Re: [squid-users] [EXTERNAL] FreeBSD 12 thousands connections

2023-03-20 Thread Periko Support
This will be MITM Transparent Proxy.
No User Auth.
Thanks for your help.

On Mon, Mar 20, 2023 at 11:08 AM Joey Officer  wrote:
>
> Will the users require authentication?  Depending on what authentication is 
> active, you'd probably want to increase the minimum amount of auth helpers to 
> satisfy the requests.
>
> That said, you really haven't given enough information about your specific 
> use.
>
> -Original Message-
> From: squid-users  On Behalf Of 
> Periko Support
> Sent: Monday, March 20, 2023 12:38 PM
> To: squid-users@lists.squid-cache.org
> Subject: [EXTERNAL][squid-users] FreeBSD 12 thousands connections
>
> CAUTION: This email originated from outside of the organization. Do not click 
> links or open attachments unless you recognize the sender and know the 
> content is safe.
>
> Hello guys.
>
> I 'm going to run a squid-proxy for around 3000 users simultaneously.
>
> The server is a Supermicro Intel 8 cores with 64GB RAM, SSD disk, I will not 
> enable caching.
>
> The switches are 1GB HP.
>
> Any recommendations for this deployment that could help tuning my FreeBSD 
> 12.3 box to take into consideration?
>
> Thanks all for your time!!!
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] FreeBSD 12 thousands connections

2023-03-20 Thread Periko Support
Yes, the latest FreeBSD 12.x.

On Mon, Mar 20, 2023 at 11:02 AM Luciano Mannucci
 wrote:
>
> On Mon, 20 Mar 2023 10:38:02 -0700
> Periko Support  wrote:
>
> > Any recommendations for this deployment that could help tuning my
> > FreeBSD 12.3 box to take into consideration?
> Well, 12.3 is EOL.
> You should consider upgrading at least to 12.4...
>
> Luciano.
> --
>  /"\ /Via A. Salaino, 7 - 20144 Milano (Italy)
>  \ /  ASCII RIBBON CAMPAIGN / PHONE : +39 02485781 FAX: +39 0248028247
>   X   AGAINST HTML MAIL/  E-MAIL: posthams...@sublink.sublink.org
>  / \  AND POSTINGS/   WWW: http://www.lesassaie.IT/
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] FreeBSD 12 thousands connections

2023-03-20 Thread Periko Support
Hello guys.

I 'm going to run a squid-proxy for around 3000 users simultaneously.

The server is a Supermicro Intel 8 cores with 64GB RAM, SSD disk, I
will not enable caching.

The switches are 1GB HP.

Any recommendations for this deployment that could help tuning my
FreeBSD 12.3 box to take into consideration?

Thanks all for your time!!!
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] Issues with blacklist and a domain.

2023-01-16 Thread Periko Support
I got the same question, why is doing that...

This is the blacklist setting:

acl blacklist dstdom_regex -i "/var/squid/acl/blacklist.acl"

http_access deny blacklist

Regards!!!

On Mon, Jan 16, 2023 at 1:47 PM  wrote:
>
> Hey,
>
> I am not sure how exactly how the domain:
> dof.gob.mx
>
> is being blocked by the:
> .me
>
> Domain suffix?
> What exactly your squid.conf is doing? (remove private info).
>
> Eliezer
>
> 
> Eliezer Croitoru
> NgTech, Tech Support
> Mobile: +972-5-28704261
> Email: ngtech1...@gmail.com
> Web: https://ngtech.co.il/
> My-Tube: https://tube.ngtech.co.il/
>
> -Original Message-
> From: squid-users  On Behalf Of 
> Periko Support
> Sent: Monday, 16 January 2023 20:30
> To: squid-users@lists.squid-cache.org
> Subject: [squid-users] Issues with blacklist and a domain.
>
> Hello people.
>
> I running squid 5.7, I got an issue that would like to know if I could fix 
> this.
> In my blacklist I got this entries:
>
> .party
> .porn
> .xxx
> .vip
> .me
>
> Which I have found on adult sites that I want to block.
>
> Now, the problem is the ".me" because I found that it is blocking a
> government domain on my country.
>
> "dof.gob.mx"
>
> If I remove ".me" from my blacklist I can surf on my government site.
>
> Then what I see is that once squid detects ".m" it will block any domain.
>
> If I add the url on the whitelist won't fix the issue.
>
> Any recommendations?
>
> Regards!!!
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
>
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] Issues with blacklist and a domain.

2023-01-16 Thread Periko Support
Hello people.

I running squid 5.7, I got an issue that would like to know if I could fix this.
In my blacklist I got this entries:

.party
.porn
.xxx
.vip
.me

Which I have found on adult sites that I want to block.

Now, the problem is the ".me" because I found that it is blocking a
government domain on my country.

"dof.gob.mx"

If I remove ".me" from my blacklist I can surf on my government site.

Then what I see is that once squid detects ".m" it will block any domain.

If I add the url on the whitelist won't fix the issue.

Any recommendations?

Regards!!!
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] Squid v4.45

2021-08-29 Thread Periko Support
Hello guys.

I'm worrying with all the info u give me guys, tracking the sites
win10 use to query and confirm it has connection.

Is a little annoying when users call u and complain about that, even
if they have internet access.

Part of IT life.

Thanks all for your input!!!

On Sun, Aug 22, 2021 at 11:55 PM L.P.H. van Belle  wrote:
>
> In your windows config.
> Remove the ip adres from the gateway and configure your proxy settings.
> Without proxy and gateway no internet.
>
> Or setup SSL proxy
> Add something like this in your firewall and you catch all.
>
> # Redirect HTTP on eth0 from LAN_CIDR to locally installed Squid instance 
> using REDIRECT for intercept mode
> iptables -t mangle -A PREROUTING -i eth0 -s 192.168.0.0/24 -p tcp --dport 80 
> -j REDIRECT --to-port 6080 -m comment --comment "Squid-Intercept 80->6080"
>
> # Redirect HTTPS on eth0 from CIDR to locally installed Squid instance using 
> REDIRECT for intercept mode
> -A PREROUTING -i eth0 -s 192.168.0.0/24 -p tcp --dport 443 -j REDIRECT 
> --to-port 6433 -m comment --comment "Squid-Intercept 443->6433"
>
> And read :
> https://wiki.squid-cache.org/KnowledgeBase/Block%20QUIC%20protocol
>
>
> >The NIC status simply says that *somehow* the Internet is available.
> No, windows 10 does a DNS querie to an MS server, block that and and you see 
> "no internet"
> Even if you have internet.
>
> Maybe PiHole is something for you that does most of what you want.
>
>
> Greetz,
>
> Louis
>
>
> > -Oorspronkelijk bericht-
> > Van: squid-users
> > [mailto:squid-users-boun...@lists.squid-cache.org] Namens
> > Periko Support
> > Verzonden: maandag 23 augustus 2021 7:55
> > Aan: squid-users@lists.squid-cache.org
> > Onderwerp: Re: [squid-users] Squid v4.45
> >
> > On Thu, Aug 19, 2021 at 7:40 PM Amos Jeffries
> >  wrote:
> > >
> > >
> > > FYI, there is no such version as Squid 4.45.
> >
> > Amos sorry, is 4.15 my mistake.
> > >
> > > What is the output when you run "squid -v" ?
> > >
> >  squid -v
> > Squid Cache: Version 4.15
> > Service Name: squid
> >
> > This binary uses OpenSSL 1.1.1k-freebsd  25 Mar 2021. For legal
> > restrictions on distribution see
> > https://www.openssl.org/source/license.html
> >
> > configure options:  '--with-default-user=squid'
> > '--bindir=/usr/local/sbin' '--sbindir=/usr/local/sbin'
> > '--datadir=/usr/local/etc/squid'
> > '--libexecdir=/usr/local/libexec/squid' '--localstatedir=/var'
> > '--sysconfdir=/usr/local/etc/squid' '--with-logdir=/var/log/squid'
> > '--with-pidfile=/var/run/squid/squid.pid'
> > '--with-swapdir=/var/squid/cache' '--without-gnutls'
> > '--with-included-ltdl' '--enable-auth' '--enable-zph-qos'
> > '--enable-build-info' '--enable-loadable-modules'
> > '--enable-removal-policies=lru heap' '--disable-epoll'
> > '--disable-linux-netfilter' '--disable-linux-tproxy'
> > '--disable-translation' '--disable-arch-native'
> > '--disable-strict-error-checking' '--enable-eui'
> > '--enable-cache-digests' '--enable-delay-pools' '--disable-ecap'
> > '--disable-esi' '--enable-follow-x-forwarded-for'
> > '--with-mit-krb5=/usr/local' 'CFLAGS=-I/usr/local/include -O2 -pipe
> > -I/usr/local/include -I/usr/local/include -fstack-protector-strong
> > -DLDAP_DEPRECATED -fno-strict-aliasing ' 'LDFLAGS=-L/usr/local/lib
> > -L/usr/local/lib -L/usr/local/lib -pthread -L/usr/local/lib
> > -lpcreposix -lpcre -Wl,-rpath,/usr/local/lib:/usr/lib
> > -fstack-protector-strong ' 'LIBS=-lkrb5 -lgssapi_krb5 '
> > 'KRB5CONFIG=/usr/local/bin/krb5-config'
> > 'krb5_config=/usr/local/bin/krb5-config' '--enable-htcp'
> > '--enable-icap-client' '--enable-icmp' '--enable-ident-lookups'
> > '--enable-ipv6' '--enable-kqueue' '--with-large-files'
> > '--enable-http-violations' '--without-nettle' '--enable-snmp'
> > '--enable-ssl' '--with-openssl=/usr'
> > '--enable-security-cert-generators=file'
> > 'LIBOPENSSL_CFLAGS=-I/usr/include' 'LIBOPENSSL_LIBS=-lcrypto -lssl'
> > '--enable-ssl-crtd' '--disable-stacktraces'
> > '--disable-ipf-transparent' '--disable-ipfw-transparent'
> > '--enable-pf-transparent' '--with-nat-devpf' '--disable-forw-via-db'
> > '--enable-wccp' '--enable-wccpv2' '--enable-auth-basic=LDAP SASL DB
> > SMB_LM NCSA PAM POP3 RADIUS fake getpwnam NIS'
> > '--enable-auth-digest=eDirectory LDAP file'
> > '--enable-external-acl-helpers=LDAP_group eDirectory_userip
> > file_userip unix_group delayer kerberos_ldap_group'
> > '--enable-auth-negotiate=kerberos wrapper' '--enable-auth

Re: [squid-users] Squid v4.45

2021-08-22 Thread Periko Support
On Thu, Aug 19, 2021 at 7:40 PM Amos Jeffries  wrote:
>
>
> FYI, there is no such version as Squid 4.45.

Amos sorry, is 4.15 my mistake.
>
> What is the output when you run "squid -v" ?
>
 squid -v
Squid Cache: Version 4.15
Service Name: squid

This binary uses OpenSSL 1.1.1k-freebsd  25 Mar 2021. For legal
restrictions on distribution see
https://www.openssl.org/source/license.html

configure options:  '--with-default-user=squid'
'--bindir=/usr/local/sbin' '--sbindir=/usr/local/sbin'
'--datadir=/usr/local/etc/squid'
'--libexecdir=/usr/local/libexec/squid' '--localstatedir=/var'
'--sysconfdir=/usr/local/etc/squid' '--with-logdir=/var/log/squid'
'--with-pidfile=/var/run/squid/squid.pid'
'--with-swapdir=/var/squid/cache' '--without-gnutls'
'--with-included-ltdl' '--enable-auth' '--enable-zph-qos'
'--enable-build-info' '--enable-loadable-modules'
'--enable-removal-policies=lru heap' '--disable-epoll'
'--disable-linux-netfilter' '--disable-linux-tproxy'
'--disable-translation' '--disable-arch-native'
'--disable-strict-error-checking' '--enable-eui'
'--enable-cache-digests' '--enable-delay-pools' '--disable-ecap'
'--disable-esi' '--enable-follow-x-forwarded-for'
'--with-mit-krb5=/usr/local' 'CFLAGS=-I/usr/local/include -O2 -pipe
-I/usr/local/include -I/usr/local/include -fstack-protector-strong
-DLDAP_DEPRECATED -fno-strict-aliasing ' 'LDFLAGS=-L/usr/local/lib
-L/usr/local/lib -L/usr/local/lib -pthread -L/usr/local/lib
-lpcreposix -lpcre -Wl,-rpath,/usr/local/lib:/usr/lib
-fstack-protector-strong ' 'LIBS=-lkrb5 -lgssapi_krb5 '
'KRB5CONFIG=/usr/local/bin/krb5-config'
'krb5_config=/usr/local/bin/krb5-config' '--enable-htcp'
'--enable-icap-client' '--enable-icmp' '--enable-ident-lookups'
'--enable-ipv6' '--enable-kqueue' '--with-large-files'
'--enable-http-violations' '--without-nettle' '--enable-snmp'
'--enable-ssl' '--with-openssl=/usr'
'--enable-security-cert-generators=file'
'LIBOPENSSL_CFLAGS=-I/usr/include' 'LIBOPENSSL_LIBS=-lcrypto -lssl'
'--enable-ssl-crtd' '--disable-stacktraces'
'--disable-ipf-transparent' '--disable-ipfw-transparent'
'--enable-pf-transparent' '--with-nat-devpf' '--disable-forw-via-db'
'--enable-wccp' '--enable-wccpv2' '--enable-auth-basic=LDAP SASL DB
SMB_LM NCSA PAM POP3 RADIUS fake getpwnam NIS'
'--enable-auth-digest=eDirectory LDAP file'
'--enable-external-acl-helpers=LDAP_group eDirectory_userip
file_userip unix_group delayer kerberos_ldap_group'
'--enable-auth-negotiate=kerberos wrapper' '--enable-auth-ntlm=fake
SMB_LM' '--enable-storeio=aufs diskd ufs'
'--enable-disk-io=DiskThreads DiskDaemon AIO Blocking IpcIo Mmapped'
'--enable-log-daemon-helpers=file DB'
'--enable-url-rewrite-helpers=fake LFS'
'--enable-storeid-rewrite-helpers=file'
'--enable-security-cert-validators=fake' '--prefix=/usr/local'
'--mandir=/usr/local/man' '--disable-silent-rules'
'--infodir=/usr/local/share/info/' '--build=amd64-portbld-freebsd12.2'
'build_alias=amd64-portbld-freebsd12.2' 'CC=cc'
'CPPFLAGS=-I/usr/local/include -I/usr/local/include' 'CXX=c++'
'CXXFLAGS=-O2 -pipe -I/usr/local/include -I/usr/local/include
-fstack-protector-strong -DLDAP_DEPRECATED -fno-strict-aliasing  '
'CPP=cpp' --enable-ltdl-convenience
> On 19/08/21 4:12 am, Periko Support wrote:
> > Hello guys.
> >
> > I have been searching the issue I have with windows 10 and the ugly
> > job he do to put the NIC "Internet access" and went we have squid
> > behind "no internet".
> >
>
> The NIC status simply says that *somehow* the Internet is available.
> that means DNS resolution, TCP connectivity, HTTP transactions and HTTPS
> transactions are all fully working and producing responses.

Windows 10 if for some reason cannot reach the internet will say "no internet".

I had sniff the communication and I just found thos 2 sites that looks
like windows use to check connectivity.

>
> Break any one and you will get "no internet". Even when the rest
> continue working fine. So it can tell you when some sort of failure
> occurs, but is not reliable when it claims success.
>
>
> Please be aware that using your Squid proxy properly is one way Windows
> can receive all those services and claim "Internet Access".
>
>
> > I have sniff logs and  I just found this sites went I turn on the computer:
> >
> > .msftconnecttest.com
> > .windows.com
> >
> > Some has win over this annoying thing with windows 10?
> >
> > No-Trans[parent Proxy WPAD.
> >
>
> Check that your firewall does not permit HTTP(S) connections directly
> from clients to the Internet.

I don't allow direct connection to the Internet, all 80/443 must cross
under squid.

> When;
>   * your network gateway firewall(s) block direct connections (other
> than from Squid) to HTTP(S), and
>   * your proxy logs show those Win10 connection URLs happening, an

[squid-users] Squid v4.45

2021-08-18 Thread Periko Support
Hello guys.

I have been searching the issue I have with windows 10 and the ugly
job he do to put the NIC "Internet access" and went we have squid
behind "no internet".

I have sniff logs and  I just found this sites went I turn on the computer:

.msftconnecttest.com
.windows.com

Some has win over this annoying thing with windows 10?

No-Trans[parent Proxy WPAD.

Regards!!!
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] Squid caching webpages now days?

2021-07-31 Thread Periko Support
Hello guys.

With today's ISP's speed increasing, does squid cache (caching web
pages) now days is a good option?

I have some customers that want to setup a cache server, but I have
doubts about how much traffic will be save, with most of the web sites
running under https.

I use squid+sg acl features.

But for me, caching  is not a bandwidth saving tool anymore.

Does caching still a good option with squid?

Regards!!!
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] Active Directory Integration?

2018-06-17 Thread Periko Support
Hi people.

If we need to integrate squid 3.5+ with a windows domain AD(2008+) and
authenticated users from the domain.

Linux(squid) need to be part of the domain?
Or we can just enable a common LDAP query to the AD server?

Thanks.
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] Reports in Squids

2018-04-11 Thread Periko Support
Check sarg.

2018-04-11 13:01 GMT-07:00 Informatico Neurodesarrollo
:
> Hi friends:
> I am use openSUSE Leap 42.3 as a proxy server.
> I am need send a report  monthly :
>
> * The first 10th sites with more access and the total amount of his
> traffics.
> * The first 10th users with more access  and the total amount of his
> traffics.
>
> * Download and Upload average of total traffic between this time:
>
> 7:00 to12:00
> 12:00   to17:00
> 17:00   to24:00
>
> Which  software I can  implement it?
>
> I hope that somebody can help me.
>
> My best regards.
>
>
> --
>
> Jesús Reyes Piedra
> Admin Red Neurodesarrollo,Cárdenas
> La caja decía:"Requiere windows 95 o superior"...
> Entonces instalé LINUX.
>
>
> --
> Este mensaje le ha llegado mediante el servicio de correo electronico que
> ofrece Infomed para respaldar el cumplimiento de las misiones del Sistema
> Nacional de Salud. La persona que envia este correo asume el compromiso de
> usar el servicio a tales fines y cumplir con las regulaciones establecidas
>
> Infomed: http://www.sld.cu/
>
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] Squid is very slow after moving to production environment

2018-04-09 Thread Periko Support
Try to add this setting:

dns_v4_first on

Latter check settings and see if there is no issue with the setting.

squid -k parse.

Then reload:

squid -k reconfigure

Test.


On Mon, Apr 9, 2018 at 1:05 PM, Antony Stone
 wrote:
> On Monday 09 April 2018 at 21:58:52, Roberto Carna wrote:
>
>> Dear Antony, both proxies are virtual machines in the same DMZthey
>> use the same DNS, the same firewall, the same Internet link, the same
>> IP but different MAC Address.
>
> So, what is different between "test" and "production"?
>
>
> Antony.
>
> --
> "Remember: the S in IoT stands for Security."
>
>  - Jan-Piet Mens
>
>Please reply to the list;
>  please *don't* CC me.
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] WIndows Server AD+Squid Integration: Query User Specs

2017-10-31 Thread Periko Support
Done, is working.
Thanks Yuri.

On Tue, Oct 31, 2017 at 1:36 PM, Periko Support
<pheriko.supp...@gmail.com> wrote:
> Testing teacher, let u know, thanks and hi-5...
>
> On Tue, Oct 31, 2017 at 1:30 PM, Yuri <yvoi...@gmail.com> wrote:
>> (facepalm) Don't use superuser rights (or equivalent) - never - if you
>> really won't require it.
>>
>> Yes, any user who has permissions to read access to AD.
>>
>> 01.11.2017 2:28, Periko Support пишет:
>>> Don't hate me Yuri, this is why I ask first.
>>> Group Users, them I can use any user for my squid settings?
>>> Thanks...don't hate me please..
>>>
>>> On Tue, Oct 31, 2017 at 1:19 PM, Yuri <yvoi...@gmail.com> wrote:
>>>>
>>>> 01.11.2017 2:16, Periko Support пишет:
>>>>> HI Guys.
>>>>>
>>>>> I want to integrate my authtenticacion vs a Windows Server 2012 R2 AD,
>>>>> my doubt is related to the user I have to use from the AD.
>>>>>
>>>>> What type of user can I use for squid config to query our AD?
>>>>>
>>>>> Must be from the Admin group or must a specific role?
>>>> The principle of the least privilege. What kind of devil is a member of
>>>> the "Administrators" group?!
>>>>
>>>> At max member of group "Users".
>>>>> Squid 3.5.x, thanks guys for your time!!!
>>>>> ___
>>>>> squid-users mailing list
>>>>> squid-users@lists.squid-cache.org
>>>>> http://lists.squid-cache.org/listinfo/squid-users
>>>> --
>>>> **
>>>> * C++: Bug to the future *
>>>> **
>>>>
>>>>
>>>> ___
>>>> squid-users mailing list
>>>> squid-users@lists.squid-cache.org
>>>> http://lists.squid-cache.org/listinfo/squid-users
>>>>
>>> ___
>>> squid-users mailing list
>>> squid-users@lists.squid-cache.org
>>> http://lists.squid-cache.org/listinfo/squid-users
>>
>> --
>> **
>> * C++: Bug to the future *
>> **
>>
>>
>> ___
>> squid-users mailing list
>> squid-users@lists.squid-cache.org
>> http://lists.squid-cache.org/listinfo/squid-users
>>
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] WIndows Server AD+Squid Integration: Query User Specs

2017-10-31 Thread Periko Support
Testing teacher, let u know, thanks and hi-5...

On Tue, Oct 31, 2017 at 1:30 PM, Yuri <yvoi...@gmail.com> wrote:
> (facepalm) Don't use superuser rights (or equivalent) - never - if you
> really won't require it.
>
> Yes, any user who has permissions to read access to AD.
>
> 01.11.2017 2:28, Periko Support пишет:
>> Don't hate me Yuri, this is why I ask first.
>> Group Users, them I can use any user for my squid settings?
>> Thanks...don't hate me please..
>>
>> On Tue, Oct 31, 2017 at 1:19 PM, Yuri <yvoi...@gmail.com> wrote:
>>>
>>> 01.11.2017 2:16, Periko Support пишет:
>>>> HI Guys.
>>>>
>>>> I want to integrate my authtenticacion vs a Windows Server 2012 R2 AD,
>>>> my doubt is related to the user I have to use from the AD.
>>>>
>>>> What type of user can I use for squid config to query our AD?
>>>>
>>>> Must be from the Admin group or must a specific role?
>>> The principle of the least privilege. What kind of devil is a member of
>>> the "Administrators" group?!
>>>
>>> At max member of group "Users".
>>>> Squid 3.5.x, thanks guys for your time!!!
>>>> ___
>>>> squid-users mailing list
>>>> squid-users@lists.squid-cache.org
>>>> http://lists.squid-cache.org/listinfo/squid-users
>>> --
>>> **
>>> * C++: Bug to the future *
>>> **
>>>
>>>
>>> ___
>>> squid-users mailing list
>>> squid-users@lists.squid-cache.org
>>> http://lists.squid-cache.org/listinfo/squid-users
>>>
>> ___
>> squid-users mailing list
>> squid-users@lists.squid-cache.org
>> http://lists.squid-cache.org/listinfo/squid-users
>
> --
> **
> * C++: Bug to the future *
> **
>
>
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
>
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] WIndows Server AD+Squid Integration: Query User Specs

2017-10-31 Thread Periko Support
Don't hate me Yuri, this is why I ask first.
Group Users, them I can use any user for my squid settings?
Thanks...don't hate me please..

On Tue, Oct 31, 2017 at 1:19 PM, Yuri <yvoi...@gmail.com> wrote:
>
>
> 01.11.2017 2:16, Periko Support пишет:
>> HI Guys.
>>
>> I want to integrate my authtenticacion vs a Windows Server 2012 R2 AD,
>> my doubt is related to the user I have to use from the AD.
>>
>> What type of user can I use for squid config to query our AD?
>>
>> Must be from the Admin group or must a specific role?
> The principle of the least privilege. What kind of devil is a member of
> the "Administrators" group?!
>
> At max member of group "Users".
>>
>> Squid 3.5.x, thanks guys for your time!!!
>> ___
>> squid-users mailing list
>> squid-users@lists.squid-cache.org
>> http://lists.squid-cache.org/listinfo/squid-users
>
> --
> **
> * C++: Bug to the future *
> **
>
>
> ___
> squid-users mailing list
> squid-users@lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
>
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] WIndows Server AD+Squid Integration: Query User Specs

2017-10-31 Thread Periko Support
HI Guys.

I want to integrate my authtenticacion vs a Windows Server 2012 R2 AD,
my doubt is related to the user I have to use from the AD.

What type of user can I use for squid config to query our AD?

Must be from the Admin group or must a specific role?

Squid 3.5.x, thanks guys for your time!!!
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


[squid-users] Pre-Built Binary Packages: squid_ldap_auth: (2) No such file or directory

2016-12-21 Thread Periko Support
Hi.

We are testing squid 3.5 from:

http://wiki.squid-cache.org/KnowledgeBase/CentOS#Squid-3.5

But we got some issue, our server requieres auth to a local LDAP server.

But looks like it was build without this module.

Can some one confirm this?

squid -z
2016/12/21 12:40:00| ERROR: Authentication helper program
/usr/lib64/squid/squid_ldap_auth: (2) No such file or directory
FATAL: Authentication helper program /usr/lib64/squid/squid_ldap_auth:
(2) No such file or directory
Squid Cache (Version 3.5.20): Terminated abnormally.
CPU Usage: 0.006 seconds = 0.005 user + 0.001 sys
Maximum Resident Size: 30512 KB
Page faults with physical i/o: 0

Centos 6.x x64, thanks.
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users