Re: [squid-users] authentication pass through upstream server

2010-02-23 Thread Amos Jeffries
Mark Engels wrote: Mark Engels wrote: Hello all, Im hopeing this is the place to come when seeking some assistance with a squid proxy configuration issue thats giving myself a little grief, and i certainly hope nothing like this has been asked before. The general idea of what im trying to

Re: [squid-users] Is there a way to stop the Auth Window pop-up in the Web browser?

2010-02-23 Thread Amos Jeffries
Michael Mansour wrote: Hi, I have Squid authenticating AD domain accounts (via it's LDAP helper) to an AD backend, if the user is part of an allowed Internet Users group they get internet access, if they don't authenticate or aren't part of the Internet Users group they don't get internet

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Amos Jeffries
Kevin Kimani wrote: Hi all, Am having a problem trying to authenticate a group that i have set up in my zimbra mail server. the users are stored in an ldap database thus thought that authentication would just be the same as other ldap databases. am able to authenticate users in singular but want

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Kevin Kimani
Find below the configurations placed in my config file auth_param basic program /usr/lib/squid/squid_ldap_auth -v 3 -b dc=openworld,dc=co,dc=ke -f ((uid=%s)(objectClass=zimbraAccount)) -h 192.168.111.130 auth_param basic realm Squid proxy-caching web server auth_param basic credentialsttl 2 hour

Re: [squid-users] error, logs say TCP_DENIED

2010-02-23 Thread Amos Jeffries
Kees Hink wrote: Amos Jeffries wrote: Kees Hink wrote: I'd like to make squid pass requests to pound, but i'm getting an error: The requested URL could not be retrieved (http://pastebin.org/95395). The squid access log says 1266857413.088 0 127.0.0.1 TCP_DENIED/400 2212 GET NONE:// -

Re: [squid-users] Re: SSLBump, help to configure for 3.1.0.16

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 16:32 -0600 skrev Andres Salazar: Thank you guys. Iam now bumping the SSL CONNECT requests. The only problem is that iam getting various errors like this on the cache.log. 2010/02/22 17:27:40| clientNegotiateSSL: Error negotiating SSL connection on FD 8:

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Amos Jeffries
Kevin Kimani wrote: Find below the configurations placed in my config file auth_param basic program /usr/lib/squid/squid_ldap_auth -v 3 -b dc=openworld,dc=co,dc=ke -f ((uid=%s)(objectClass=zimbraAccount)) -h 192.168.111.130 auth_param basic realm Squid proxy-caching web server auth_param basic

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Kevin Kimani
oops had left out tthe deny part acl ldapauth proxy_auth REQUIRED acl InetAccess external InetGroup Admins acl InetDeny external InetGroup Users http_access deny InetDeny http_access deny bannedips http_access allow InetAccess http_access allow my_network When i do this, all are blocked from

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Amos Jeffries
Kevin Kimani wrote: oops had left out tthe deny part acl ldapauth proxy_auth REQUIRED acl InetAccess external InetGroup Admins acl InetDeny external InetGroup Users http_access deny InetDeny http_access deny bannedips http_access allow InetAccess http_access allow my_network When i do this,

[squid-users] authenticate_ip_shortcircuit_ttl

2010-02-23 Thread Matt Richards
Hello, Does anybody know if its possible to setup something similar to authenticate_ip_shortcircuit in squid 3? I have squid 3 running and I am seeing a number of issues with embedded java applications that don't appear to support kerberos based authentication. If not is there anything else

Re: [squid-users] Squid ldap group authentication with Zimbra LDAP

2010-02-23 Thread Kevin Kimani
The setup that i have is in collaboration between zimbra and samba. the users are created in posix accounts and have to belong to either Admins or Users who are translated to Domain Admins Domain Users respectively. Hence want to allow the Admins but deny the Users. The bannedips acl bannedips

Re: [squid-users] better performance using multiple http_port

2010-02-23 Thread Felipe W Damasio
Hi Mr. Jeffreis, 2010/2/22 Amos Jeffries squ...@treenet.co.nz:   The time to do a /usr/bin/time squidclient http://www.terra.com.br/portal; goes down almost immediately after starting squid. Please define 'down'. Error pages returning? TCP links closing unexpectedly? TCP links hanging?

[squid-users] Re: Squid 3 (20) Kerberos Authentication working except for Safari on Mac

2010-02-23 Thread nickcx
Whilst this relates to ISA I believe this is relevant to my question i.e. Safari = No to Kerberos: http://lists.apple.com/archives/client-management/2009/Nov/msg00032.html Would be grateful to hear of any other experiences thanks Nickcx -- View this message in context:

Re: [squid-users] One instance as both, proxy and reverse proxy

2010-02-23 Thread Bastian Spanneberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Chris, Hi Henrik http://www.mail-archive.com/squid-users@squid-cache.org/msg61608.html Thx for the hint. I have at least a partly running configuration now, but still suffer from different problems :) Below is the upper part of my squid.conf

Re: [squid-users] (SOLVED) setting up different filtering based on port number

2010-02-23 Thread Al - Image Hosting Services
Hi, I have a solution: acl custom-auth proxy_auth REQUIRED acl mysite dstdomain .zickswebventures.com acl blocklistA dstdomain .facebook.com .youtube.com acl blocklistB dstdomain .youtube.com acl portA myport 8100 acl portB myport 8101 acl portC myport 8102 acl portJ myport 8109 http_access

[squid-users] TProxy for Squid-2.7.STABLE8

2010-02-23 Thread Richard Wall
Hi Henrik, Amos, etc I've been trying to compile Squid-2.7.STABLE8 (squid-2.HEAD-20100222) but am having difficulty applying the Visolve TProxy-4 patch * http://www.visolve.com/squid/squid-tproxy.php The patch no longer applies cleanly. I spent some time trying to resolve the conflicts, and

[squid-users] Conditional proxy

2010-02-23 Thread Noceg
First, I am very new to proxy servers and Squid. My company has just been acquired and we are connected through a hardware VPN to their offices. We are able to get to all of their webpages that are held locally to them. We have an issue connecting to an off site web page that requires all

[squid-users] squid 3.1.0.15, TPROXY; cache.log empty

2010-02-23 Thread Rhino
my system: Squid 3.1.0.15 (run/installed as squid3) WCCP v2 HASH (Cisco switch) centOS 5.4 kernel 2.6.30.10 w/TPROXY enabled iptables v1.4.4 WCCP established between squid and switch. TPROXY iptables rules set to forward tcp port 80 to 3128 From a client on a separate test subnet can browse

RE: [squid-users] Conditional proxy

2010-02-23 Thread Angelo Höngens
-Original Message- From: Noceg [mailto:jcl...@tigilinea.com] Sent: dinsdag 23 februari 2010 19:16 To: squid-users@squid-cache.org Subject: [squid-users] Conditional proxy First, I am very new to proxy servers and Squid. My company has just been acquired and we are connected

Re: [squid-users] cache manager

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 12:04 +0100 skrev David C. Heitmann: how can i configure my cachemanager with a user and a pass? It's only configured with a password set in squid.conf, and user name only used for logging/audit purposes. Alternatively you can protect the cachemgr functions with basic

Re: [squid-users] which filesystem to use the cache?

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 13:50 -0600 skrev Luis Daniel Lucio Quiroz: extXfs has a performance issue when you have more than 2500 entries per directory. And a Squid setup generally do not have more than 250 entries per directory. Related note: Too large directories (many thousands) will make

Re: [squid-users] GZIP and Squid on a high performance website?

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 21:31 +0100 skrev Gerrit Berkouwer: Can this be done with Apache? So let Apache do the GZIP and serve Squid this gzipped file? Without the eCAP module? Apache handles content negotiation very well, much better than dynamic gzip:ing. It works on static files simply by

Re: [squid-users] error, logs say TCP_DENIED

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 18:06 +0100 skrev Kees Hink: I'd like to make squid pass requests to pound, but i'm getting an error: The requested URL could not be retrieved (http://pastebin.org/95395). The squid access log says 1266857413.088 0 127.0.0.1 TCP_DENIED/400 2212 GET NONE:// - NONE/-

Re: [squid-users] better performance using multiple http_port

2010-02-23 Thread Henrik Nordström
mån 2010-02-22 klockan 19:28 -0300 skrev Felipe W Damasio: We then used iptables to direct each network to a different http_port (all with tproxy), and the time improved on the http_ports that have fewer users... Check your /var/log/messages... most people running into problems like yours

Re: [squid-users] One instance as both, proxy and reverse proxy

2010-02-23 Thread Henrik Nordström
tis 2010-02-23 klockan 16:26 +0100 skrev Bastian Spanneberg: What still doesn't work is, that I can access the web apps running on the SERVICES machine via http://localhost. When I have the proxy enabled in my browser, I can visit access them via http://www.example.net, but localhost doesn't

Re: [squid-users] GZIP and Squid on a high performance website?

2010-02-23 Thread Gerrit Berkouwer
Henrik, let me get this straight: do you suggest to turn GZIP on on Apache, so 2 files exist on Apache, and then let Squid simply serve and cache these 2 files? Or is that not possible with Squid? This is something I cannot find the answer to anywhere! :-) What do you mean by make sure your

Re: [squid-users] better performance using multiple http_port

2010-02-23 Thread Amos Jeffries
On Tue, 23 Feb 2010 09:08:22 -0300, Felipe W Damasio felip...@gmail.com wrote: Hi Mr. Jeffreis, 2010/2/22 Amos Jeffries squ...@treenet.co.nz: The time to do a /usr/bin/time squidclient http://www.terra.com.br/portal; goes down almost immediately after starting squid. Please define

Re: [squid-users] GZIP and Squid on a high performance website?

2010-02-23 Thread Henrik Nordström
tis 2010-02-23 klockan 22:07 +0100 skrev Gerrit Berkouwer: let me get this straight: do you suggest to turn GZIP on on Apache, so 2 files exist on Apache, and then let Squid simply serve and cache these 2 files? Or is that not possible with Squid? This is something I cannot find the answer to

Re: [squid-users] NTLM pass-through breaking uploads to Flickr, etc.

2010-02-23 Thread Mike Ely
On 2/19/10 6:11 PM, Amos Jeffries squ...@treenet.co.nz wrote: Mike Ely wrote: On 2/17/10 4:10 PM, Mike Ely mike...@amyskitchen.net wrote: Hi there, We've got 2.6 stable running as logging only server, no caching going on. Users are authenticated via NTLM if they're on Windows, works

[squid-users] Problem with squid 3.1

2010-02-23 Thread Bruno de Oliveira Bastos
Hi i have a baisc squid 3.1, with only one http_access to localnet, i try to access www.bradescoseguros.com.br, but everytime i use proxy with this site, its very slow, without proxy its ok. I really dont know why, if someone can help me, i try this in 3 different places, with 3 diffetent

Re: [squid-users] TProxy for Squid-2.7.STABLE8

2010-02-23 Thread Amos Jeffries
On Tue, 23 Feb 2010 17:24:17 +, Richard Wall rich...@the-moon.net wrote: Hi Henrik, Amos, etc I've been trying to compile Squid-2.7.STABLE8 (squid-2.HEAD-20100222) but am having difficulty applying the Visolve TProxy-4 patch * http://www.visolve.com/squid/squid-tproxy.php Greetings. We

Re: [squid-users] NTLM pass-through breaking uploads to Flickr, etc.

2010-02-23 Thread Amos Jeffries
On Tue, 23 Feb 2010 15:38:34 -0800, Mike Ely mike...@amyskitchen.net wrote: On 2/19/10 6:11 PM, Amos Jeffries squ...@treenet.co.nz wrote: Mike Ely wrote: On 2/17/10 4:10 PM, Mike Ely mike...@amyskitchen.net wrote: Hi there, We've got 2.6 stable running as logging only server, no

Re: [squid-users] Is there a way to stop the Auth Window pop-up in the Web browser?

2010-02-23 Thread Amos Jeffries
(copy for the list.) It's out of my knowledge zone now, so is someone with SSO working able to assist? On Tue, 23 Feb 2010 16:41:35 -0800 (PST), Michael Mansour mico...@yahoo.com wrote: Hi Amos, --- On Tue, 23/2/10, Amos Jeffries squ...@treenet.co.nz wrote: From: Amos Jeffries

Re: [squid-users] squid 3.1.0.15, TPROXY; cache.log empty

2010-02-23 Thread Amos Jeffries
On Tue, 23 Feb 2010 14:26:38 -0600, Rhino rh...@machlink.com wrote: my system: Squid 3.1.0.15 (run/installed as squid3) WCCP v2 HASH (Cisco switch) centOS 5.4 kernel 2.6.30.10 w/TPROXY enabled iptables v1.4.4 WCCP established between squid and switch. TPROXY iptables rules set to forward

Re: [squid-users] Problem with squid 3.1

2010-02-23 Thread Henrik Nordström
tis 2010-02-23 klockan 21:05 -0300 skrev Bruno de Oliveira Bastos: Hi i have a baisc squid 3.1, with only one http_access to localnet, i try to access www.bradescoseguros.com.br, but everytime i use proxy with this site, its very slow, without proxy its ok. I really dont know why, if someone

Re: [squid-users] Problem with squid 3.1

2010-02-23 Thread Amos Jeffries
On Tue, 23 Feb 2010 21:05:22 -0300, Bruno de Oliveira Bastos kid...@brturbo.com.br wrote: Hi i have a baisc squid 3.1, with only one http_access to localnet, i try to access www.bradescoseguros.com.br, but everytime i use proxy with this site, its very slow, without proxy its ok. I really dont

Re: [squid-users] no source

2010-02-23 Thread Luis Daniel Lucio Quiroz
Le Jeudi 18 Février 2010 19:06:36, Amos Jeffries a écrit : Luis Daniel Lucio Quiroz wrote: Le Mercredi 17 Février 2010 19:21:57, Amos Jeffries a écrit : On Wed, 17 Feb 2010 19:01:38 -0600, Luis Daniel Lucio Quiroz luis.daniel.lu...@gmail.com wrote: 2010/02/17 18:50:49| Failed to select

Re: [squid-users] time to pack?

2010-02-23 Thread Luis Daniel Lucio Quiroz
Le Mercredi 10 Février 2010 16:07:17, Amos Jeffries a écrit : On Wed, 10 Feb 2010 10:51:16 -0600, Luis Daniel Lucio Quiroz luis.daniel.lu...@gmail.com wrote: Le Mardi 9 Février 2010 22:57:58, Amos Jeffries a écrit : Henrik Nordström wrote: tis 2010-02-09 klockan 15:18 -0600 skrev Luis

Re: [squid-users] time to pack?

2010-02-23 Thread Amos Jeffries
Luis Daniel Lucio Quiroz wrote: Le Mercredi 10 Février 2010 16:07:17, Amos Jeffries a écrit : On Wed, 10 Feb 2010 10:51:16 -0600, Luis Daniel Lucio Quiroz luis.daniel.lu...@gmail.com wrote: Le Mardi 9 Février 2010 22:57:58, Amos Jeffries a écrit : Henrik Nordström wrote: tis 2010-02-09

[squid-users] Benchmark performance of Squid Version 2.7 Stable 4

2010-02-23 Thread squid squid
Hi, Currently I am running Squid Version 2.7 Stable 4 on 2 different Linux ES3 box. The specification of the boxes are 2 x Intel Xeon 2.6GHHz CPU and 2.5GB RAM as well as 2 x Xeon 3.6GHz with 2GB RAM. Basically there is no caching configured on the squid apps and it is being used like a

[squid-users] Re: squid redirect to EUNOC problem

2010-02-23 Thread Sergiu Tătar
Hello my friends. I using squid v3.0.stable24 as transparent proxy server compiled with: ./configure '--enable-cache-digests' '--disable-icmp' '--disable-delay-pools' '--disable-internal-dns' '--disable-snmp' '--enable-storeio=ufs,aufs' '--enable-async-io'