Re: [squid-users] Reverse proxy: http to https and certificate authentication

2009-02-04 Thread Mailing List SVR
Il giorno mar, 03/02/2009 alle 17.20 +0100, Matus UHLAR - fantomas ha scritto: I have a soap client using python ZSI, the other end is oracle soa 10.1.3.1.0 all works fine since some months. The last week oracle soa was configured to accept client certificate

[squid-users] LDAP Authentication Password Problem.

2009-02-04 Thread Emre YILMAZ
hi list, As all you know, whenever a user opens a web browser, squid asks password for ldap authentication. We are trying to keep this session open for specific time even if the browser has been closed.(Just like NTLM authentication) Actually what we are trying to do is; creating an ip

Re: [squid-users] WWW-Authenticate header field

2009-02-04 Thread bijayant kumar
Bijayant Kumar --- On Wed, 4/2/09, Amos Jeffries squ...@treenet.co.nz wrote: From: Amos Jeffries squ...@treenet.co.nz Subject: Re: [squid-users] WWW-Authenticate header field To: bijayan...@yahoo.com Cc: squid users squid-users@squid-cache.org Date: Wednesday, 4 February, 2009, 12:12 PM

Re: [squid-users] LDAP Authentication Password Problem.

2009-02-04 Thread Amos Jeffries
Emre YILMAZ wrote: hi list, As all you know, whenever a user opens a web browser, squid asks password for ldap authentication. We are trying to keep this session open for specific time even if the browser has been closed.(Just like NTLM authentication) Actually what we are trying to do is;

[squid-users] cache_dir

2009-02-04 Thread vivian t
hi if i have /var/spool/dir partation (91 GB) what should i put in cache_dir ...? when i execute df -h command i found it's size used 99%

[squid-users] Squid Security Advisory: Denial of service in request processing

2009-02-04 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2009:1 __ Advisory ID:SQUID-2009:1 Date: February 02, 2009 Summary:

Re: [squid-users] squid cannot open page, but the other proxy can

2009-02-04 Thread myszaty
done, but no effect. still having the problem Chris Robertson-2 wrote: myszaty wrote: you're right. here's the result of squidclient with correct address squidclient http://www.malopolska.uw.gov.pl HTTP/1.0 200 OK Date: Tue, 27 Jan 2009 07:16:28 GMT Server: Microsoft-IIS/6.0

Re: [squid-users] cache_dir

2009-02-04 Thread Amos Jeffries
vivian t wrote: hi if i have /var/spool/dir partation (91 GB) what should i put in cache_dir ...? when i execute df -h command i found it's size used 99% http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid?highlight=(cache\_dir) http://www.squid-cache.org/Doc/config/cache_dir/ Amos --

[squid-users] Intermittent slow response from Squid

2009-02-04 Thread Moses Truong
We have squid running on a server with delay pools enabled. The squidclient usually responds very quickly - in less than 0.03 seconds most of the time. However, there are times when this rises to over 39 seconds. There are 2 Gb of RAM, and there's about 900mb used. There's 1024 file

[squid-users] Squid 3.1.0.5 beta is available

2009-02-04 Thread Amos Jeffries
The Squid HTTP Proxy team is very pleased to announce the availability of the Squid-3.1.0.5 beta release! This release fixes the denial of Service vulnerability http://www.squid-cache.org/Advisories/SQUID-2009_1.txt All Squid 3.1 testers are strongly recommended to upgrade immediately. The

Re: [squid-users] LDAP Authentication Password Problem.

2009-02-04 Thread Emre YILMAZ
Amos, Thnx for your reply, We have tried auth_param basic credentialsttl 2 hours but whenever user closes the browser, and reopened password box appears again and again. But i want to keep this authentication (session) for 2 hours. in that case what should i do, have you an idea?

Re: [squid-users] LDAP Authentication Password Problem.

2009-02-04 Thread Amos Jeffries
Emre YILMAZ wrote: Amos, Thnx for your reply, We have tried auth_param basic credentialsttl 2 hours but whenever user closes the browser, and reopened password box appears again and again. But i want to keep this authentication (session) for 2 hours. in that case what should i do, have

Re: [squid-users] cache_dir

2009-02-04 Thread Ralf Peng
2009/2/4 vivian t vivij...@gmail.com: hi if i have /var/spool/dir partation (91 GB) what should i put in cache_dir ...? when i execute df -h command i found it's size used 99% so you shouldn't use that partation as cache_dir. when a partation's free space is less than 20%, it's better not

[squid-users] Squid 3.0.STABLE13 is available

2009-02-04 Thread Amos Jeffries
The Squid HTTP Proxy team is pleased to announce the availability of the Squid-3.0.STABLE13 release! This release fixes the denial of Service vulnerability http://www.squid-cache.org/Advisories/SQUID-2009_1.txt All Squid 3.0 users are strongly recommended to upgrade or patch immediately. The

Re: [squid-users] Squid -z problem (plz...)

2009-02-04 Thread Henrik Nordstrom
Ignore the Mem: line, it's not important. It's the +/- buffers line you need to read. The difference is the filesystem buffers, maintained autoatically by the OS to speed up disk I/O when there is free memory. Reclaimed automatically if applications needs memory. ons 2009-02-04 klockan 12:00

[squid-users] bind socket

2009-02-04 Thread vivian t
hello when i try to surf any site from any pc i start the squid server in debug level 1 and found this lines commBind: cannot bind socket FD 14 to X.X.X.X: (99) cannot assign requested address what is it mean ...?

Re: [squid-users] Certain applications when using NTLM auth

2009-02-04 Thread Henrique Machado
Okay. That worked. That really worked. APT is working perfectly. Log´s show my user accessing and downloading. I didn´t remove my ntlm lines, just added those u suggested. Now, why? I didn´t understand. 2009/2/3 James Zuelow james_zue...@ci.juneau.ak.us: -Original Message- From:

[squid-users] Squid, ntlm, java, and gotomeeting

2009-02-04 Thread Kevin Blackwell
Hi, I currently have a deployment of Squid. We use it to track surfing habbits of users on Windows 2003 Terminal Servers. It's AD aware and using ntlm. It seems that when a users tries to goto gotomeeting.com and start a meeting. An Auth box pops up that says ntlm at the top and ask for

Re: [squid-users] Forwarding loop detected issue

2009-02-04 Thread Ricardo Nuno
Hi Amos, Thanks for your reply. Ill try to explain better what im trying to do here. | You don't appear to have a: | Squid1-DG-Squid2 setup | | you do appear to have a: | Squid1 - Internet or DG - Squid1 - Internet setup. | | Is there any particular reason you need to have two squid? | The

RE: [squid-users] Certain applications when using NTLM auth

2009-02-04 Thread James Zuelow
-Original Message- From: Henrique Machado [mailto:henrique.cic...@gmail.com] Sent: Wednesday, 04 February, 2009 07:19 To: James Zuelow Cc: squid-users@squid-cache.org Subject: Re: [squid-users] Certain applications when using NTLM auth Okay. That worked. That really worked. APT

RE: [squid-users] Certain applications when using NTLM auth

2009-02-04 Thread James Zuelow
I think my original reply went only to Henrique -- -Original Message- From: Henrique Machado [mailto:henrique.cic...@gmail.com] Sent: Wednesday, 04 February, 2009 07:19 To: James Zuelow Cc: squid-users@squid-cache.org Subject: Re: [squid-users] Certain applications when using NTLM

Re: [squid-users] Squid as HTTPS Proxy Server

2009-02-04 Thread Chris Robertson
Keefe John wrote: Hello, I currently have a standard squid proxy server setup doing forward proxying. I'd like to encrypt the traffic between the clients and the squid server. Have you found a browser that supports this? None of the big four (IE, Firefox, Safari or Chrome) do. All support

Re: [squid-users] Intermittent slow response from Squid

2009-02-04 Thread Chris Robertson
Moses Truong wrote: We have squid running on a server with delay pools enabled. The squidclient usually responds very quickly - in less than 0.03 seconds most of the time. However, there are times when this rises to over 39 seconds. There are 2 Gb of RAM, and there's about 900mb used.

Re: [squid-users] bind socket

2009-02-04 Thread Chris Robertson
vivian t wrote: hello when i try to surf any site from any pc i start the squid server in debug level 1 and found this lines commBind: cannot bind socket FD 14 to X.X.X.X: (99) cannot assign requested address what is it mean ...? It means that Squid can't open a network socket on the IP

[squid-users] reducing access.log to !200 messages

2009-02-04 Thread Woodward, Andrew
Hi group, I'd like to reduce the amount of information being set to access.log so that only requests that's come back !200 are logged. I figure that I can use: acl HTTPnot200 http_status !200 access_log /usr/local/squid/var/logs/access.log squid HTTPnot200 access_log none However, in the

[squid-users] Some sites not working!!!

2009-02-04 Thread viveksnv
Hi All, I am using Squid 2.7 Stable 5 with Tproxy. I have problem while accessing some sites. Example: When accessing http://seek.co.nz, it takes more time and returns error time out. It works good with out squid. I had changed following parameters, but no luck. Is it related with http

[squid-users] Mid-size Schools that use Squid

2009-02-04 Thread Mickey Walker
I am interested in talking with Tech Support individuals that have implemented Squid in mid-sized school districts. I would like to know what kinds of problems they had with the implementation and the performance improvements they received. I am trying to figure out if this will help our

Re: [squid-users] Certain applications when using NTLM auth

2009-02-04 Thread Robert Collins
On Mon, 2009-02-02 at 13:48 -0200, Henrique Machado wrote: Morning, For quite some time I´ve wondered about something. Certain applications worked perfectly with Squid in the past. But, since we´ve integrated it with Active Directory (NTLM auth) some applications just don´t work anymore,

Re: [squid-users] Squid, ntlm, java, and gotomeeting

2009-02-04 Thread Chris Robertson
Kevin Blackwell wrote: Hi, I currently have a deployment of Squid. We use it to track surfing habbits of users on Windows 2003 Terminal Servers. It's AD aware and using ntlm. It seems that when a users tries to goto gotomeeting.com and start a meeting. An Auth box pops up that says ntlm at the

Re: [squid-users] weird traffic coming from my squid box to clients on port 3128

2009-02-04 Thread Bostonian
Thank you, Amos. From access.log, these client IPs with state of Established seem to have some hits from cached contents. I have also noticed that squid.ip.randomport. but majority of established tcp connections is using 3128. Any further idea on this issue is highly appreciated. On Tue, Feb

Re: [squid-users] Forwarding loop detected issue

2009-02-04 Thread Amos Jeffries
Hi Amos, Thanks for your reply. Ill try to explain better what im trying to do here. | You don't appear to have a: | Squid1-DG-Squid2 setup | | you do appear to have a: | Squid1 - Internet or DG - Squid1 - Internet setup. | | Is there any particular reason you need to have two

RE: [squid-users] Squid as HTTPS Proxy Server

2009-02-04 Thread Keefe John
I'm actually not using a browser as the client. I'm using an IPTV streaming client that does support both HTTP and HTTPS proxy. On squid 2.x when I attempt to connect I see the following error in cache.log: 2009/02/04 18:30:30| clientNegotiateSSL: Error negotiating SSL connection on FD 25:

[squid-users] Restricting access by user by time

2009-02-04 Thread jjrowan
A customer has a problematic employee that spends excessive time on Facebook, Myspace and FoxSports. They are willing to let him access these sites before and after work and during lunch but during office hours they want him and others restricted from these sites. I found examples but they

Re: [squid-users] Mid-size Schools that use Squid

2009-02-04 Thread B. Cook
On 2/4/09 4:40 PM, Mickey Walker wrote: I am interested in talking with Tech Support individuals that have implemented Squid in mid-sized school districts. I would like to know what kinds of problems they had with the implementation and the performance improvements they received. I am trying

Re: [squid-users] Restricting access by user by time

2009-02-04 Thread Jose Ildefonso Camargo Tolosa
Hi! On Thu, Feb 5, 2009 at 10:02 PM, jjrowan squid_u...@rownetco.com wrote: A customer has a problematic employee that spends excessive time on Facebook, Myspace and FoxSports. They are willing to let him access these sites before and after work and during lunch but during office hours they

Re: [squid-users] weird traffic coming from my squid box to clients on port 3128

2009-02-04 Thread Amos Jeffries
Bostonian wrote: Thank you, Amos. From access.log, these client IPs with state of Established seem to have some hits from cached contents. I have also noticed that squid.ip.randomport. but majority of established tcp connections is using 3128. Hmm, okay doesn't sound good. Can I see your