Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-31 Thread Nick Cairncross
Well, for me it is not so much of a problem since I upstream to an ISP with content/malware protection etc, but it would be nice to be able report on all users of every method. Perhaps someone could enlighten this mail? My relevant squid.conf is as follows (I have the ACLs defined obviously...)

Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-30 Thread Tom Tux
Hi Nick Thank you for this explanation. I think, you're right. Could this eventually be a security-problem, to allow unauthenticated https-traffic with http_access allow CONNECT SSL_ports? Might be yes, might be no. Is this behaviour part of a fact with SSL/HTTPS or could this be eventually

Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-28 Thread Nick Cairncross
Tom, Just to say what I think (since you have almost the same setup as me I think): you will always get that 407 at the moment. Squid requires an authenticated user before allowing the page but you can't authenticate every method (at least that is what I have found) in my setup. Regardless

[squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-27 Thread Tom Tux
Hi For every HTTPS-Site I have the following tcp_denied/407-entry in the access.log: 282895826.492 1 xx.xx.xx.xx TCP_DENIED/407 3720 CONNECT mail.google.com:443 - NONE/- text/html 1282896033.320 1 xx.xx.xx.xx TCP_DENIED/407 3744 CONNECT secure-www.novell.com:443 - NONE/- text/html The

Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-27 Thread Amos Jeffries
Tom Tux wrote: Hi For every HTTPS-Site I have the following tcp_denied/407-entry in the access.log: 282895826.492 1 xx.xx.xx.xx TCP_DENIED/407 3720 CONNECT mail.google.com:443 - NONE/- text/html 1282896033.320 1 xx.xx.xx.xx TCP_DENIED/407 3744 CONNECT secure-www.novell.com:443 -

Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-27 Thread Tom Tux
Hi Amos Thanks a lot for this informations. Is it usual/normal, that all https-requests have this error? 1282899033.246 0 xx.xx.xx.xx TCP_DENIED/407 3720 CONNECT mail.google.com:443 - NONE/- text/html As I already mentioned: The sites, which are denied in the access.log, are normal

Re: [squid-users] TCP_DENIED/407 with SSL-Sites, but the site is accessible...

2010-08-27 Thread Amos Jeffries
Tom Tux wrote: Hi Amos Thanks a lot for this informations. Is it usual/normal, that all https-requests have this error? 100% depends on your configuration file. 1282899033.246 0 xx.xx.xx.xx TCP_DENIED/407 3720 CONNECT mail.google.com:443 - NONE/- text/html As I already mentioned: The