Re: [squid-users] Internet Browsing very slow after implementing Squid peek & splice + Access log not tracing full URL

2016-05-18 Thread Garri Djavadyan
On Thu, 2016-05-19 at 05:27 +1200, Amos Jeffries wrote: > On 19/05/2016 2:21 a.m., Garri Djavadyan wrote: > > > > On Thu, 2016-05-19 at 00:39 +1200, Amos Jeffries wrote: > > > > > > Using ignore-private and ignore-must-revalidate on the same > > > refresh_pattern is *extremely* dangerous. Just

Re: [squid-users] Problem talking ICAP to McAfee Web Gateway

2016-05-18 Thread Alex Rousskov
On 05/18/2016 03:56 PM, Rob Worsnop wrote: > In certain circumstances, MWG will start streaming the RESPMOD response > before Squid has finished sending all the chunks in the RESPMOD request. > > Squid does not like this. If Squid does not like this, it is a Squid bug IMO. > As far as I can

[squid-users] Problem talking ICAP to McAfee Web Gateway

2016-05-18 Thread Rob Worsnop
I'm having a problem talking ICAP with McAfee Web Gateway (MWG). In certain circumstances, MWG will start streaming the RESPMOD response before Squid has finished sending all the chunks in the RESPMOD request. Squid does not like this. It seems to interpret the arrival of response traffic as a

Re: [squid-users] ext_kerberos_ldap_group_acl and Kerberos cache

2016-05-18 Thread Eugene M. Zheganin
Hi. On 18.05.2016 16:29, Amos Jeffries wrote: I don't know what you mean by "the main tree". But The feature you describe does not qualify for adding to the 3.5 production release series. The only features added to a series after is goes to "stable" production releases are ones which resolve

Re: [squid-users] Internet Browsing very slow after implementing Squid peek & splice + Access log not tracing full URL

2016-05-18 Thread Amos Jeffries
On 19/05/2016 2:21 a.m., Garri Djavadyan wrote: > On Thu, 2016-05-19 at 00:39 +1200, Amos Jeffries wrote: >> Using ignore-private and ignore-must-revalidate on the same >> refresh_pattern is *extremely* dangerous. Just asking to get your >> cache pwned. > > I'm also using the both options on the

Re: [squid-users] Transparent Mode w/ Peek and Splice trouble

2016-05-18 Thread Amos Jeffries
On 19/05/2016 2:14 a.m., s...@kpa.gr wrote: > Hello! > > I am currently setting up a squid server, which should serve as a > transparent proxy in our network. > > We mainly need it to do the following: > Allow and Block Domains on HTTP and HTTPS protocol (withOUT bumping the > traffic). We only

Re: [squid-users] Transparent Mode w/ Peek and Splice trouble

2016-05-18 Thread James Lay
On 2016-05-18 08:14, s...@kpa.gr wrote: Hello! I am currently setting up a squid server, which should serve as a transparent proxy in our network. We mainly need it to do the following: Allow and Block Domains on HTTP and HTTPS protocol (withOUT bumping the traffic). We only want to allow

Re: [squid-users] Internet Browsing very slow after implementing Squid peek & splice + Access log not tracing full URL

2016-05-18 Thread Alex Rousskov
On 05/18/2016 05:05 AM, Sagar Malve wrote: > when we pass the Network through Squid the > Internet work very slow In addition to other comments on this thread, please note that, according to my _ballpark_ estimates, Squid "ssl_bump bump" performance is about 10% of regular plain traffic

Re: [squid-users] Internet Browsing very slow after implementing Squid peek & splice + Access log not tracing full URL

2016-05-18 Thread Garri Djavadyan
On Thu, 2016-05-19 at 00:39 +1200, Amos Jeffries wrote: > Using ignore-private and ignore-must-revalidate on the same > refresh_pattern is *extremely* dangerous. Just asking to get your > cache pwned. I'm also using the both options on the same refresh_pattern for several years. Can you explain

Re: [squid-users] squid_ldap_auth: WARNING, LDAP search error 'Referral'

2016-05-18 Thread L . P . H . van Belle
This has probely todo with the latest samba/windows updates. But your giving so little info. You can confirm it by testing the ldap. Connect to ldaps (port 636). Does that work? No, try adding in /etc/ldap/ldap.conf TLS_REQCERT allow And make sure your AD Root CA cert is know in : TLS_CACERT

Re: [squid-users] squid_ldap_auth: WARNING, LDAP search error 'Referral'

2016-05-18 Thread Amos Jeffries
On 19/05/2016 12:25 a.m., Manduva, Ranga Sai wrote: > Hi, > > Does anyone had similar issue ?? Is there any workaround for it ? Something > like configure squid to follow referral etc.. > Squid has nothing to do with those layers of operations. The closest it gets is to pass the helper command

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-18 Thread Robert W Weaver
>> 18.05.16 3:11, Robert W Weaver пишет: >>> The issue is I need to connect to a site that requires client >>> authentication. Don't want to put the key and cert on each individual >>> user, so instead want the key and cert on the proxy. >>> Diagram: >>> User A ---> Squid S ---> Server B >>>

Re: [squid-users] squid_ldap_auth: WARNING, LDAP search error 'Referral'

2016-05-18 Thread Manduva, Ranga Sai
Hi, Does anyone had similar issue ?? Is there any workaround for it ? Something like configure squid to follow referral etc.. Thanks. Regards, Ranga -Original Message- From: Manduva, Ranga Sai Sent: Monday, May 16, 2016 6:32 PM To: 'squid-users@lists.squid-cache.org'

Re: [squid-users] ext_kerberos_ldap_group_acl and Kerberos cache

2016-05-18 Thread Amos Jeffries
On 18/05/2016 5:57 p.m., Eugene M. Zheganin wrote: > Hi. > > I've just checked that squid 3.5.19 sources, and discovered the > following fact that is really disturbing: > (first some explanation) > Markus Moeller, the author of the external kerberos group helper, has > implemented the Kerberos

[squid-users] Internet Browsing very slow after implementing Squid peek & splice + Access log not tracing full URL

2016-05-18 Thread Sagar Malve
Scenario : I want to block certain HTTPS website using SSL Bump and without installing any SSL Certificate on Clients End as I will be distributing this Same Network for Mobile Devices so I don't want to keep installing certificate in each Mobile Device like Android / IOS / Windows etc phones

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-18 Thread Matus UHLAR - fantomas
On 17.05.16 17:11, Robert W Weaver wrote: The issue is I need to connect to a site that requires client authentication. Don't want to put the key and cert on each individual user, so instead want the key and cert on the proxy. Diagram: User A ---> Squid S ---> Server B ^^

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-18 Thread Matus UHLAR - fantomas
On 17.05.16 18:10, zodyo wrote: I have same problem here, client cant login to a server with auth like LDAP via transparent/static squid. i have try with lusca and the newer squid 3.5.17 how can this be the same problem? It's very different problem. when talking about "transparent" proxy,