Build failed in Jenkins: 3.HEAD-amd64-CentOS-5.3 #2132

2012-11-14 Thread noc
See Changes: [Francesco Chemolli] Bug fix in TextException: gracefully handle exceptions with null text messages. -- [...truncated 3810 lines...] libtool: compile: gcc -DHAVE_CONFIG_

Re: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-14 Thread Alex Rousskov
On 11/14/2012 11:17 AM, Vincent Miszczak wrote: > I’d like to know how Squid resolves the remote host when handling an > intercepted server-first bumped connection, so I’ll be able to setup my > network accordingly. Using the destination address of the intercepted TCP connection, Squid securely c

Re: StringNG merge?

2012-11-14 Thread Kinkie
On Mon, Nov 12, 2012 at 1:05 AM, Amos Jeffries wrote: > > I've run the maintenance script on this branch and it found quite a few bits > of bad code formatting. Please apply the attached patch. It is all > whitespace corrections except one bad include of squid.h and some #if > protection macro nam

Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-14 Thread Vincent Miszczak
Hi guys, I'm testing this feature, working like it should at the moment, great feature :) For now, I've been testing with an inline Linux server using iptables redirection. Both Netfilter REDIRECT and DNAT targets make this configuration work. My production setup won't have the Squid box inline

[PATCH] cert validation cache

2012-11-14 Thread Tsantilas Christos
This patch add squid internal cache for cert validator helper. It is posted as separate patch because investigates the LruMap template class which can be used to implement object caches inside squid. The new LruMap template class used to replace old Ssl::LocalContextStorage class which is used as

[PATCH] SSL server certificate fingerprint ACL type

2012-11-14 Thread Tsantilas Christos
SSL server certificate fingerprint ACL type This patch add the "server_ssl_cert_fingerprint" acl type to match against server SSL certificate fingerprint. The new acl type has the form: acl aclname server_ssl_cert_fingerprint [-sha1] fingerprint1 ... The fingerprint must given in the form: