[squid-users] R: [squid-users] Squid 3 - Cento 6 - don't display flash player

2011-07-28 Thread Franco, Battista
Hello
Someone can help me regarding this issue?


-Messaggio originale-
Da: Franco, Battista [mailto:battista.fra...@saint-gobain.com] 
Inviato: lunedì 25 luglio 2011 12:20
A: Amos Jeffries; squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

Sorry I didn't see that there are error messagges in access.log (see below)

1311589001.112  0 10.239.57.89 TCP_DENIED/407 4459 GET 
http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/ - NONE/- text/html
1311589001.116  1 10.239.57.89 TCP_DENIED/407 4723 GET 
http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/ - NONE/- text/html


-Messaggio originale-
Da: Franco, Battista [mailto:battista.fra...@saint-gobain.com] 
Inviato: lunedì 25 luglio 2011 09:15
A: Amos Jeffries; squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

Hello
Now with nonhierarchical_direct OFF directive banner and other animation works 
fine but flash video don't work.
i.e. I tried to see the videos on page :

http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/

and the videos don't start.
In access.log I didn't see error (see below)

1311577629.238336 10.239.57.82 TCP_MISS/301 588 GET 
http://tv.quattroruote.it/asset/css/commenti.css - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577629.432192 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset/css/commenti.css/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.027581 10.239.57.82 TCP_MISS/200 6281 GET 
http://adlev.neodatagroup.com/ad/edidomus.jsp? - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.273  0 10.239.57.82 TCP_IMS_HIT/304 433 GET 
http://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js - NONE/- 
text/javascript
1311577630.300 78 10.239.57.82 TCP_MISS/301 600 GET 
http://tv.quattroruote.it/asset/css/images/fieldbg.gif - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.379 77 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset/css/images/fieldbg.gif/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.580322 10.239.57.82 TCP_MISS/200 2328 GET 
http://www.facebook.com/plugins/like.php? - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.587117 10.239.57.82 TCP_MISS/200 475 GET 
http://secure-it.imrworldwide.com/cgi-bin/j? - 
DEFAULT_PARENT/proxy-parent.domain.net text/javascript
1311577630.686339 10.239.57.82 TCP_MISS/200 472 GET 
http://www.google-analytics.com/__utm.gif? - 
DEFAULT_PARENT/proxy-parent.domain.net image/gif
1311577630.721 68 10.239.57.82 TCP_MISS/200 468 GET 
http://secure-it.imrworldwide.com/cgi-bin/m? - 
DEFAULT_PARENT/proxy-parent.domain.net image/gif
1311577630.803 78 10.239.57.82 TCP_MISS/301 646 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-bg_flat_0_ff_40x100.png - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.860113 10.239.57.82 TCP_MISS/301 640 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-icons_33_256x240.png - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.913108 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-bg_flat_0_ff_40x100.png/ 
- DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.957 84 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-icons_33_256x240.png/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577632.043554 10.239.57.82 TCP_MISS/200 4528 GET 
http://cms.quattroruote.tv/webservices/frontend.asmx/GetVideoByChannelHome? - 
DEFAULT_PARENT/proxy-parent.domain.net application/json
1311577760.827657 10.239.57.89 TCP_MISS/200 352 POST 
http://85.94.205.240/open/1 - DEFAULT_PARENT/proxy-parent.domain.net 
application/x-fcs
1311577761.815639 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/send/20WmTt9BUoguy6-Z/0 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577762.530656 10.239.57.89 TCP_MISS/403 1943 POST 
http://85.94.205.240/idle/20WmTt9BUoguy6-Z/1 - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577763.184605 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/close/20WmTt9BUoguy6-Z/2 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577824.119521 10.239.57.89 TCP_MISS/200 352 POST 
http://85.94.205.240/open/1 - DEFAULT_PARENT/proxy-parent.domain.net 
application/x-fcs
1311577824.682241 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/send/2kWmTt9BUogDy6-Z/0 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577825.099361 10.239.57.89 TCP_MISS/403 1943 POST 
http://85.94.205.240/idle/2kWmTt9BUogDy6-Z/1 - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577825.660383 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/close/2kWmTt9BUogDy6-Z/2 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs


-Messaggio

[squid-users] R: [squid-users] R: [squid-users] Squid 3 - Cento 6 - don't display flash player

2011-07-25 Thread Franco, Battista
Hello
On the server there isn't firewall rules I disabled them.
On my corporate lan there is a firewall and the only way to surfing is
to use the parent proxy (so I used the cache_peer directive).
But in access.log I see that all request with DIRECT/x.x.x.x are KO and
the requeste with DEFAUL_PARENT/Proxy_Parent was OK.
The question is :  why are there DIRECT/x.x.x.x request instead of
DEFAULT_PARENT/Proxy_Parent?



-Messaggio originale-
Da: Amos Jeffries [mailto:squ...@treenet.co.nz] 
Inviato: sabato 23 luglio 2011 06:05
A: squid-users@squid-cache.org
Oggetto: Re: [squid-users] R: [squid-users] Squid 3 - Cento 6 - don't
display flash player

On 23/07/11 02:15, Franco, Battista wrote:

 Hello

 In to access.log there are many 503 see an example below.
 P.S. on my LAN there is another server with squid 2.6 Stable16 and it
works without problem


 1311340425.016  63101 10.239.57.89 TCP_MISS/503 4297 GET
http://ad.it.doubleclick.net/adj/hp.libero.it/hp;bgarea=hp;adv_sso1=0;ad
v_sso2=0;adv_sso3=0;adv_np=yes;region=0;dcopt=ist;tile=1;sz=728x90,970x9
0,970x27;ord=3947939781? - DIRECT/74.125.227.59 text/html
 1311340488.306  63169 10.239.57.89 TCP_MISS/503 4251 GET
http://ad.it.doubleclick.net/adj/hp.libero.it/hp;fasciahp=1;adv_sso1=0;a
dv_sso2=0;adv_sso3=0;adv_np=yes;region=0;tile=2;sz=300x250,300x600;ord=3
947939781? - DIRECT/74.125.227.59 text/html
 1311342983.075  63771 10.239.57.89 TCP_MISS/503 3994 GET
http://www.microsoft.com/en-us/homepage/shared/core/2/js/js.ashx? -
DIRECT/207.46.131.43 text/html
 1311342983.075  63770 10.239.57.89 TCP_MISS/503 4038 GET
http://www.microsoft.com/en-us/homepage/shared/core/2/css/css.ashx? -
DIRECT/207.46.131.43 text/html


Lots of domains you are unable to connect to. Firewall rules?

Nothing in that set related to flash.


Amos
-- 
Please be using
   Current Stable Squid 2.7.STABLE9 or 3.1.14
   Beta testers wanted for 3.2.0.9


Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

2011-07-25 Thread Franco, Battista
Sorry I didn't see that there are error messagges in access.log (see below)

1311589001.112  0 10.239.57.89 TCP_DENIED/407 4459 GET 
http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/ - NONE/- text/html
1311589001.116  1 10.239.57.89 TCP_DENIED/407 4723 GET 
http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/ - NONE/- text/html


-Messaggio originale-
Da: Franco, Battista [mailto:battista.fra...@saint-gobain.com] 
Inviato: lunedì 25 luglio 2011 09:15
A: Amos Jeffries; squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

Hello
Now with nonhierarchical_direct OFF directive banner and other animation works 
fine but flash video don't work.
i.e. I tried to see the videos on page :

http://tv.quattroruote.it/la-prova/video/chevrolet-aveo-ltz/

and the videos don't start.
In access.log I didn't see error (see below)

1311577629.238336 10.239.57.82 TCP_MISS/301 588 GET 
http://tv.quattroruote.it/asset/css/commenti.css - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577629.432192 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset/css/commenti.css/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.027581 10.239.57.82 TCP_MISS/200 6281 GET 
http://adlev.neodatagroup.com/ad/edidomus.jsp? - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.273  0 10.239.57.82 TCP_IMS_HIT/304 433 GET 
http://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js - NONE/- 
text/javascript
1311577630.300 78 10.239.57.82 TCP_MISS/301 600 GET 
http://tv.quattroruote.it/asset/css/images/fieldbg.gif - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.379 77 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset/css/images/fieldbg.gif/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.580322 10.239.57.82 TCP_MISS/200 2328 GET 
http://www.facebook.com/plugins/like.php? - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.587117 10.239.57.82 TCP_MISS/200 475 GET 
http://secure-it.imrworldwide.com/cgi-bin/j? - 
DEFAULT_PARENT/proxy-parent.domain.net text/javascript
1311577630.686339 10.239.57.82 TCP_MISS/200 472 GET 
http://www.google-analytics.com/__utm.gif? - 
DEFAULT_PARENT/proxy-parent.domain.net image/gif
1311577630.721 68 10.239.57.82 TCP_MISS/200 468 GET 
http://secure-it.imrworldwide.com/cgi-bin/m? - 
DEFAULT_PARENT/proxy-parent.domain.net image/gif
1311577630.803 78 10.239.57.82 TCP_MISS/301 646 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-bg_flat_0_ff_40x100.png - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.860113 10.239.57.82 TCP_MISS/301 640 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-icons_33_256x240.png - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.913108 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-bg_flat_0_ff_40x100.png/ 
- DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577630.957 84 10.239.57.82 TCP_MISS/302 542 GET 
http://tv.quattroruote.it/asset_new/img/ui_img/ui-icons_33_256x240.png/ - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577632.043554 10.239.57.82 TCP_MISS/200 4528 GET 
http://cms.quattroruote.tv/webservices/frontend.asmx/GetVideoByChannelHome? - 
DEFAULT_PARENT/proxy-parent.domain.net application/json
1311577760.827657 10.239.57.89 TCP_MISS/200 352 POST 
http://85.94.205.240/open/1 - DEFAULT_PARENT/proxy-parent.domain.net 
application/x-fcs
1311577761.815639 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/send/20WmTt9BUoguy6-Z/0 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577762.530656 10.239.57.89 TCP_MISS/403 1943 POST 
http://85.94.205.240/idle/20WmTt9BUoguy6-Z/1 - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577763.184605 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/close/20WmTt9BUoguy6-Z/2 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577824.119521 10.239.57.89 TCP_MISS/200 352 POST 
http://85.94.205.240/open/1 - DEFAULT_PARENT/proxy-parent.domain.net 
application/x-fcs
1311577824.682241 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/send/2kWmTt9BUogDy6-Z/0 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs
1311577825.099361 10.239.57.89 TCP_MISS/403 1943 POST 
http://85.94.205.240/idle/2kWmTt9BUogDy6-Z/1 - 
DEFAULT_PARENT/proxy-parent.domain.net text/html
1311577825.660383 10.239.57.89 TCP_MISS/200 300 POST 
http://85.94.205.240/close/2kWmTt9BUogDy6-Z/2 - 
DEFAULT_PARENT/proxy-parent.domain.net application/x-fcs


-Messaggio originale-
Da: Amos Jeffries [mailto:squ...@treenet.co.nz] 
Inviato: lunedì 25 luglio 2011 08:32
A: squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

On 25/07/11 18:16, Franco, Battista wrote:
 Hello
 On the server there isn't firewall rules I

[squid-users] Squid 3 - Cento 6 - don't display flash player

2011-07-22 Thread Franco, Battista
Hello
On Centos 6 and squid 3.1.4 when client surfing on page with flash
player animation they aren't displayed.
I tried to default minimum configuration (see below) + cache_peer  but
nothing change.
Can you help me?

-
Squid.conf 

#
# Recommended minimum configuration:
#
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl localhost src ::1/128
acl to_localhost dst 127.0.0.0/8 0.0.0.0/32
acl to_localhost dst ::1/128

# Example rule allowing access from your local networks.
# Adapt to list your (internal) IP networks from where browsing
# should be allowed
acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
acl localnet src 172.16.0.0/12  # RFC1918 possible internal network
acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
acl localnet src fc00::/7   # RFC 4193 local private network range
acl localnet src fe80::/10  # RFC 4291 link-local (directly plugged)
machines

acl SSL_ports port 443
acl Safe_ports port 80  # http
acl Safe_ports port 21  # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70  # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT

#
# Recommended minimum Access Permission configuration:
#
# Only allow cachemgr access from localhost
http_access allow manager localhost
http_access deny manager

# Deny requests to certain unsafe ports
http_access deny !Safe_ports

# Deny CONNECT to other than secure SSL ports
http_access deny CONNECT !SSL_ports

# We strongly recommend the following be uncommented to protect innocent
# web applications running on the proxy server who think the only
# one who can access services on localhost is a local user
#http_access deny to_localhost

#
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#

# Example rule allowing access from your local networks.
# Adapt localnet in the ACL section to list your (internal) IP networks
# from where browsing should be allowed
http_access allow localnet
http_access allow localhost

# And finally deny all other access to this proxy
http_access deny all

# Squid normally listens to port 3128
http_port 3128

# We recommend you to use at least the following line.
hierarchy_stoplist cgi-bin ?

# Uncomment and adjust the following to add a disk cache directory.
#cache_dir ufs /var/spool/squid 100 16 256

# Leave coredumps in the first cache dir
coredump_dir /var/spool/squid

# Add any of your own refresh_pattern entries above these.
refresh_pattern ^ftp:   144020% 10080
refresh_pattern ^gopher:14400%  1440
refresh_pattern -i (/cgi-bin/|\?) 0 0%  0
refresh_pattern .   0   20% 4320

cache_peer proxy_parent.domain.com parent 8080 0 proxy-only default




[squid-users] R: [squid-users] Squid 3 - Cento 6 - don't display flash player

2011-07-22 Thread Franco, Battista

Hello

In to access.log there are many 503 see an example below.
P.S. on my LAN there is another server with squid 2.6 Stable16 and it works 
without problem


1311340425.016  63101 10.239.57.89 TCP_MISS/503 4297 GET 
http://ad.it.doubleclick.net/adj/hp.libero.it/hp;bgarea=hp;adv_sso1=0;adv_sso2=0;adv_sso3=0;adv_np=yes;region=0;dcopt=ist;tile=1;sz=728x90,970x90,970x27;ord=3947939781?
 - DIRECT/74.125.227.59 text/html
1311340488.306  63169 10.239.57.89 TCP_MISS/503 4251 GET 
http://ad.it.doubleclick.net/adj/hp.libero.it/hp;fasciahp=1;adv_sso1=0;adv_sso2=0;adv_sso3=0;adv_np=yes;region=0;tile=2;sz=300x250,300x600;ord=3947939781?
 - DIRECT/74.125.227.59 text/html
1311342983.075  63771 10.239.57.89 TCP_MISS/503 3994 GET 
http://www.microsoft.com/en-us/homepage/shared/core/2/js/js.ashx? - 
DIRECT/207.46.131.43 text/html
1311342983.075  63770 10.239.57.89 TCP_MISS/503 4038 GET 
http://www.microsoft.com/en-us/homepage/shared/core/2/css/css.ashx? - 
DIRECT/207.46.131.43 text/html




-Messaggio originale-
Da: Amos Jeffries [mailto:squ...@treenet.co.nz] 
Inviato: venerdì 22 luglio 2011 16:06
A: squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid 3 - Cento 6 - don't display flash player

On 23/07/11 01:02, Franco, Battista wrote:
 Hello
 On Centos 6 and squid 3.1.4 when client surfing on page with flash
 player animation they aren't displayed.
 I tried to default minimum configuration (see below) + cache_peer  but
 nothing change.
 Can you help me?

You should see a bunch of requests in access.log as each animation icon, 
image, script gets loaded.

So are the requests happening? if not the app is broken and either not 
making any requests or not making them through the proxy like it should.

If they are, is there a sign of 4xx/5xx status codes? take a closer look 
at those, particularly on script requests, to see whats going wrong.

Amos
-- 
Please be using
   Current Stable Squid 2.7.STABLE9 or 3.1.14
   Beta testers wanted for 3.2.0.9


[squid-users] R: [squid-users] Re: squid with kerberos authentication

2011-07-20 Thread Franco, Battista
Hello

The cache.log file are below:

2011/07/20 09:49:08| Starting Squid Cache version 3.1.4 for i686-pc-linux-gnu...
2011/07/20 09:49:08| Process ID 6027
2011/07/20 09:49:08| With 1024 file descriptors available
2011/07/20 09:49:08| Initializing IP Cache...
2011/07/20 09:49:08| DNS Socket created at [::], FD 7
2011/07/20 09:49:08| Adding domain xx.yy.zz.net from /etc/resolv.conf
2011/07/20 09:49:08| Adding nameserver 10.239.56.3 from /etc/resolv.conf
2011/07/20 09:49:08| helperOpenServers: Starting 10/10 'squid_kerb_auth' 
processes
2011/07/20 09:49:08| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:08| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:08| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:08| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| User-Agent logging is disabled.
2011/07/20 09:49:09| Referer logging is disabled.
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| squid_kerb_auth: INFO: Starting version 1.0.5
2011/07/20 09:49:09| Unlinkd pipe opened on FD 32
2011/07/20 09:49:09| Local cache digest enabled; rebuild/rewrite every 
3600/3600 sec
2011/07/20 09:49:09| Store logging disabled
2011/07/20 09:49:09| Swap maxSize 0 + 262144 KB, estimated 20164 objects
2011/07/20 09:49:09| Target number of buckets: 1008
2011/07/20 09:49:09| Using 8192 Store buckets
2011/07/20 09:49:09| Max Mem  size: 262144 KB
2011/07/20 09:49:09| Max Swap size: 0 KB
2011/07/20 09:49:09| Using Least Load store dir selection
2011/07/20 09:49:09| Set Current Directory to /var/spool/squid
2011/07/20 09:49:09| Loaded Icons.
2011/07/20 09:49:09| Accepting  HTTP connections at [::]:8080, FD 33.
2011/07/20 09:49:09| Accepting  HTTP connections at [::]:8084, FD 34.
2011/07/20 09:49:09| HTCP Disabled.
2011/07/20 09:49:09| Squid modules loaded: 0
2011/07/20 09:49:09| Adaptation support is off.
2011/07/20 09:49:09| Ready to serve requests.
2011/07/20 09:49:09| Configuring Parent parent.xx.yy.zz.net/8084/0
2011/07/20 09:49:09| Configuring Parent parent1.xx.yy.zz.net/8080/0
2011/07/20 09:49:10| storeLateRelease: released 0 objects
2011/07/20 09:50:33| squid_kerb_auth: DEBUG: Got 'YR 
YIII4QYGKwYBBQUCoIII1TCCCNGgJDAiBgkqhkiC9xIBAgIGCSqGSIb3EgECAgYKKwYBBAGCNwICCqKCCKcEggijYIIInwYJKoZIhvcSAQIC
 

2011/07/20 09:50:33| squid_kerb_auth: DEBUG: Decode 
'YIII4QYGKwYBBQUCoIII1TCCCNGgJDAiBgkqhkiC9xIBAgIGCSqGSIb3EgECAgYKKwYBBAGCNwICCqKCCKcEggijYIIInwYJKoZIhvcSAQI

2011/07/20 09:50:35| squid_kerb_auth: ERROR: gss_acquire_cred() failed: 
Unspecified GSS failure.  Minor code may provide more information. Key table 
entry not found
2011/07/20 09:50:35| authenticateNegotiateHandleReply: Error validating user 
via Negotiate. Error returned 'BH gss_acquire_cred() failed: Unspecified GSS 
failure.  Minor code may provide more information. Key table entry not found'


IE 8 was configurated with :
Enable Integrated Windows Authentication checked
Connection | Lan Setting | Server Proxy - proxyservername Port 8080

On KerbTray List there is the following Ticket:

HTTP:/proxyservername
Client name : usern...@xx.yy.zz.net
Servicename : HTTP:/proxyservern...@xx.yy.zz.net
Target name : HTTP:/proxyservern...@xx.yy.zz.net
Checked Flags are: Forwardable, Renewable, Preauthenticated




-Messaggio originale-
Da: Markus Moeller [mailto:hua...@moeller.plus.com] 
Inviato: martedì 19 luglio 2011 23:15
A: squid-users@squid-cache.org
Oggetto: [squid-users] Re: squid with kerberos authentication

What does the cache.log file say if you add -d to

auth_param negotiate program /usr/lib/squid/squid_kerb_auth

i.e.
auth_param negotiate program /usr/lib/squid/squid_kerb_auth -d

How did you configure IE ?

Can you see a ticket for HTTP/squid-fqdn in kerbtray 
(http://www.microsoft.com/download/en/details.aspx?displaylang=enid=23018)?

Regards
Markus


Franco, Battista battista.fra...@saint-gobain.com wrote in message 
news:0b0bf3f65f960a4b8be340e64290f4cd0696d...@a00exgec23.za.if.atcsg.net...
Hello

On Centos 6 I want used squid (version 3.1.4) with Kerberos
authentication so only AD Windows 2003 authenticated users can surfing.
Well I perform the steps (explained at link
http://wiki.squid-cache.org/ConfigExamples/Authenticate/Kerberos)

but when users tried to surfing the IE require user and password and
didn't surfing.
Why?
Can you help me.

 MORE INFO 

I did the following steps:

Install  and configure samba
modify krb5.conf
net ads join -U DOMAIN\administrator
kinit administrator@DOMAIN
export KRB5_KTNAME=FILE:/etc/squid/HTTP.keytab
net ads keytab CREATE -U DOMAIN\administrator
net ads keytab ADD HTTP -U DOMAIN\administrator
unset KRB5_KTNAME
chgrp squid /etc

[squid-users] squid with kerberos authentication

2011-07-19 Thread Franco, Battista
Hello

On Centos 6 I want used squid (version 3.1.4) with Kerberos
authentication so only AD Windows 2003 authenticated users can surfing.
Well I perform the steps (explained at link
http://wiki.squid-cache.org/ConfigExamples/Authenticate/Kerberos)

but when users tried to surfing the IE require user and password and
didn't surfing.
Why?
Can you help me.

 MORE INFO 

I did the following steps:

Install  and configure samba 
modify krb5.conf
net ads join -U DOMAIN\administrator
kinit administrator@DOMAIN
export KRB5_KTNAME=FILE:/etc/squid/HTTP.keytab
net ads keytab CREATE -U DOMAIN\administrator
net ads keytab ADD HTTP -U DOMAIN\administrator
unset KRB5_KTNAME
chgrp squid /etc/squid/HTTP.keytab
chmod g+r /etc/squid/HTTP.keytab
modify squid startup file with :
KRB5_KTNAME=/etc/squid/HTTP.keytab
export KRB5_KTNAME



below squid.conf file:


auth_param negotiate program /usr/lib/squid/squid_kerb_auth
auth_param negotiate children 10
auth_param negotiate keep_alive on
acl auth proxy_auth REQUIRED
...
http_access deny !auth
http_access allow auth
http_access deny all



With command :
/usr/lib/squid/squid_kerb_auth_test proxyserver 
The token was displayed.

 


[squid-users] two different proxy parent with 2 different port

2010-01-21 Thread Franco, Battista
Hello

My Company changed the parent Proxy

So parent proxy for normal activity is ParentProxy_1 (see my line below)

cache_peer ParentProxy_1 parent 8080 0 default

and SSL traffic ParentProxy_2 on port 8084

I tried to add the following line on my squid.conf

cache_peer ParentProxy_2 parent 8084 0 proxy-only
 
but it doesn't work
can you help me?



[squid-users] TCP_MISS/000 error message

2006-06-28 Thread Franco, Battista
Hi

I connected to site https://xxx.com; after I put username and password
but it doesn't work (user  password are correct because if I tried to
connect without squid everything is Ok).

In access.log the following messages appears: 

1151413575.687   1596 10.239.57.34 TCP_MISS/000 16284 CONNECT 
xxx.com:443 - DEFAULT_PARENT/parent.it -
1151413592.744  20121 10.239.57.34 TCP_MISS/000 71521 CONNECT 
xxx.com:443 - DEFAULT_PARENT/parent.it -
1151413593.137  17437 10.239.57.34 TCP_MISS/000 6256 CONNECT 
xxx.com:443 - DEFAULT_PARENT/parent.it -
 



[squid-users] R: [squid-users] R: [squid-users] AD and Single Sign On

2006-06-12 Thread Franco, Battista
Hello 
I configured squid and samba but (from a client with MS IE 6) when i tried to 
connect to internet the pop-up with a request of username and password appears.
More info below:

# wbinfo -t
checking the trust secret via RPC calls succeeded
# wbinfo -a mydom\\user%password
plaintext password authentication succeeded
challenge/response password authentication succeeded
# /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
Mydom+user password
[2006/06/12 14:52:07, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
  NT_STATUS_OK: Success (0x0)
OK
#



Smb.conf is:


   netbios name = aa1pxysav00
   realm = ZA.IF.ATCSG.NET
   workgroup = ZA
   security = ADS
   password server = server.mydom.com
   encrypt passwords = yes
   log level = 3 passdb:5 auth:10 winbind:5
   idmap uid = 1-2
   template shell = /bin/false
   winbind enum users = yes
   winbind uid = 1-2
   winbind gid = 1-2
   winbind separator = +
   winbind use default domain = yes
...



Squid.conf is:

auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 30
auth_param ntlm max_challenge_reuses 0
auth_param ntlm max_challenge_lifetime 2 minutes # ntlm_auth from Samba 3 
supports NTLM NEGOTIATE packet auth_param ntlm use_ntlm_negotiate on auth_param 
basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic auth_param 
basic children 5 auth_param basic realm Squid proxy-caching web server 
auth_param basic credentialsttl 2 hours auth_param basic casesensitive off 
acl AuthorizedUsers proxy_auth REQUIRED
http_access allow all AuthorizedUsers

cache_peer proxy.xxx.com parent 8080 0 proxy-only default

--

Access.log

1150117192.969364 10.239.57.34 TCP_MISS/200 4388 GET http://www.google.it/ 
username DEFAULT_PARENT/proxy.xxx.com text/html
1150117223.316  24100 10.239.57.34 TCP_MISS/503 1384 GET 
http://www.google.it/imghp? username NONE/- text/html



Could you help me?



-Messaggio originale-
Da: Jakob Curdes [mailto:[EMAIL PROTECTED]
Inviato: venerdì 9 giugno 2006 14.44
A: Franco, Battista
Cc: squid-users@squid-cache.org
Oggetto: Re: [squid-users] AD and Single Sign On

Franco, Battista schrieb:

Hello

I used a squid 2.5 stable 9 on fedora code 4.

My windows domain is an AD 2003.

Is it possibile to configure my squid to work as single sign on so 
users will not need to put username and password when accessing to 
internet?

How do i do it?

 
 
  

See

http://wiki.squid-cache.org/SquidFaq/ProxyAuthentication

Hope this helps,

Jakob Curdes

Hint for the FAQ admins : the keyword NTLM or AD does not show up anywhere in 
the content list, myabe it would be a good idea to shift one of the headlines a 
little - this question keeps getting asked again and again.

Jakob Curdes


[squid-users] R: [squid-users] AD and Single Sign On

2006-06-12 Thread Franco, Battista
 Yes it is.



-Messaggio originale-
Da: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] 
Inviato: lunedì 12 giugno 2006 15.01
A: Franco, Battista
Cc: squid-users@squid-cache.org
Oggetto: Re:[squid-users] AD and Single Sign On

Is that computer on your windows domain ? 

Quoting Franco, Battista [EMAIL PROTECTED]:

 Hello
 I configured squid and samba but (from a client with MS IE 6) when i 
 tried to connect to internet the pop-up with a request of username and 
 password appears.
 More info below:
 
 # wbinfo -t
 checking the trust secret via RPC calls succeeded # wbinfo -a 
 mydom\\user%password plaintext password authentication succeeded 
 challenge/response password authentication succeeded # 
 /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
 Mydom+user password
 [2006/06/12 14:52:07, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
   NT_STATUS_OK: Success (0x0)
 OK
 #
 
 
 
 Smb.conf is:
 
 
netbios name = aa1pxysav00
realm = ZA.IF.ATCSG.NET
workgroup = ZA
security = ADS
password server = server.mydom.com
encrypt passwords = yes
log level = 3 passdb:5 auth:10 winbind:5
idmap uid = 1-2
template shell = /bin/false
winbind enum users = yes
winbind uid = 1-2
winbind gid = 1-2
winbind separator = +
winbind use default domain = yes
 ...
 
 
 
 Squid.conf is:
 
 auth_param ntlm program /usr/bin/ntlm_auth 
 --helper-protocol=squid-2.5-ntlmssp
 auth_param ntlm children 30
 auth_param ntlm max_challenge_reuses 0 auth_param ntlm 
 max_challenge_lifetime 2 minutes # ntlm_auth from Samba 3 supports 
 NTLM NEGOTIATE packet auth_param ntlm use_ntlm_negotiate on auth_param 
 basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic 
 auth_param basic children 5 auth_param basic realm Squid proxy-caching 
 web server auth_param basic credentialsttl 2 hours auth_param basic 
 casesensitive off 
 acl AuthorizedUsers proxy_auth REQUIRED http_access allow all 
 AuthorizedUsers 
 cache_peer proxy.xxx.com parent 8080 0 proxy-only default
 
 --
 
 Access.log
 
 1150117192.969364 10.239.57.34 TCP_MISS/200 4388 GET
 http://www.google.it/ username DEFAULT_PARENT/proxy.xxx.com text/html
 1150117223.316  24100 10.239.57.34 TCP_MISS/503 1384 GET 
 http://www.google.it/imghp? username NONE/- text/html
 
 
 
 Could you help me?
 
 
 
 -Messaggio originale-
 Da: Jakob Curdes [mailto:[EMAIL PROTECTED]
 Inviato: venerdì 9 giugno 2006 14.44
 A: Franco, Battista
 Cc: squid-users@squid-cache.org
 Oggetto: Re: [squid-users] AD and Single Sign On
 
 Franco, Battista schrieb:
 
 Hello
 
 I used a squid 2.5 stable 9 on fedora code 4.
 
 My windows domain is an AD 2003.
 
 Is it possibile to configure my squid to work as single sign on so 
 users will not need to put username and password when accessing to 
 internet?
 
 How do i do it?
 
  
  
   
 
 See
 
 http://wiki.squid-cache.org/SquidFaq/ProxyAuthentication
 
 Hope this helps,
 
 Jakob Curdes
 
 Hint for the FAQ admins : the keyword NTLM or AD does not show up 
 anywhere in the content list, myabe it would be a good idea to shift 
 one of the headlines a little - this question keeps getting asked again and 
 again.
 
 Jakob Curdes
 
 


-- 
 Peter Collins Wasenda 
 Network Administrator 
 IT Division, Corporate Services
 Uganda Revenue Authority  
 P.O. Box 7279, Kampala

 Tel: (041)334474,334535   
 Mob: 0752-996477  
 
---
  


This message was sent using IMP, the Internet Messaging Program.


[squid-users] AD and Single Sign On

2006-06-09 Thread Franco, Battista

Hello

I used a squid 2.5 stable 9 on fedora code 4.

My windows domain is an AD 2003.

Is it possibile to configure my squid to work as single sign on so
users will not need to put username and password when accessing to
internet?

How do i do it?

 
 


[squid-users] R: [squid-users] AD and Single Sign On

2006-06-09 Thread Franco, Battista
Hello
I configured squid and samba but (from a client with MS IE 6) when i tried to 
connect to internet the pop-up with a request of username and password appears.
My squid.conf is:

auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 30
auth_param ntlm max_challenge_reuses 0
auth_param ntlm max_challenge_lifetime 2 minutes
# ntlm_auth from Samba 3 supports NTLM NEGOTIATE packet
auth_param ntlm use_ntlm_negotiate on
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off

acl AuthorizedUsers proxy_auth REQUIRED
http_access allow all AuthorizedUsers

cache_peer xxx.x.com parent 8080 0 proxy-only default

--

Could you help me?



-Messaggio originale-
Da: Jakob Curdes [mailto:[EMAIL PROTECTED] 
Inviato: venerdì 9 giugno 2006 14.44
A: Franco, Battista
Cc: squid-users@squid-cache.org
Oggetto: Re: [squid-users] AD and Single Sign On

Franco, Battista schrieb:

Hello

I used a squid 2.5 stable 9 on fedora code 4.

My windows domain is an AD 2003.

Is it possibile to configure my squid to work as single sign on so 
users will not need to put username and password when accessing to 
internet?

How do i do it?

 
 
  

See

http://wiki.squid-cache.org/SquidFaq/ProxyAuthentication

Hope this helps,

Jakob Curdes

Hint for the FAQ admins : the keyword NTLM or AD does not show up anywhere in 
the content list, myabe it would be a good idea to shift one of the headlines a 
little - this question keeps getting asked again and again.

Jakob Curdes


[squid-users] Save clients password

2006-02-22 Thread Franco, Battista
Hi
I use squid ldap users authentication.
From my client PCs every time I start IE I need to insert username and
password. 
Is it possible to configure squid user and password popup with a
checkbox to permit to save password?
So next time I'll not retype password.


Re: [squid-users] Squid - Ldap

2006-02-19 Thread Franco, Battista
I tried setenforce 0 and now it's OK. :o
But another question: everytime I restart server should i need repeat 
setenforce 0?


-Messaggio originale-
Da: Chris Robertson [mailto:[EMAIL PROTECTED] 
Inviato: giovedì 16 febbraio 2006 19.15
A: squid-users@squid-cache.org
Oggetto: RE: [squid-users] Squid - Ldap

 -Original Message-
 From: Franco, Battista [mailto:[EMAIL PROTECTED]
 Sent: Thursday, February 16, 2006 7:34 AM
 To: squid-users@squid-cache.org
 Cc: Mark Elsen
 Subject: [squid-users] R: [squid-users] R: [squid-users] Squid - Ldap
 
 
 Hi 
 I understand it but why when do i use squid_ldap_auth from 
 command line it's work?
 Another thing:
 I tried to connect with LDAP Browser program; it work with 
 anonymous bind.

1) Try running /usr/lib/squid/squid_ldap_auth as the cache_effective_user.
2) Do you have SELINUX enabled?  That could be the problem.  Try running 
setenforce 0 (without the quotes), and see if you can authenticate.

Chris


[squid-users] Squid - Ldap

2006-02-16 Thread Franco, Battista
Hello
I want use squid 2.5stable9 with LDAP Windows 2003 Server
authentication.
From command line :
/usr/lib/squid/squid_ldap_auth -b
OU=Users,OU=,OU=Locations,OU=,dc=bb,dc=cc,dc=,dc=net  -f
sAMAccountName=%s -h 10.239.56.2

It's OK.
But when I try to connect to internet from a client it doesn't work
This is the error on access.log files:
1140087014.218  0 10.239.57.19 TCP_DENIED/407 1784 GET
http://www.microsoft.com/isapi/redir.dll? - NONE/- text/html

My squid.conf is:

http_port 8080
...
/usr/lib/squid/squid_ldap_auth -b
OU=Users,OU=,OU=Locations,OU=,dc=bb,dc=cc,dc=,dc=net  -f
sAMAccountName=%s -h 10.239.56.2
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours

acl password proxy_auth REQUIRED
acl all src 0.0.0.0/0.0.0.0
http_access allow password
http_access deny all
acl localhost src 127.0.0.1/255.255.255.255

cache_peer anotherproxy.com parent 8080 0 proxy-only default


can you help me?




 


[squid-users] R: [squid-users] Squid - Ldap

2006-02-16 Thread Franco, Battista
Hi 
I understand it but why when do i use squid_ldap_auth from command line it's 
work?



-Messaggio originale-
Da: Mark Elsen [mailto:[EMAIL PROTECTED] 
Inviato: giovedì 16 febbraio 2006 11.20
A: Franco, Battista
Cc: squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid - Ldap

 Hello
 I want use squid 2.5stable9 with LDAP Windows 2003 Server
 authentication.
 From command line :
 /usr/lib/squid/squid_ldap_auth -b
 OU=Users,OU=,OU=Locations,OU=,dc=bb,dc=cc,dc=,dc=net  -f
 sAMAccountName=%s -h 10.239.56.2

 It's OK.
 But when I try to connect to internet from a client it doesn't work
 This is the error on access.log files:


  
http://www.squid-cache.org/mail-archive/squid-users/200602/0323.html

  (maybe).

  M.


[squid-users] R: [squid-users] R: [squid-users] Squid - Ldap

2006-02-16 Thread Franco, Battista
Another thing:
I tried to connect with LDAP Browser program; it work with anonymous bind.


-Messaggio originale-
Da: Franco, Battista [mailto:[EMAIL PROTECTED] 
Inviato: giovedì 16 febbraio 2006 11.32
A: squid-users@squid-cache.org
Cc: Mark Elsen
Oggetto: [squid-users] R: [squid-users] Squid - Ldap

Hi 
I understand it but why when do i use squid_ldap_auth from command line it's 
work?



-Messaggio originale-
Da: Mark Elsen [mailto:[EMAIL PROTECTED] 
Inviato: giovedì 16 febbraio 2006 11.20
A: Franco, Battista
Cc: squid-users@squid-cache.org
Oggetto: Re: [squid-users] Squid - Ldap

 Hello
 I want use squid 2.5stable9 with LDAP Windows 2003 Server
 authentication.
 From command line :
 /usr/lib/squid/squid_ldap_auth -b
 OU=Users,OU=,OU=Locations,OU=,dc=bb,dc=cc,dc=,dc=net  -f
 sAMAccountName=%s -h 10.239.56.2

 It's OK.
 But when I try to connect to internet from a client it doesn't work
 This is the error on access.log files:


  
http://www.squid-cache.org/mail-archive/squid-users/200602/0323.html

  (maybe).

  M.


[squid-users] R: [squid-users] Squid - LDAP

2006-02-14 Thread Franco, Battista
When I used (from command line) it's OK.
/usr/lib/squid/squid_ldap_auth -R -b dc=xx,dc=yyy,dc=,dc=  -f 
sAMAccountName=%s -h 10.239.56.2





-Messaggio originale-
Da: Tim Neto [mailto:[EMAIL PROTECTED] 
Inviato: martedì 14 febbraio 2006 16.01
A: squid-users@squid-cache.org
Cc: Esteban; Franco, Battista
Oggetto: Re: [squid-users] Squid - LDAP


One thing to note, In Windows 2003 Server, Microsoft disables anonymous 
LDAP binds by default.  Instead of doing an anonymous bind, try testing 
your squid_ldap_auth command with options to bind as an authorative 
user.  Like:

/usr/lib/squid/squid_ldap_auth -D Administrator -w Admin_Password -R 
-b dc=xx,dc=yyy,dc=,dc=  -f sAMAccountName=%s -h 10.239.56.2

Note the -D and -w options.

I do not recommend encoding the Active Directory administrator account 
in the squid configuration file.  Either set up another authorized 
account that has read only permissions, or see Microsoft's documentation 
on enabling anonymous binds to a Windows 2003 Active Directory via LDAP.

Tim

---
Timothy E. Neto
Computer Systems Engineer Komatsu Canada Limited
Ph#: 905-625-6292 x2651725B Sismet Road
Fax: 905-625-6348 Mississauga, Canada
E-Mail: [EMAIL PROTECTED]  L4W 1P9
---



Esteban wrote:
 Test if the autenticator work..
 run /usr/lib/squid/squid_ldap_auth -R -b dc=xx,dc=yyy,dc=,dc=  -f
 sAMAccountName=%s -h 10.239.56.2 
 And enter UsernameSPACEpasswordENTER IF you get OK the autenticator
 Works If you always get an ERR you should chech te configuration of the
 Helper / the Ldap Server

 And for testing only use this Http_access Schema

 http_access allow password
 http_access deny all


   
 My squid.conf is:
 .
 auth_param basic program /usr/lib/squid/squid_ldap_auth -R -b
 dc=xx,dc=yyy,dc=,dc=  -f sAMAccountName=%s -h 10.239.56.2
 auth_param basic children 5
 auth_param basic realm Squid proxy-caching web server
 auth_param basic credentialsttl 2 hours
 auth_param basic casesensitive off
 .
 acl password proxy_auth REQUIRED
 acl all src 0.0.0.0/0.0.0.0
 acl manager proto cache_object
 acl localhost src 127.0.0.1/255.255.255.255
 acl to_localhost dst 127.0.0.0/8
 acl SSL_ports port 443 563 407
 acl Safe_ports port 80  # http
 acl Safe_ports port 21  # ftp
 acl Safe_ports port 443 563 # https, snews
 acl Safe_ports port 70  # gopher
 acl Safe_ports port 210 # wais
 acl Safe_ports port 1025-65535  # unregistered ports
 acl Safe_ports port 280 # http-mgmt
 acl Safe_ports port 488 # gss-http
 acl Safe_ports port 591 # filemaker
 acl Safe_ports port 777 # multiling http
 acl Safe_ports port 407
 acl CONNECT method CONNECT
 


   
 http_access allow manager localhost
 http_access allow password
 http_access deny manager
 http_access deny !Safe_ports
 http_access deny CONNECT !SSL_ports
 http_access allow localhost
 http_access deny all
 
 cache_peer another-proxy..com parent 8080 0 proxy-only default
 #

 Which is the problem?

 



   


[squid-users] Squid - Ldap

2006-02-13 Thread Franco, Battista


[squid-users] Squid - LDAP

2006-02-13 Thread Franco, Battista

Hello 
I use squid 2.5stable9 on fedora core 4. 
I want use squid with ldap (Windows 2003) authentications.
Client doesn't work and access.log file is:
1139839762.746  0 10.239.57.19 TCP_DENIED/407 1784 GET
http://www.microsoft.com/isapi/redir.dll? - NONE/- text/html

My squid.conf is:
.
auth_param basic program /usr/lib/squid/squid_ldap_auth -R -b
dc=xx,dc=yyy,dc=,dc=  -f sAMAccountName=%s -h 10.239.56.2
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
.
acl password proxy_auth REQUIRED
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563 407
acl Safe_ports port 80  # http
acl Safe_ports port 21  # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70  # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 407
acl CONNECT method CONNECT
http_access allow manager localhost
http_access allow password
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access deny all

cache_peer another-proxy..com parent 8080 0 proxy-only default
#

Which is the problem?
 


[squid-users] Squid permits read only access to ftp address

2005-02-14 Thread Franco Battista \(Baky\)
I want to connect to

ftp://user:[EMAIL PROTECTED]

my user have a write permission but I receive a message that inform me I
have only read permission.
Why?
I have squid 2.5.STABLE6

Best regards






[squid-users] Problem with squid and flash

2004-08-26 Thread FRANCO Battista
I use Squid 2.5.STABLE3
I connected to:
https://ebanking.crbra.it:443
after license, user and password Internet explorer shows an incorrect page.
ebanking.crbra.it 's administrator tell me that the problem is proxy cache, 
infact i try to connect at this site without using squid and it working.
This site use HTML and Macromedia Flash.
Can you help me?






[squid-users] Squid report

2004-02-19 Thread FRANCO Battista
How can i produce a HTML report from access.log.
i need know all site visited from my clients




[squid-users] R: [squid-users] Squid and DNS

2003-04-01 Thread FRANCO Battista (Baky)
You must set the following squid parameter :  
dns_nameservers x.y.w.z


-Messaggio originale-
Da: Emanuele Lo Giudice [mailto:[EMAIL PROTECTED]
Inviato:martedi 1 aprile 2003 10.33
A:  [EMAIL PROTECTED]
Oggetto:[squid-users] Squid and DNS

I need to now if is possible to delegate the name resolution of some domain
to other name server (not in the resolv.conf file)

someting like:
all the domain are solved by resolv.conf content
*.my.foo.com is dolved by x.y.z.w

is this possible? and How?

Thanks
Emanuele



[squid-users] R: [squid-users] Client Computer Name in access.log

2003-02-14 Thread FRANCO Battista (Baky)
I set :
log_fqdn on
after 
squid -k reconfigure
but it doesn't work :o

-Messaggio originale-
Da: Henrik Nordstrom [mailto:[EMAIL PROTECTED]]
Inviato:venerdi 14 febbraio 2003 1.43
A:  FRANCO Battista (Baky)
Cc: [EMAIL PROTECTED]
Oggetto:Re: [squid-users] Client Computer Name in access.log

log_fqdn

Regards
Henrik


FRANCO Battista (Baky) wrote:
 
 In my access.log i find client Ip address and its url links can i modify my
 confiuratin file to write client computer name instad of IP address.
 Thank You




[squid-users] R: [squid-users] R: [squid-users] Client Computer Name in access.log

2003-02-14 Thread FRANCO Battista (Baky)
Yes it's because from my Server Linux i can ping clientcomputername  


-Messaggio originale-
Da: Henrik Nordstrom [mailto:[EMAIL PROTECTED]]
Inviato:venerdi 14 febbraio 2003 11.06
A:  FRANCO Battista (Baky)
Cc: [EMAIL PROTECTED]
Oggetto:Re: [squid-users] R: [squid-users] Client Computer Name in access.log

And is the name of your client stations registered on their IP addresses
in your DNS servers?

(if not, how do you expect Squid to be able to know the computer name..)

Regards
Henrik


FRANCO Battista (Baky) wrote:
 
 I set :
 log_fqdn on
 after
 squid -k reconfigure
 but it doesn't work :o
 
 -Messaggio originale-
 Da: Henrik Nordstrom [mailto:[EMAIL PROTECTED]]
 Inviato:venerdi 14 febbraio 2003 1.43
 A:  FRANCO Battista (Baky)
 Cc: [EMAIL PROTECTED]
 Oggetto:Re: [squid-users] Client Computer Name in access.log
 
 log_fqdn
 
 Regards
 Henrik
 
 FRANCO Battista (Baky) wrote:
 
  In my access.log i find client Ip address and its url links can i modify my
  confiuratin file to write client computer name instad of IP address.
  Thank You




[squid-users] Client Computer Name in access.log

2003-02-13 Thread FRANCO Battista (Baky)
In my access.log i find client Ip address and its url links can i modify my 
confiuratin file to write client computer name instad of IP address.
Thank You




[squid-users] DHCP and acl aclname src a.b.c.d /netmask.

2003-02-03 Thread FRANCO Battista (Baky)
I have DHCP and i want use squid with acl aclname src ip-address/netmask
So when a client change IP  address i need to change my role.
Can i use computer name instead of IP address.
Thank You