0xb7b4, argc=2) at main.cc:1216
No locals.
#10 main (argc=2, argv=0xbffff7b4) at main.cc:1208
No locals.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de
* Loïc BLOT :
> Hi amos,
> your patch seems to be correct. I try it next monday.
I already installed it. No crashes so far.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.char
* Ralf Hildebrandt :
> This mail didn't have an attachment...
Ah, to the bug report. FOund it. Will install right away!
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.ch
catch these brokenness rather than permitting the
> traffic to get screwed up silenly ("watermelon metrics" etc).
>
> I have attached an experimental patch which might resolve this to the
> bug report.
This mail didn't have an attachment...
--
Ralf Hildebrandt
remove the assert and manage the getaddrinfo result on this
> function :)
Hm, doesn't my assertion error occur at another place? And with an IPv6
address?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin F
EventLoop::run (this=0xb6a4) at EventLoop.cc:95
#16 0x081cd6c0 in SquidMain (argc=-1073744128, argv=0xb6a4) at main.cc:1501
#17 0x081ceebd in SquidMainSafe (argv=0xb7f4, argc=2) at main.cc:1216
#18 main (argc=2, argv=0xbffff7f4) at main.cc:1208
(gdb)
--
Ralf Hildebrandt
id=[0-9]+&client=DynGate(&rnd=[0-9]+)?&p=[0-9]+
acl teamviewer-out url_regex dout\.aspx\?s=[0-9]+&p=[0-9]+&client=DynGate
http_access deny teamviewer-in
http_access deny teamviewer-out
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@cha
dns_v4_first/
I think this is a border case. The domain itself has migrated
elsewhere anyway.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155
* Dmitry Melekhov :
> 19.12.2012 16:19, Ralf Hildebrandt пишет:
> >When trying to access http://www.vkontakte.ru/, I'm getting an error:
> >
> >Connection to 2a00:bdc0:3:103:1:0:403:900 failed.
> >(101) Network is unreachable
> >
> >
> to solve
:0:403:907
www.vkontakte.ru. 3876 IN 2a00:bdc0:3:103:1:0:403:908
But why is it using ipv6 here?
When accessing http://www.arschkrebs.de/ which ALSO has both A and
records, it happily uses the A record?!
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hild
is on the local machine
> or on remote server?
It's a local ICAP server.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereic
* Ralf Hildebrandt :
> > But why? Are there known performance issues with 3.2?
Turns out that it was this:
"ICAP server connection leaks have been resolved."
which had been resolved in 3.2.7 - YAY!
--
Ralf Hildebrandt Charite Universitätsmedizin Berl
* Ralf Hildebrandt :
> * Amos Jeffries :
> > The Squid HTTP Proxy team is very pleased to announce the availability
> > of the Squid-3.2.2 release!
>
> I tried 3.2.2 in the same setup as 3.1.21 - same machine, same
> settings, starting with an empty cache_dir.
>
> Do name them please. Or at least the broken agent you uncovered.
It's Afaria after a current hotfix -- which fixed it to actually use a
proxy for all requests instead of just some.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@ch
www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.1
clearly define that there must be a CRLF after the HTTP Version, no
spaces are allowed.
Still, it's easier to have a workaround in squid than to get a big,
three letter company to fix their software.
Is there a way for me to relax that pa
ervers in a cluster here, so it's relatively
easy to reproduce.
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
Geschäftsbereich IT, Abt. Netz
proxy.charite.de/proxy/ dmz
deny_info http://proxy.charite.de/proxy/ intranet
> or are you logging more 4xx/5xx responses than before?
Nope.
> A scan of your logs should indicate what errors are happening more
> often now.
So I guess it's that "deny_info" stuff.
* Ralf Hildebrandt :
> HttpErrors being client_http.errors from SNMP.
Actually it's this:
# squidclient -p 8080 mgr:counters |grep client_http.errors
client_http.errors = 259580
# sleep 5
# squidclient -p 8080 mgr:counters |grep client_http.errors
client_http.errors = 259605
of the "HttpErrors" counter.
HttpErrors being client_http.errors from SNMP.
Since the clients using the Squid proxy have not changed, what would
create that sudden increase in errors?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.de
* Maqsood Ahmad :
>
> Dear All,
>
>
> I am continuously getting this error " TCP_MISS/503 0 CONNECT " in my squid
> proxy.
> I did not find any good help through google.
Like this?
http://squid-web-proxy-cache.1019090.n4.nabble.com/Strange-503-on-https
t; /proc/sys/kernel/msgmni
ulimit -n 8192 -c unlimited
exec 2>&1
exec /usr/sbin/squid -NsYC
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampus Benjamin Franklin
http://www.charite.de Hindenburgdamm 30, 12203 Berlin
y for domains but faster than light and you can mix with
> > dansguardian or acl for objects and urls.
>
> The bbdd of dansguardian is not free. am I wrong?
What is bbdd?
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@charite.deCampu
* Helmut Hullen :
> Hallo, squid-users,
>
> my self made squid 3.2.0.14 sometimes produces messages like
>
>
> Jan 30 08:56:58 Arktur squid[4263]: Failed to select source for
> 'http://ivwbox.de/'
ivwbox.de does not resolve. Maybe that's normal?
--
Ralf H
Help: <mailto:squid-users-h...@squid-cache.org>
List-Unsubscribe: <mailto:squid-users-unsubscr...@squid-cache.org>
List-Subscribe: <mailto:squid-users-subscr...@squid-cache.org>
--
Ralf Hildebrandt Charite Universitätsmedizin Berlin
ralf.hildebra...@char
ds like a bug.
>
> First step, upgrade to a current release. 3.1.10 is pretty dated by now
> (a year to be exact). Current release is 3.1.17.
3.1.18!
(need to update as well)
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Be
* Benjamin :
> Hi,
>
> When i have heavy traffic that time squid always consume 100% cpu
> utilization. Is there anyway to tune squid or OS to reduce cpu
> utilization?
Usually restarting squid fixes things.
It does for me
--
Ralf Hildebrandt
Geschäftsbereich IT | Abt
number of file descriptors: 6691
Reserved number of file descriptors: 100
Maximum number of file descriptors: 8192
Available number of file descriptors: 6653
Reserved number of file descriptors: 100
What are the filedescriptors used for?
--
Ralf H
-1
Oct 21 16:18:41 proxy-cvk-2 squid[13989]: StoreEntry->lock_count: 2
Oct 21 16:18:41 proxy-cvk-2 squid[13989]: StoreEntry->mem_status: 0
Oct 21 16:18:41 proxy-cvk-2 squid[13989]: StoreEntry->ping_status: 2
Oct 21 16:18:41 proxy-cvk-2 squid[13989]: StoreEntry->store_status: 1
Oct 21 16:18:
> > squid-3.1.16:
> > squid -k shutdown causes a crash, below is the result of:
>
> Here: not reproduceable.
>
> Slackware 13.37 (self made)
> squid-3.1.16 (self made)
> http://arktur.shuttle.de/CD/Testpakete/squid-3.1.16-i486-1_hln.tgz
I also built it from
igh load
Maybe I should remove those, I think those are the defaults anyway.
> > debug_options ALL,1
http://www.squid-cache.org/Doc/config/debug_options/
yep "debug_options ALL,1" is the default. Will delete it anyway.
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwer
* Ralf Hildebrandt :
> * Fred B :
> > Hi,
> >
> > No problem for me
> > Something particular in your squid.conf ?
>
> Hard to tell. No icap, a few ACLs, no buckets.
I stripped out the "http_access" && "acl" lines:
http_port 8080
icp
* Fred B :
> Hi,
>
> No problem for me
> Something particular in your squid.conf ?
Hard to tell. No icap, a few ACLs, no buckets.
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm
18 0x0814b98d in SquidMainSafe (argv=0xbe14, argc=2) at main.cc:1176
No locals.
#19 main (argc=2, argv=0xbe14) at main.cc:1168
No locals.
A debugging session is active.
Inferior 1 [process 1333] will be killed.
Quit anyway? (y or n) [answered Y; input not from terminal]
--
Ralf Hil
* Justin Lawler :
> Thanks Amos - regex pattern we're using is:
>
> .*some_url_end.html$
Wouldn't
some_url_end.html$
be more efficient?
* Amos Jeffries :
> On 15/08/11 23:52, Ralf Hildebrandt wrote:
> >With today's BZR checkout (3.2-HEAD) I'm getting a lot of "SECURITY
> >ALERT: Host: header forgery detected" with everyday requests:
> >
> >2011/08/15 13:50:59.016| SECURITY ALER
ote=10.43.21.32:4096 FD 54 flags=1
2011/08/15 13:51:02.247| SECURITY ALERT: Host: header forgery detected from
local=141.42.1.205:8080 remote=141.42.195.43:1355 FD 158 flags=1
(professional.avira-update.com does not match 80.190.130.195)
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilun
> This new release can be downloaded from our HTTP or FTP servers
>
> http://www.squid-cache.org/Versions/v3/3.2/
> ftp://ftp.squid-cache.org/pub/squid/
> ftp://ftp.squid-cache.org/pub/archive/3.2/
It's not there yet.
Daily snapshots are also stale
gging session is active.
Inferior 1 [process 28126] will be killed.
Quit anyway? (y or n) [answered Y; input not from terminal]
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Be
* Amos Jeffries :
> On 22/06/11 23:16, Ralf Hildebrandt wrote:
> >* Amos Jeffries:
> >>The Squid HTTP Proxy team is very pleased to announce the
> >>availability of the Squid-3.2.0.9 beta release!
> >
> >With ICAP enabled I'm getting:
> >
> >
* Amos Jeffries :
> The Squid HTTP Proxy team is very pleased to announce the
> availability of the Squid-3.2.0.9 beta release!
With ICAP enabled I'm getting:
2011/06/22 13:15:22| assertion failed: comm.cc:749: "fd >= 0"
Without ICAP, all is well...
--
Ralf Hildebran
240 FD 634 flags=1,
url=http://www.essence.eu/uploads/RTEmagicC_comp_lips_30.png.png
Can this be disabled somehow?
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49 30 4
ymbol table info available.
#7 0x081974a1 in SquidMainSafe (argc=2, argv=0xbe14) at main.cc:1232
e =
#8 main (argc=2, argv=0xbe14) at main.cc:1221
No locals.
A debugging session is active.
Inferior 1 [process 6228] will be killed.
Quit anyway? (y or n) [answered Y; i
like a client bug if you ask me, since the file is much
larger:
-rw-r--r-- 1 h h 3617644 2011-06-15 09:45 hg18.genome
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962
ralf.hildebra...@charite.de | http://www.charite.de
xy using a normal webbrowser works
without problems (it seems to be an archive of sorts).
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49 30 450 570 155 | Fax: +49 30 4
alled
on your distribution)
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962
ralf.hildebra...@charite.de | http://www.charite.de
e[3]: Leaving directory /usr/src/squid/trunk/src'
make[2]: *** [install-recursive] Error 1
make[2]: Leaving directory /usr/src/squid/trunk/src'
make[1]: *** [install] Error 2
make[1]: Leaving directory /usr/src/squid/trunk/src'
make: *** [install-recursive] Error 1
--
ap_filen: -1
2011/04/29 12:29:45| StoreEntry->lock_count: 2
2011/04/29 12:29:45| StoreEntry->mem_status: 0
2011/04/29 12:29:45| StoreEntry->ping_status: 2
2011/04/29 12:29:45| StoreEntry->store_status: 1
2011/04/29 12:29:45| StoreEntry->swap_status: 0
2011/04/29 12:29:45| assertion
* Amos Jeffries :
> Arg! now I'm going crazy (and blind).
>
> Fix applied to trunk.
> http://www.squid-cache.org/Versions/v3/3.HEAD/changesets/squid-3-11387.patch
Working...
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
* Amos Jeffries :
> The Squid HTTP Proxy team is very pleased to announce the
> availability of the Squid-3.2.0.7 beta release!
It doesn't build; I'm getting:
Making install in wrapper
make[3]: Entering directory
/usr/src/squid-3.2.0.7/helpers/negotiate_auth/wrapper'
g++ -DHAVE_CONFIG_H -I../../
I'm useing squid 3.2.0.6 as proxy for my users (my users are accessing
the internet). Is there consensus about which scheduler is most suited
for people surfing the internet?
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Ben
* Helpdesk :
> Hi folks
>
> If we want to access www.football.ch, the webpage cannot be displayed.
>
> The access.log tells me the following:
> TCP_MISS/302 135 GET http://www.football.ch - DEFAULT_PARENT/127.0.0.1 -
What kind of parent proxy is running on localhost?
--
ch is about to hit the squid-dev mailing list. See the audit
> submission email there for more details.
I'll check.
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49
distribution do you use?
None. I built it from the source.
> Have you changed "/etc/squid/mime.conf" too?
I'm using /etc/squid3 for config parameters.
Indeed, I didn't change that file...
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universit
* Ralf Hildebrandt :
> 1) squid won't start, since it complains about a missing
> /usr/share/squid3/icons
>directory
>
> 2) Once I mkdir'ed that directory, squid will start, but it keeps
> crashing:
After purging the cache entirely, I'm getting:
2011
ccepting HTCP messages on port 4827, FD 20.
2011/04/05 11:56:50| Accepting SNMP messages on [::]:3401, FD 21.
2011/04/05 11:56:50| Store rebuilding is 0.21% complete
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
uid just ignore the ACL so no harm in
> leaving.
good!
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 30 | D-12203 Berlin
Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962
ralf.hildebra...@charite.de | http://www.charite.de
Ignoring unknown protocol 'cache_object' in the
ACL named 'manager'
2011/03/08 11:24:16| Processing Configuration File:
/etc/squid3/squid-icap.conf.3.2 (depth 1)
>From the config:
#Recommended minimum configuration:
acl manager proto cache_object
Can I omit that line?
--
* Ralf Hildebrandt :
> I get a compilation error:
>
> make[3]: Entering directory /usr/src/squid-3.2.0.5/src/adaptation'
> Making all in icap
> make[4]: Entering directory /usr/src/squid-3.2.0.5/src/adaptation/icap'
> /bin/bash ../../../libtool --tag=CXX --mode=c
request'
ModXact.cc:1426: error: 'const class HttpRequest' has no member named
'auth_user_request'
make[4]: *** [ModXact.lo] Error 1
make[4]: Leaving directory /usr/src/squid-3.2.0.5/src/adaptation/icap'
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung
* Ralf Hildebrandt :
> Thanks. Stupid me. I'm now using:
>
> acl cornils src 141.42.x.y
> adaptation_access service_req deny cornils
> adaptation_access service_req allow all
>
> adaptation_access service_resp deny cornils
> adaptation_access service_resp allow
* Kinkie :
> On Wed, Feb 9, 2011 at 9:08 AM, Ralf Hildebrandt
> wrote:
> > Can I selectively bypass the use of ICAP (we're using c-icap) for certain
> > * client IPs
> > * destination URLs
> > * destination IPs
>
> You can check http://www.squid-cache
Can I selectively bypass the use of ICAP (we're using c-icap) for certain
* client IPs
* destination URLs
* destination IPs
Squid 3.2.0.x
--
Ralf Hildebrandt
Geschäftsbereich IT | Abteilung Netzwerk
Charité - Universitätsmedizin Berlin
Campus Benjamin Franklin
Hindenburgdamm 3
1 - 100 of 433 matches
Mail list logo