[squid-users] ext_kerberos_ldap_group_acl and Kerberos cache

2016-05-17 Thread Eugene M. Zheganin
Hi. I've just checked that squid 3.5.19 sources, and discovered the following fact that is really disturbing: (first some explanation) Markus Moeller, the author of the external kerberos group helper, has implemented the Kerberos credentials cache in the ext_kerberos_ldap_group_acl helper back

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread zodyo
Dear all, I have same problem here, client cant login to a server with auth like LDAP via transparent/static squid. i have try with lusca and the newer squid 3.5.17 -- View this message in context:

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 PS. I read the manual out loud. With an expression. Expensive. :-!:-D 18.05.16 3:11, Robert W Weaver пишет: > Greetings, squid users and devs, > > I think this is usual, but I can't find examples, and I can't make it work. :-) > > The issue is I

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 . and a bit below in squid.conf.documented we can see. # SSL OPTIONS # - # TAG: sslproxy_client_certificate #Client SSL Certificate to use when proxying

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 18.05.16 3:11, Robert W Weaver пишет: > Greetings, squid users and devs, > > I think this is usual, but I can't find examples, and I can't make it work. :-) > > The issue is I need to connect to a site that requires client authentication. Don't

[squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Robert W Weaver
Greetings, squid users and devs, I think this is usual, but I can't find examples, and I can't make it work. :-) The issue is I need to connect to a site that requires client authentication. Don't want to put the key and cert on each individual user, so instead want the key and cert on the

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Heh, qos need to be configured with squid.conf to be something different from 0x0 :) 18.05.16 2:40, J Green пишет: > That could work, I would just need to know at some point, if this event was > triggered. > > Been playing with %st , %>qos , &

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread J Green
That could work, I would just need to know at some point, if this event was triggered. Been playing with %st , %>qos , & % wrote: > On 17/05/2016 6:37 a.m., J Green wrote: > > Re logging, does this eventually get logged by Squid, somewhere? > > > > I assume by "this" you mean the TOS values? > >

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 We need more information. Enable debug wccp gre and the router. See what happens. You may need to redirect the router debugging to the syslogd. This may be as a bug in the router and in Linux - yes, and there are spots in the Sun. Usually wccp

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 We need more information. Enable debug wccp gre and the router. See what happens. You may need to redirect the router debugging to the syslogd. This may be as a bug in the router and in Linux - yes, and there are spots in the Sun. Usually wccp

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Maile Halatuituia
Yuri/Amos I have a situation. I suspect it is my gre tunnel idle time or something but not sure. Every time like after 6 hrs, 4hrs it's not constant but after sometime i have to tear down the tunnel and re established it again in order for packet to be redirected from the router , at the same

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread Amos Jeffries
On 17/05/2016 6:37 a.m., J Green wrote: > Re logging, does this eventually get logged by Squid, somewhere? > I assume by "this" you mean the TOS values? There are the %>qos and %http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Amos Jeffries
On 17/05/2016 8:23 a.m., Aashima Madaan wrote: > Hi, > > I have a PNG file uploaded on server. > As part of Download process, it passes through SQUID to another server for > scanning and then to Client . > > When I send request to Download , the response sends only 27kb of image > back from

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
I have installed squid as my router and below are my iptable rules 675 39972 DNAT tcp -- eth1 * 0.0.0.0/00.0.0.0/0 tcp dpt:80 to:192.168.0.200:3127 0 0 REDIRECT tcp -- eth0 * 0.0.0.0/0 0.0.0.0/0tcp dpt:80 redir ports 3127

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread admin
I have the same config, but in my logs domain names Reet Vyas писал 2016-05-17 15:48: > Here is my txt file, as of now its working but I am getting secure connection > failed, I want to know if we can customize error message like Access Denied . > > In logs I am not getting full URL PFA

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
Here is my txt file, as of now its working but I am getting secure connection failed, I want to know if we can customize error message like Access Denied . In logs I am not getting full URL PFA logs for same. What I have to change in peek and splice ssl bump to get full URL ? Logs:

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread admin
get your blocked_https.txt Reet Vyas писал 2016-05-17 14:47: > Hi > > Below is my squid configuration > > Squid : 3.5.13 > OS ubuntu 14.04 > > http_port 3128 > http_port 3127 intercept > https_port 3129 intercept ssl-bump generate-host-certificates=on >

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
Hi Below is my squid configuration Squid : 3.5.13 OS ubuntu 14.04 http_port 3128 http_port 3127 intercept https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_certs/squid.crt key=/etc/squid/ssl_certs/squid.key

[squid-users] Squid transfers much not requested data from uplink in specific cases

2016-05-17 Thread Garri Djavadyan
Hello Squid community, According to the bug report 4511 [1], Squid may transfer much useless, not requested data from uplink after specific sequence of actions. For example, slow client (access rate 128Kb/s) may begin transfer of big cacheable object (4GB). After some time, another client