Re: [squid-users] Host header forgery policy in service provider environment

2016-01-06 Thread Amos Jeffries
On 6/01/2016 10:10 p.m., Garri Djavadyan wrote: >> On 2015-12-31 00:01, Garri Djavadyan wrote: >>> Hello Squid members and developers! >>> >>> First of all, I wish you a Happy New Year 2016! >>> >>> The current Host header forgery policy effectively prevents a cache >>> poisoning. But also, I

Re: [squid-users] Host header forgery policy in service provider environment

2016-01-06 Thread Garri Djavadyan
>On 2015-12-31 00:01, Garri Djavadyan wrote: >> Hello Squid members and developers! >> >> First of all, I wish you a Happy New Year 2016! >> >> The current Host header forgery policy effectively prevents a cache >> poisoning. But also, I noticed, it deletes verified earlier cached >> object. Is

Re: [squid-users] Host header forgery policy in service provider environment

2016-01-01 Thread garryd
On 2015-12-31 13:31, Amos Jeffries wrote: On 2015-12-31 00:01, Garri Djavadyan wrote: Hello Squid members and developers! First of all, I wish you a Happy New Year 2016! The current Host header forgery policy effectively prevents a cache poisoning. But also, I noticed, it deletes verified

Re: [squid-users] Host header forgery policy in service provider environment

2015-12-31 Thread Amos Jeffries
On 2015-12-31 00:01, Garri Djavadyan wrote: Hello Squid members and developers! First of all, I wish you a Happy New Year 2016! The current Host header forgery policy effectively prevents a cache poisoning. But also, I noticed, it deletes verified earlier cached object. Is it possible to

[squid-users] Host header forgery policy in service provider environment

2015-12-30 Thread Garri Djavadyan
Hello Squid members and developers! First of all, I wish you a Happy New Year 2016! The current Host header forgery policy effectively prevents a cache poisoning. But also, I noticed, it deletes verified earlier cached object. Is it possible to implement more careful algorithm as an option? For

Re: [squid-users] Host header forgery policy

2014-07-15 Thread Amos Jeffries
On 15/07/2014 6:23 a.m., Edwin Marqe wrote: Hi Eliezer, I understand that, but this is pretty much the point of my e-mail. In my company we don't work with servers installed physically here, instead, we rent servers to a company. We use 2 nameservers for our clients, and the IT company uses

[squid-users] Host header forgery policy

2014-07-14 Thread Edwin Marqe
Hi all, After an upgrade of squid3 to version 3.3.8-1ubuntu6, I got the unpleasant surprise of what is called the Host header forgery policy. I've read the documentation of this part, and although I understand the motivation of its implementation, I honestly see not very practical implementing

Re: [squid-users] Host header forgery policy

2014-07-14 Thread Eliezer Croitoru
Hey There, I do not know your setup but if you run: dig domain.com and the results are different from what the client tries to request it seems to be a Host Header Forgery like.. In the case of google, it seems like google instead of pointing to one of your servers points to a local server but

Re: [squid-users] Host header forgery policy

2014-07-14 Thread Edwin Marqe
Hi Eliezer, I understand that, but this is pretty much the point of my e-mail. In my company we don't work with servers installed physically here, instead, we rent servers to a company. We use 2 nameservers for our clients, and the IT company uses others and additionally they don't allow to

Re: [squid-users] Host header forgery policy

2014-07-14 Thread James Lay
On Mon, 2014-07-14 at 19:23 +0100, Edwin Marqe wrote: Hi Eliezer, I understand that, but this is pretty much the point of my e-mail. In my company we don't work with servers installed physically here, instead, we rent servers to a company. We use 2 nameservers for our clients, and the IT

Re: [squid-users] Host header forgery policy

2014-07-14 Thread Eliezer Croitoru
On 07/14/2014 09:23 PM, Edwin Marqe wrote: Hi Eliezer, I understand that, but this is pretty much the point of my e-mail. In my company we don't work with servers installed physically here, instead, we rent servers to a company. We use 2 nameservers for our clients, and the IT company uses