Re: [squid-users] SSL Peek and Splice

2015-10-01 Thread Yuri Voinov
01.10.15 17:26, Job пишет: Hello, by reading the 3.5 Squid verson "Peek and splice" features: http://wiki.squid-cache.org/Features/SslPeekAndSplice i would like to ask you two questions, please: 1. in this implementations, i have to install the selfmade Certification Authority as for SSL

Re: [squid-users] R: SSL Peek and Splice

2015-10-01 Thread Yuri Voinov
01.10.15 17:31, Job пишет: Thank Yuri! By opening your png image the accessed domain is visible. So it is possible to block it in https peek and splice mode? Because of this occurs in SSL bump mode, inside HTTPS session. Thank you again! Francesco

[squid-users] Basic example for store.log analyzer

2015-10-01 Thread Eliezer Croitoru
I already had a plan to write something like that in the past and I had some time so I wrote this store.log tool: http://paste.ngtech.co.il/pr3kbbf4q The tool is written in ruby and what it does is "estimating" what is in the cache_dir now based on reading the store.log. Since I have not

[squid-users] Squid ignores crlfile options

2015-10-01 Thread Sebastian Kirschner
Hi I´m using squid (3.5.9) as transparent https proxy with build options (see below) and config (see below , I removed some uninteresting things from the config like caching). To get the system more secure I would like to add crl checking (at the moment static , later maybe dynamic if it's

Re: [squid-users] SSL Peek and Splice

2015-10-01 Thread James Lay
On Thu, 2015-10-01 at 13:26 +0200, Job wrote: > Hello, > > by reading the 3.5 Squid verson "Peek and splice" features: > http://wiki.squid-cache.org/Features/SslPeekAndSplice > > i would like to ask you two questions, please: > > 1. in this implementations, i have to install the selfmade

[squid-users] R: SSL Peek and Splice

2015-10-01 Thread Job
Thank Yuri! By opening your png image the accessed domain is visible. So it is possible to block it in https peek and splice mode? Thank you again! Francesco Da: squid-users [squid-users-boun...@lists.squid-cache.org] per conto di Yuri Voinov

Re: [squid-users] Install squid problems

2015-10-01 Thread S.Kirschner
I think the easiest way for you is to install squid3 via apt-get install squid3. It isnt the version 3.5.9 but is 3.5.8. Best Regards Sebastian -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Install-squid-problems-tp4673495p4673502.html Sent from the

Re: [squid-users] Can not pass Squid basic authentication

2015-10-01 Thread Amos Jeffries
On 1/10/2015 10:41 p.m., birbird wrote: > Hi All, > > > I have setup basic authentication for Squid, but I can not get passed from > browser, just asked to inpu user/password time and time again. > > > I was stuck at, the command > /usr/lib64/squid/ncsa_auth /etc/squid/squid_passwd > dose not

[squid-users] SSL Peek and Splice

2015-10-01 Thread Job
Hello, by reading the 3.5 Squid verson "Peek and splice" features: http://wiki.squid-cache.org/Features/SslPeekAndSplice i would like to ask you two questions, please: 1. in this implementations, i have to install the selfmade Certification Authority as for SSL Bump? 2. how can i block domain

Re: [squid-users] Install squid problems

2015-10-01 Thread Amos Jeffries
On 2/10/2015 12:25 a.m., S.Kirschner wrote: > I think the easiest way for you is to install squid3 via apt-get install > squid3. > > It isnt the version 3.5.9 but is 3.5.8. > On Ubuntu it is 3.3.8 still. One needs to upgrade to Debian Testing repositories for more up to date software. sawa;

Re: [squid-users] How to avoid Squid disclosing the origin server IP when there is an error

2015-10-01 Thread Manuel
Hi again, Thank you for all the information regarding this matter. Anyhow, I must say that I changed in my message the origin server to 127.0.0.1 just to not make public the real address of the origin server but the address that was made public was the real IP of that origin server which was

Re: [squid-users] Squid ignores crlfile options

2015-10-01 Thread Amos Jeffries
On 1/10/2015 11:54 p.m., Sebastian Kirschner wrote: > Hi > > I´m using squid (3.5.9) as transparent https proxy with build options (see > below) and config (see below , I removed some uninteresting things from the > config like caching). > > To get the system more secure I would like to add

[squid-users] ICAP response header ACL

2015-10-01 Thread Steve Hill
The latest adaption response headers are available through the %adapt::headers through an ACL? The documentation says that adaptation headers are available in the notes, but this only appears to be headers set with adaptation_meta, not the ICAP response headers. I had also considered using

Re: [squid-users] ICAP response header ACL

2015-10-01 Thread Alex Rousskov
On 10/01/2015 07:43 AM, Steve Hill wrote: > The latest adaption response headers are available through the > %adapt:: headers through an ACL? > > The documentation says that adaptation headers are available in the > notes, but this only appears to be headers set with adaptation_meta, and with

[squid-users] Transparent proxy with Ubuntu 15.04 and Squid3

2015-10-01 Thread Jake
I have a Squid/Dansguardian proxy server that successfully works when the client web browser is manually configured to use the proxy address:port. What I want to do is configure a transparent proxy server, presuming I wouldn't have to manually configure browsers. My LAN environment diagram:

Re: [squid-users] analyzing cache in and out files

2015-10-01 Thread Matus UHLAR - fantomas
Em 30/09/15 04:13, Matus UHLAR - fantomas escreveu: the problem was iirc in caching partial objects http://wiki.squid-cache.org/Features/PartialResponsesCaching that problem could be avoided with properly setting range_offset_limit http://www.squid-cache.org/Doc/config/range_offset_limit/ but

[squid-users] [3.5.9]: Error negotiating SSL connection on FD 12: error:14094416:SSL routines:SSL3_READ_BYTES:sslv3 alert certificate unknown (1/0)

2015-10-01 Thread David Touzeau
Dear I'm using Squid Cache: Version 3.5.9-20150922-r13918 in transparent mode with SSL hooked In my config, i did not bump any site ( just to pass SSL protocol to squid in transparent mode) I'm trying to connect to https://raj2796.wordpress.com In cache.log 2015/10/02 00:07:05 kid1|

Re: [squid-users] after changed from 3.4.13 to 3.5.8 sslbump doesn't work for the site https://banking.postbank.de/

2015-10-01 Thread HackXBack
we wish that somebody can build a good fingerprinting algorithm for pinning clients Thank you Alex -- View this message in context:

Re: [squid-users] Transparent proxy with Ubuntu 15.04 and Squid3

2015-10-01 Thread Amos Jeffries
On 2/10/2015 8:15 a.m., Jake wrote: > I have a Squid/Dansguardian proxy server that successfully works when > the client web browser is manually configured to use the proxy address:port. > > What I want to do is configure a transparent proxy server, presuming I > wouldn't have to manually

Re: [squid-users] [3.5.9]: Error negotiating SSL connection on FD 12: error:14094416:SSL routines:SSL3_READ_BYTES:sslv3 alert certificate unknown (1/0)

2015-10-01 Thread Amos Jeffries
On 2/10/2015 11:18 a.m., David Touzeau wrote: > > Dear > > I'm using Squid Cache: Version 3.5.9-20150922-r13918 in transparent mode > with SSL hooked > In my config, i did not bump any site ( just to pass SSL protocol to > squid in transparent mode) > > I'm trying to connect to

[squid-users] Can not pass Squid basic authentication

2015-10-01 Thread birbird
Hi All, I have setup basic authentication for Squid, but I can not get passed from browser, just asked to inpu user/password time and time again. I was stuck at, the command /usr/lib64/squid/ncsa_auth /etc/squid/squid_passwd dose not give any output. I think it means squid can not get the