Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
sorry it seems that http://squid-web-proxy-cache.1019090.n4.nabble.com doesnt remove posts Yuri Voinov wrote > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > I said exactly: "Cache peer cannot use re-crypting right now". > > No matter what do you have behind cache_peer. > > 30.03.16

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I said exactly: "Cache peer cannot use re-crypting right now". No matter what do you have behind cache_peer. 30.03.16 2:40, Baselsayeh пишет: > is there a workaround that i can use cache peer and squid sslbump? > isnt stunnel is using ssl that

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
sorry it seems that http://squid-web-proxy-cache.1019090.n4.nabble.com doesnt remove posts -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/ssl-stunnel-and-cache-peer-tp4676844p4676852.html Sent from the Squid - Users mailing list archive at Nabble.com.

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
is there a workaround that i can use cache peer and squid sslbump? isnt stunnel is using ssl that squid dont need to re-crypting? Yuri Voinov wrote > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > He means something like privoxy. > > It possible tunnel https. > > The similar config

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 There is no workaround. 30.03.16 2:38, Baselsayeh пишет: > is there a workaround that i can use ssl bump with cache peer? > > > Yuri Voinov wrote > He means something like privoxy. > > It possible tunnel https. > > The similar config often uses

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
is there a workaround that i can use ssl bump with cache peer? Yuri Voinov wrote > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > He means something like privoxy. > > It possible tunnel https. > > The similar config often uses for tunnel some proxied connections to Tor > or another

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 He means something like privoxy. It possible tunnel https. The similar config often uses for tunnel some proxied connections to Tor or another ISP or something. But the thing he required is not possible. Cache peers does not support re-crypting

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Antony Stone
On Tuesday 29 Mar 2016 at 20:11, Baselsayeh wrote: > my setup is > my pc with squid(as stunnel client) -> stunnel and proxy(normal non > https) > ive got these errors: > 2-i cant surf any https site What do you mean by the remote proxy being "normal non https"? Is that perhaps the reason

Re: [squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
And note that i need ssl bumping not splicing Baselsayeh wrote > hello > im trying to get squid + stunnel working > my setup is > > my pc with squid(as stunnel client) -> stunnel and proxy(normal non > https) > squid should be bumping the connection > > my config: > > https_port 3429

[squid-users] ssl + stunnel and cache peer

2016-03-29 Thread Baselsayeh
hello im trying to get squid + stunnel working my setup is my pc with squid(as stunnel client) -> stunnel and proxy(normal non https) squid should be bumping the connection my config: https_port 3429 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=200MB

Re: [squid-users] We have a big problems with Squid 3.3.8, it's a bug ?

2016-03-29 Thread Rafael Akchurin
Hello Olivier, I really do not know. This also is of great interest to me. Hopefully knowledgeable people on the list will be able to explain. Best regards, Rafael From: Olivier CALVANO [mailto:o.calv...@gmail.com] Sent: Tuesday, March 29, 2016 7:32 PM To: Rafael Akchurin

Re: [squid-users] We have a big problems with Squid 3.3.8, it's a bug ?

2016-03-29 Thread Olivier CALVANO
hi thanks for your answer, i have a entry into generic information. it must remove? but this will not happen again? regards olivier 2016-03-29 18:33 GMT+02:00 Rafael Akchurin : > Hello Olivier, > > > > See if you have credentials cached in the credentials manager

Re: [squid-users] We have a big problems with Squid 3.3.8, it's a bug ?

2016-03-29 Thread Rafael Akchurin
Hello Olivier, See if you have credentials cached in the credentials manager in windows. Best regards, Rafael From: squid-users [mailto:squid-users-boun...@lists.squid-cache.org] On Behalf Of Olivier CALVANO Sent: Tuesday, March 29, 2016 6:23 PM To: squid-users@lists.squid-cache.org Subject:

[squid-users] We have a big problems with Squid 3.3.8, it's a bug ?

2016-03-29 Thread Olivier CALVANO
Hi we use on a new server Squid 3.3.8 on CentOS 7 with a Active Directory Authentification (tested in negotiate_wrapper but same problems with ntlm_auth) . That's work's very good a time but without reason, a limited user can't access to internet and i don't know why. In the logs, we have:

Re: [squid-users] Squid with LDAP-authentication: bypass selected URLs

2016-03-29 Thread FredB
> > auth_param basic program /usr/sbin/squid_ldap_auth -b T=MYDOMAIN -f > "uid=%s" > -s sub -h 192.168.1.1 acl password > auth_param basic children 10 > auth_param basic realm Internetzugang im VERWALTUNGSNETZ FAL-BK: > Bitte mit > den Daten aus diesem Netzwerk anmelden! > acl password

Re: [squid-users] Squid with LDAP-authentication: bypass selected URLs

2016-03-29 Thread Verwaiser
Hello Fred, thank you for your help! Ok, I tried to insert a the acl in auth_param block as you described: acl pdfdoc dstdomain webgate.ec.europa.eu http_access allow password !pdfdoc http_access allow pdfdoc but no success was shown using the pdf-doc. Then: Testing access to

Re: [squid-users] Squid Log

2016-03-29 Thread Marc Mapplebeck
I'll give that regex a try, funny though, that's just built on the code from lightparser.pl, must be a problem with the stock code as well, the original 4 entries that were shipped with it are exactly like the one I posted. Thanks, - Marc -_-_-_-_-_-_-_-_-_-_-_- Marc A. Mapplebeck,