Re: [squid-users] caching videos over https?

2016-11-19 Thread Yuri Voinov
This is fake. 19.11.2016 20:56, Bakhtiyor Homidov пишет: > thanks, yuri, > > just found https://cachevideos.com/, what do you think about this? > > > > > On Sat, Nov 19, 2016 at 7:16 PM, Yuri Voinov <yvoi...@gmail.com > <mailto:yvoi...@gmail.com>> wro

Re: [squid-users] caching videos over https?

2016-11-19 Thread Yuri Voinov
http://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit http://wiki.squid-cache.org/Features/StoreID http://wiki.squid-cache.org/Features/StoreID/DB http://wiki.squid-cache.org/ConfigExamples/DynamicContent

Re: [squid-users] Trusted CA Certificate with ssl_bump

2016-11-15 Thread Yuri Voinov
15.11.2016 22:28, Alex Crow пишет: > On 15/11/16 16:22, Yuri Voinov wrote: >> >>> You can if you have control over the clients, ie install your CA into >>> the browser/OS. >> ... and this can be illegal ;) >> > > YMMV (depending on where y

Re: [squid-users] Trusted CA Certificate with ssl_bump

2016-11-15 Thread Yuri Voinov
15.11.2016 20:43, Alex Crow пишет: > > > On 15/11/16 14:28, Yuri Voinov wrote: >> >> >> So, you can't do SSL bump without users notification. > > You can if you have control over the clients, ie install your CA into > the browser/OS. ... and this can be ille

Re: [squid-users] Trusted CA Certificate with ssl_bump

2016-11-15 Thread Yuri Voinov
15.11.2016 20:22, Sergio Belkin пишет: > Hi, > > When using something like that: > > http_port 8080 intercept ssl-bump generate-host-certificates=on > dynamic_cert_mem_cache_size=4MB > cert=/home/proxy/ssl_cert/example.com.cert > key=/home/proxy/ssl_cert/example.com.private > > > Is possible to

Re: [squid-users] squid-users Digest, Vol 27, Issue 26

2016-11-14 Thread Yuri Voinov
15.11.2016 2:46, Patrick Flaherty пишет: > RE: squid-users Digest, Vol 27, Issue 26 > > Message: 3 > > Date: Tue, 15 Nov 2016 02:12:49 +0600 > > From: Yuri Voinov <yvoi...@gmail.com<mailto:yvoi...@gmail.com>> > > To:squid-users@lists.squid-cache.org&l

Re: [squid-users] 21 sec connect timeout

2016-11-14 Thread Yuri Voinov
No, TAG_NONE/503 is not able to connect. 15.11.2016 2:05, Patrick Flaherty пишет: > > Hello, > > > > Can anyone tell me if the ‘*HIER_NONE’* entries below is Squid not > able to connect to www.website.com ? The 21 > sec timeout is a classic Windows TCP connection

Re: [squid-users] Squid multithread

2016-11-14 Thread Yuri Voinov
14.11.2016 21:59, Eduardo Carneiro пишет: > Yuri Voinov wrote >> http://wiki.squid-cache.org/Features/SmpScale >> >> http://wiki.squid-cache.org/MultipleInstances >> >> >> 14.11.2016 20:22, Eduardo Carneiro пишет: >>> Hi everyone! >>> &

Re: [squid-users] Squid multithread

2016-11-14 Thread Yuri Voinov
14.11.2016 21:59, Eduardo Carneiro пишет: > Yuri Voinov wrote >> http://wiki.squid-cache.org/Features/SmpScale >> >> http://wiki.squid-cache.org/MultipleInstances >> >> >> 14.11.2016 20:22, Eduardo Carneiro пишет: >>> Hi everyone! >>> &

Re: [squid-users] Squid multithread

2016-11-14 Thread Yuri Voinov
http://wiki.squid-cache.org/Features/SmpScale http://wiki.squid-cache.org/MultipleInstances 14.11.2016 20:22, Eduardo Carneiro пишет: > Hi everyone! > > I have a Squid 3.5.19 with dynamic content cache using url rewrite. It's a > virtual machine (VMWare) with 2 quad-core processors each. Squid

Re: [squid-users] SSL bump not working w/some sites.

2016-11-07 Thread Yuri Voinov
It seems simple no intermediate certificate in chain. Root CA bundle(s) usually does not contain all intermediate CA's, because of browsers can simple download it from server/site. Squid can't do auto-downloading (autocomplete) certificate chains and require to confiugure

Re: [squid-users] squid warning

2016-11-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 04.11.2016 18:39, Matus UHLAR - fantomas пишет: > On 04.11.16 18:23, Yuri wrote: >> This warning is irrelevent to your google issue. > > are you sure that creating fake google certificate is not the reason of > delay? I'm talking about this

Re: [squid-users] Certificate transparency: problem for ssl-bumping, no effect, or?

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 02.11.2016 2:58, Alex Rousskov пишет: > On 11/01/2016 02:47 PM, Yuri Voinov wrote: > >> if the SSL bump will be impossible to do - >> whether it should be understood that in such a situation you close the >> proj

Re: [squid-users] Certificate transparency: problem for ssl-bumping, no effect, or?

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 02.11.2016 2:03, Alex Rousskov пишет: > On 10/31/2016 04:13 PM, L. A. Walsh wrote: >> Google is pushing this for all websites by October 2017 > > Just Extended Validation (EV) sites, to be exact AFAICT. All other sites > will be forced into the

Re: [squid-users] iOS 10.x, https and squid

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 02.11.2016 0:47, Eugene M. Zheganin пишет: > Hi. > > Does anyone have issues with iOS 10.x devices connecting through proxy (3.5.x) to the https-enabled sites ? Because I do. Non-https sites work just fine, but https ones just stuck on loading.

Re: [squid-users] iOS 10.x, https and squid

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 02.11.2016 0:47, Eugene M. Zheganin пишет: > Hi. > > Does anyone have issues with iOS 10.x devices connecting through proxy (3.5.x) to the https-enabled sites ? Because I do. Non-https sites work just fine, but https ones just stuck on loading.

Re: [squid-users] Getting "browser history" from squid logs

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 01.11.2016 23:01, Andrea Venturoli пишет: > Hello. > > I'd think this question would have appeared so many times, still searching the web did not help... > > I'm familiar with Squid logs and even with some of the several software that produces

Re: [squid-users] Getting "browser history" from squid logs

2016-11-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 As you certainly know, the history of the browser is not the same as the proxy access log. Putting the problem, as a rule should clarify - what you want to achieve? If the purpose forensic - from this point of view there is no difference.

Re: [squid-users] Certificate transparency: problem for ssl-bumping, no effect, or?

2016-10-31 Thread Yuri Voinov
:) 01.11.2016 4:41, Yuri Voinov пишет: > > When the future comes - then we will worry. What wonder, then? > > October 2017 is not tomorrow. > > > 01.11.2016 4:13, L. A. Walsh пишет: > > Google is pushing this for all websites by October 2017 > > > One issue to b

Re: [squid-users] Certificate transparency: problem for ssl-bumping, no effect, or?

2016-10-31 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 When the future comes - then we will worry. What wonder, then? October 2017 is not tomorrow. 01.11.2016 4:13, L. A. Walsh пишет: > Google is pushing this for all websites by October 2017 > > One issue to be "caught" are subordinated CA certs

Re: [squid-users] Default state for the option generate-host-certificates

2016-10-28 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It seems bug. Just always specify option explicity. 28.10.2016 18:56, Garri Djavadyan пишет: > Hello list, > > The last sentence for generate-host-certificates[=] option > paragraph states: > > This option is enabled by default when

Re: [squid-users] Squid Logs local and remote

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 or on writable NFS-mount from remote server. :) 28.10.2016 1:40, Ambrose LI пишет: > 2016-10-27 15:35 GMT-04:00 Jose Torres-Berrocal : >> Is there a way that I can have the squid logs locally and remotely?

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Good. We are came to an agreement :) Peace :) Let's support to op :) 28.10.2016 1:14, Antony Stone пишет: > On Thursday 27 October 2016 at 21:09:44, Yuri Voinov wrote: > >> OP originally wrote - "I have no IPtables and so

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
we argue? Op originally wrote - "I have no iptables and so on." He needs specific guidance, not word games. So, no? 28.10.2016 1:04, Yuri Voinov пишет: > > (facepalm) > > rdr(REDIRECT) is NAT functionality? Yes or no? > > > 28.10.2016 0:59, Antony Stone пишет: > &

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 (facepalm) rdr(REDIRECT) is NAT functionality? Yes or no? 28.10.2016 0:59, Antony Stone пишет: > On Thursday 27 October 2016 at 20:57:04, Yuri Voinov wrote: > >> You know method to do this without NAT? ;) > > I know how to

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You know method to do this without NAT? ;) 28.10.2016 0:54, Antony Stone пишет: > On Thursday 27 October 2016 at 19:51:22, Yuri Voinov wrote: > >> You absolutely sure, Eliezier? :) > > Yes - you do not use DNAT. >

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 erdosain9, here is documentation your required. http://wiki.squid-cache.org/ConfigExamples/Intercept Sadly, but interception proxy with modern Squid, in addition to router with PBR/WCCP redirection, also always required NAT, configured on proxy

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
tructions on how to do it in a mikrotik. > > Eliezer > > > Eliezer Croitoru > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngtech.co.il > > > -Original Message- > From: squid-users [mailto:squid-users-boun...@lists.squid-cache.o

Re: [squid-users] Transparent and non Transparent at the same time

2016-10-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You absolutely sure, Eliezier? :) 27.10.2016 23:46, Eliezer Croitoru пишет: > You need routing policy not DNAT. > > Eliezer > > > Eliezer Croitoru > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngtech.co.il > > >

Re: [squid-users] filtering http(s) sites, transparently

2016-10-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 27.10.2016 4:37, Amos Jeffries пишет: > On 27/10/2016 7:55 a.m., Yuri Voinov wrote: >> >> 27.10.2016 0:54, Jok Thuau пишет: >> >>> Setting up the client and the proxy to use a common infrastructure for >>&

Re: [squid-users] filtering http(s) sites, transparently

2016-10-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 27.10.2016 0:54, Jok Thuau пишет: > > On Wed, Oct 26, 2016 at 11:45 AM, Yuri Voinov <yvoi...@gmail.com <mailto:yvoi...@gmail.com>> wrote: > > > > Jok, > > it can be DNS leak. Does you tested i

Re: [squid-users] filtering http(s) sites, transparently

2016-10-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jok, it can be DNS leak. Does you tested it? 8.8.8.8 can be poisoned (probably) or intercepted by ISP. 27.10.2016 0:01, Jok Thuau пишет: > After being side-tracked with a few different project, I ended up with the > config below. It appears to

Re: [squid-users] skype connection problem

2016-10-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 25.10.2016 21:45, Andrea Venturoli пишет: > On 10/25/16 16:43, Yuri Voinov wrote: >> >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA256 >> >> Wireshark? :) > > No good: I don't trust MS not to

Re: [squid-users] skype connection problem

2016-10-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Wireshark? :) No, I have no IP list. In my environment this not required. 25.10.2016 20:41, Andrea Venturoli пишет: > On 10/25/16 16:26, Yuri Voinov wrote: > >> You LAN settings is too restrictive. AFAIK you require to pe

Re: [squid-users] skype connection problem

2016-10-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 25.10.2016 20:35, Eliezer Croitoru пишет: > Hey Nicolas, > > I know that it should work but it will request all sort of weird CONNECT requests to other parties. > Skype is designed to work as a p2p network and there for might not work as

Re: [squid-users] skype connection problem

2016-10-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You LAN settings is too restrictive. AFAIK you require to permit traffic to skype servers directly from your clients. Without proxy. Because of Skype voice traffic is non-HTTP(S). And proxy can't know how to handle it. 25.10.2016 20:25, Nicolas

Re: [squid-users] Squid with ASR9001

2016-10-24 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 No, Juniper is not my area ;) It is impossible to know everything :) -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJYDpOEAAoJENNXIZxhPexGUWEH/jdttWLpJNQm49z0XlTMwwIM

Re: [squid-users] Squid with ASR9001

2016-10-24 Thread Yuri Voinov
e much more efficient then Policy > Based routing. > I believe it’s very simple to implement in linux. > > Eliezer > > > Eliezer Croitoru <http://ngtech.co.il/lmgtfy/> > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngtech.co.il > &g

Re: [squid-users] Squid with ASR9001

2016-10-24 Thread Yuri Voinov
le it would be to implement the same concepts with an > HTTP\tcp interface. > > Eliezer > > > Eliezer Croitoru <http://ngtech.co.il/lmgtfy/> > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngtech.co.il > > > From: Yuri Voi

Re: [squid-users] Squid with ASR9001

2016-10-24 Thread Yuri Voinov
eally just all. The main thing to understand how the network works on L2 and L3 in OSI. And a bit network hardware knowledge. > > Eliezer > > > Eliezer Croitoru <http://ngtech.co.il/lmgtfy/> > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngt

Re: [squid-users] Squid with ASR9001

2016-10-24 Thread Yuri Voinov
s like all of the ASR9000 range which makes use of IOS XR no > longer supports WCCP. > Please, provide prooflink from Cisco. > > > > Policy Based Routing has been replaced by ACL Based Forwarding or ABF. > So? This is therminology difference, if any. > > > > > > > From

Re: [squid-users] skype connection problem

2016-10-24 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 24.10.2016 22:28, Nicolas Valera пишет: > > > On 10/24/2016 01:21 PM, Yuri Voinov wrote: >> > > 24.10.2016 22:19, Nicolas Valera пишет: > >>> Hi Yuri, thanks for the answer! > >>> > >>> we

Re: [squid-users] skype connection problem

2016-10-24 Thread Yuri Voinov
4320 80% 43200 reload-into-ims ignore-no-cache > refresh_pattern -i live.net/.*\.(cab|exe|ms[i|u|f]|[ap]sf|wm[v|a]|dat|zip) 4320 80% 43200 reload-into-ims ignore-no-cache > refresh_pattern .020%4320 > > -

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-24 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 24.10.2016 22:05, Garri Djavadyan пишет: > On 2016-10-24 19:40, Garri Djavadyan wrote: >> So, the big G sends 304 only to HEAD requests, although it is a >> violation [1], AIUI: >> >> curl --head -H 'If-Modified-Since: Thu, 20 Oct 2016 08:29:09

Re: [squid-users] skype connection problem

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 24.10.2016 4:11, N V пишет: > hi there, > i've had problems with windows skype clients with the only internet connection is through squid. the clients can login successful but when they make a call, it hangs after 12 secconds. > > I checked the

Re: [squid-users] Squid with ASR9001

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 23.10.2016 23:16, Garth van Sittert | BitCo пишет: > > Good day all > > > > Has anyone had any experience setting up Squid with any IOS XR Cisco routers? The Cisco ASR9000 range doesn’t support WCCP and I cannot find any examples online. >

Re: [squid-users] Squid with ASR9001

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 https://supportforums.cisco.com/discussion/12227051/ios-xr-and-wccp https://supportforums.cisco.com/discussion/11561126/wccp-not-working-after-asr-migration-done 23.10.2016 23:16, Garth van Sittert | BitCo пишет: > Cisco ASR9000 -BEGIN PGP

Re: [squid-users] squid-users Digest, Vol 26, Issue 82

2016-10-23 Thread Yuri Voinov
016 at 15:26:54, Yuri Voinov wrote: > >> You can have slow DNS. Consider to use local caching DNS recursor as >> source for proxy & users. > > Why would that result in requests via Squid being slower than direct? > > @Krishna: You *have* confirmed that Squid requests

Re: [squid-users] squid-users Digest, Vol 26, Issue 82

2016-10-23 Thread Yuri Voinov
e edit your Subject line so it is more specific > than "Re: Contents of squid-users digest..." > > > Today's Topics: > >1. Slowness in Squid (Krishna Kulkarni) >2. Re: Slowness in Squid (Antony Stone) >3. external_acl_type problem (re

Re: [squid-users] Slowness in Squid

2016-10-23 Thread Yuri Voinov
then. 23.10.2016 18:15, Yuri Voinov пишет: > > > > 23.10.2016 18:09, Matus UHLAR - fantomas пишет: > >> 23.10.2016 17:40, Yuri Voinov пишет: > >>> This effect is good known to all who have worked with relational > >>> databases. In fact, it is typical in gene

Re: [squid-users] Slowness in Squid

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 23.10.2016 18:09, Matus UHLAR - fantomas пишет: >> 23.10.2016 17:40, Yuri Voinov пишет: >>> This effect is good known to all who have worked with relational >>> databases. In fact, it is typical in general for all caches

Re: [squid-users] Slowness in Squid

2016-10-23 Thread Yuri Voinov
. But this is from the category of personal experience. Everyone can choose their own road to hell. :) 23.10.2016 17:40, Yuri Voinov пишет: > > This effect is good known to all who have worked with relational > databases. In fact, it is typical in general for all caches except > purpose-

Re: [squid-users] Slowness in Squid

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This effect is good known to all who have worked with relational databases. In fact, it is typical in general for all caches except purpose-built highly scalable systems. 23.10.2016 17:37, Matus UHLAR - fantomas пишет: > doesn't that imply kind

Re: [squid-users] Slowness in Squid

2016-10-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Keep in mind - a huge in-memory cache does not always give the acceleration. Moreover, in most cases you can get the opposite effect expected. It is a common misconception - that the giant memory cache will give a giant performance gain.

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 22.10.2016 19:32, gar...@comnet.uz пишет: > On 2016-10-22 17:56, Antony Stone wrote: >> Disclaimer: I am not a Squid developer. >> >> On Saturday 22 October 2016 at 14:43:55, gar...@comnet.uz wrote: >> >>> IMO: >>> >>> The only reason I believe

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I will explain why I am extremely outraged by this position. Every single major players - both from the Web companies and from suppliers caching solutions (BlueCoat, ThunderCache etc.) - to one degree or another violate RFC. And developers of

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 22.10.2016 18:43, gar...@comnet.uz пишет: > On 2016-10-22 16:05, Yuri Voinov wrote: >> Good explanations do not always help to get a good solution. A person >> needs no explanation and solution. >> >> So far I've seen

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 22.10.2016 16:55, gar...@comnet.uz пишет: > On 2016-10-22 13:53, Rui Lopes wrote: >> Hello, >> >> I'm trying to receive a cached version of >> googlechromestandaloneenterprise64.msi with: >> >> refresh_pattern

Re: [squid-users] Caching Google Chrome googlechromestandaloneenterprise64.msi

2016-10-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Try to use store-ID. Your URL seems dynamic. So, Squid never can cache it. Don't forget - Google, like many other web companies, actively counteracts caching. It is likely that you even Store ID will not help. 22.10.2016 14:53, Rui Lopes пишет:

Re: [squid-users] Caching http google deb files

2016-10-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 But I think it will be quite sufficient to bring back one of the options HTTP violations, namely - "Ignore cache-control". That's all. The rest we do ourselves. 22.10.2016 1:28, Yuri Voinov пишет: > > This is inappropriate. Just

Re: [squid-users] Caching http google deb files

2016-10-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This is inappropriate. Just all we are need that to make the option "F*ck the RFC and f*ck anyone who opposes caching" in the SQUID. 22.10.2016 1:07, Eliezer Croitoru пишет: > Instead of modifying the code, would you consider to use an ICAP

Re: [squid-users] Squid 2.7 to Squid 3.5

2016-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You have in the cryochamber, apparently, there was no internet :) :) It's not been :) 17.10.2016 4:17, Yuri Voinov пишет: > > In _your_ environment :) All world uses DNS caches ;) > > > 17.10.2016 3:07, reinerotto пишет: >

Re: [squid-users] Squid 2.7 to Squid 3.5

2016-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Come on! You think so?! :) 17.10.2016 3:02, reinerotto пишет: > Off topic, but anyway: >> Not a word, man. 10 years in IT - eternity :)< > Not true. > 40yrs ago we already did interrupt driven programming or 20 yrs ago online > apps for mobile

Re: [squid-users] Squid 2.7 to Squid 3.5

2016-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 16.10.2016 19:20, Johnny Lam пишет: > Dear All, > > I've encountered a issue during upgrade from 2.7 to 3.5, please find my config below. Seems everything changed in version 3.5. Not a word, man. 10 years in IT - eternity :) You'd still awake

Re: [squid-users] TCP_MISS/304 question

2016-10-14 Thread Yuri Voinov
0.2016 18:36, Yuri Voinov пишет: > > > > 14.10.2016 18:30, Amos Jeffries пишет: > > On 15/10/2016 12:34 a.m., Yuri Voinov wrote: > >> > >> A bit more details. > >> > >> This is 4 transactions in chronological order. Two from wget -S and two >

Re: [squid-users] TCP_MISS/304 question

2016-10-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.10.2016 18:30, Amos Jeffries пишет: > On 15/10/2016 12:34 a.m., Yuri Voinov wrote: >> >> A bit more details. >> >> This is 4 transactions in chronological order. Two from wget -S and two >> from sam

Re: [squid-users] TCP_MISS/304 question

2016-10-14 Thread Yuri Voinov
object has no headers preventing caching. Is it bug or feature? Because of, when site goes under HTTPS, it will has lower hit with the same content. It seems wrong. Note: This is news site. There is no private headers or any other cache-preventing headers. 14.10.2016 15:57, Yuri Voinov пише

Re: [squid-users] TCP_MISS/304 question

2016-10-14 Thread Yuri Voinov
in access.log, and this is wrong. It seems like bug. 14.10.2016 3:44, Yuri Voinov пишет: > > > > 14.10.2016 2:48, Alex Rousskov пишет: > > On 10/13/2016 01:44 PM, Yuri Voinov wrote: > > >> However, this is nothing more than word games, Alex. > > > ... unless the d

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.10.2016 2:48, Alex Rousskov пишет: > On 10/13/2016 01:44 PM, Yuri Voinov wrote: > >> However, this is nothing more than word games, Alex. > > ... unless the definition of a hit affects your billing or your > in

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.10.2016 1:28, Alex Rousskov пишет: > On 10/13/2016 12:46 PM, Yuri Voinov wrote: >> >> >> 14.10.2016 0:28, Alex Rousskov пишет: >>> On 10/13/2016 11:52 AM, Yuri Voinov wrote: >>>> When we seen ??

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.10.2016 0:28, Alex Rousskov пишет: > On 10/13/2016 11:52 AM, Yuri Voinov wrote: >> When we seen ??/304 with only headers - most probably content behind >> proxy already and this is CLIENT_IMS_HIT observed. >> >&g

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 13.10.2016 21:02, Yuri Voinov пишет: > > > > 13.10.2016 20:09, Amos Jeffries пишет: > > On 14/10/2016 2:46 a.m., Yuri Voinov wrote: > >> > >> > >> > >> 13.10.2016 19:44, Yuri Voinov пишет

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
of this event as a TCP_MISS seems incorrect and, consequently, leads to errors in accounting/billing. That, in turn, can lead to a loss of money. So, nice to have functionality for correct handling this cases. 13.10.2016 20:09, Amos Jeffries пишет: > On 14/10/2016 2:46 a.m., Yuri Voinov wr

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 13.10.2016 20:09, Amos Jeffries пишет: > On 14/10/2016 2:46 a.m., Yuri Voinov wrote: >> >> >> >> 13.10.2016 19:44, Yuri Voinov пишет: >> >> >> >>> 13.10.2016 19:41, Amos Jeffries

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 13.10.2016 19:44, Yuri Voinov пишет: > > > > 13.10.2016 19:41, Amos Jeffries пишет: > > On 14/10/2016 1:38 a.m., Yuri Voinov wrote: > >> > >> -BEGIN PGP SIGNED MESSAGE- > >> Hash: SHA256 >

Re: [squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 13.10.2016 19:41, Amos Jeffries пишет: > On 14/10/2016 1:38 a.m., Yuri Voinov wrote: >> >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA256 >> >> Hi gents. >> >> I have very stupid

[squid-users] TCP_MISS/304 question

2016-10-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi gents. I have very stupid question. Look at this access.log entry: 1476236018.506 85 192.168.100.103 TCP_MISS/304 354 GET https://www.gazeta.ru/nm2015/gzt/img/logo_footer.png - HIER_DIRECT/81.19.72.2 - I'm see this:

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This is what Squid has to be. Do not ask me to share configuration - it is not a magic configuration. This is something else. Custom code, custom config, custom setup. Train better! Hard luck! 09.10.2016 5:14, Yuri Voinov пишет: > > (Wh

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 (When you can just - you come and boast) 09.10.2016 5:08, Yuri Voinov пишет: > > But you can continue to assume that the hit - a measure of the efficiency of the cache :) > > > 09.10.2016 4:44, Yuri Voinov пишет: > > >

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 But you can continue to assume that the hit - a measure of the efficiency of the cache :) 09.10.2016 4:44, Yuri Voinov пишет: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Those who understand - have rushed to they mo

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Those who understand - have rushed to they monitor :) PS. HIT is about nothing. Only BYTE HIT matters. 09.10.2016 4:39, Yuri Voinov пишет: > > Blue line :) Colorblind go to the optometrist :) > > > 09.10.2016 4:11, reinerotto пише

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Blue line :) Colorblind go to the optometrist :) 09.10.2016 4:11, reinerotto пишет: > You mean the 10% ? No problem. > > > > -- > View this message in context:

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I mean BYTE HIT :) If you have eyes :) 09.10.2016 4:11, reinerotto пишет: > You mean the 10% ? No problem. > > > > -- > View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Your-real-byte-hit-tp4680014p4680016.html >

Re: [squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This is simple interception/forwarding proxy :) 09.10.2016 2:32, Yuri Voinov пишет: > > Can your achieve this? > > https://i1.someimage.com/ce1txmo.png > > At the week-end! ;) > > -BEGIN PGP SIGNATUR

[squid-users] Your real byte hit

2016-10-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Can your achieve this? https://i1.someimage.com/ce1txmo.png At the week-end! ;) -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJX+VfwAAoJENNXIZxhPexG7/sIALJe0URPi0iCu2ZFycJmFn2V

Re: [squid-users] Problem with Squid3 Caches

2016-10-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Show config. 04.10.2016 0:55, Jason Alexander пишет: > Greetings - > > I’m trying to install squid on an Ubuntu workstation in a VM. I install squid but unable to initialize caches. I get the following error: > > Initializing the Squid cache

Re: [squid-users] FW: squid tproxy ssl-bump and Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-09-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 30.09.2016 17:36, Vieri пишет: > Hi, > > - Original Message - >> From: Amos Jeffries >> >> Squid mimics the client details when contacting the server. So you would > >> get the same problem (though maybe different

Re: [squid-users] cache_peer name gone from logs after upgrade to 3.5

2016-09-28 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It's tragedy, man. But 3.1 is too antique against 3.5 to remain unchanged. Also, do not expect good documentation from open source - you can always read sources yourself and know what's changed. Too sad. But this it. WBR, Yuri 28.09.2016

Re: [squid-users] The Squid “Persona”- Squid 3.5.21+4.0.14 Release

2016-09-28 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It seems to me more important than the quality of the product debugging instead invention mascot for it. 28.09.2016 17:43, Antony Stone пишет: > On Wednesday 28 September 2016 at 13:39:04, Eliezer Croitoru wrote: > >> Take a look at the page

Re: [squid-users] Question: Is it possible adaptation_service_chain from services with different access lists?

2016-09-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 27.09.2016 0:08, Alex Rousskov пишет: > On 09/26/2016 11:32 AM, Yuri Voinov wrote: >> 26.09.2016 23:16, Alex Rousskov пишет: >>> On 09/26/2016 10:42 AM, Yuri Voinov wrote: >>>> How can I make a chain of adapta

Re: [squid-users] Question: Is it possible adaptation_service_chain from services with different access lists?

2016-09-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 26.09.2016 23:16, Alex Rousskov пишет: > On 09/26/2016 10:42 AM, Yuri Voinov wrote: >> 26.09.2016 22:25, Alex Rousskov пишет: >>> I assume you meant that Squid should >>> not send service B non-text messages at all. &

Re: [squid-users] Question: Is it possible adaptation_service_chain from services with different access lists?

2016-09-26 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 26.09.2016 22:25, Alex Rousskov пишет: > On 09/26/2016 09:44 AM, Yuri Voinov wrote: > >> I have to adaptation service A, which has the access list "All". >> >> And B adaptation service that has access list "

Re: [squid-users] libevent

2016-09-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 23.09.2016 3:33, reinerotto пишет: >> You are too few in number to provide something decent enough, and not from > the last century.< > The smaller the development team, the more efficient it is. Highly qualified > staff assumed. Oh, yes, we've

Re: [squid-users] libevent

2016-09-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Joined. 22.09.2016 2:46, joe пишет: > is there a support for libevent in squid ??? > > > > -- > View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/libevent-tp4679637.html > Sent from the Squid - Users mailing list

Re: [squid-users] SQUID 3.4.8 on RPi 3

2016-09-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 IDK. I'm not Linux fanboy. 17.09.2016 19:02, VB пишет: > Hi Yuri > > which version do you suggest for Raspian Jesse? > Is it OK the 3.5.21? Probably. At least 3.5.20. > > thx > Vincenzo > > > > -- > View this message in context:

Re: [squid-users] SQUID 3.4.8 on RPi 3

2016-09-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 17.09.2016 12:38, VB пишет: > Hi Yuri > > thx a lot for your links.. following the first one, what I did: > > 1. Create and sign the .pem certificate > > 2. Update my squid.conf with: > https_port 3130 ssl-bump \ > cert=/etc/squid/ssl/myCA.pem \

Re: [squid-users] SQUID 3.4.8 on RPi 3

2016-09-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 17.09.2016 12:38, VB пишет: > Hi Yuri > > thx a lot for your links.. following the first one, what I did: > > 1. Create and sign the .pem certificate > > 2. Update my squid.conf with: > https_port 3130 ssl-bump \ > cert=/etc/squid/ssl/myCA.pem \

Re: [squid-users] Preserving Squid.conf when upgrading

2016-09-15 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 15.09.2016 20:28, Rafael Akchurin пишет: > > Hello Patrick, > > > > Sorry I do not know. I guess MSI will just remove it. > > So back it up somewhere before uninstall/install. > This is easy and obvious procedure ;) > > > > Best regards, > >

Re: [squid-users] Web Whatsapp, Dropbox... problem

2016-09-13 Thread Yuri Voinov
128 TCP_TUNNEL/200 3639 CONNECT w7.web.whatsapp.com:443 <http://w7.web.whatsapp.com:443> - HIER_DIRECT/169.55.69.156 <http://169.55.69.156> - > > > Chico Venancio > > 2016-09-13 17:40 GMT-03:00 Yuri Voinov <yvoi...@gmail.com <mailto:yvoi...@gmail.com>>

Re: [squid-users] Web Whatsapp, Dropbox... problem

2016-09-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Wait. Does anybody see WebSockets connections to web.whatsapp.com? 14.09.2016 2:38, Chico Venancio пишет: > > We need more of access log. > There is at least connect attempts at w1.web.whatsapp.com not shown. > >

<    1   2   3   4   5   6   7   8   9   10   >