Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-30 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/30/2014 05:11 AM, Victor Sudakov wrote: Can you share the basic cache manager requests statistics and the up time for the service? (mgr:info) This would give us a basic idea of the load\requests needed to reproduce it. I am not Steve

Re: [squid-users] ERROR: URL-rewrite

2014-09-30 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Alejandro, Can I ask where in the site have you taken this code from? Using php as a helper is not such a good choice due to couple issues it has with squid stdin\stdout emulation. You'd better use perl\python\ruby\other then php unless you

Re: [squid-users] redirect all ports to squid

2014-09-30 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Indeed using SSL-BUMP it's possible but(a bit but).. It will not be able to handle non http\https traffic just like that. It will require more then just squid setup and it might be a better idea to find a better solution for you rather then using

Re: [squid-users] redirect all ports to squid

2014-09-30 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/30/2014 08:30 PM, Leonardo Rodrigues wrote: Other protocols, SMTP, IMAP, POP3, etc etc etc, cannot be handled by squid. They cannot be interpreted but can be handled with a none rule for ssl bump. Eliezer -BEGIN PGP SIGNATURE-

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-07 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/08/2014 06:29 AM, Victor Sudakov wrote: Markus, I could find the said script neither in the source nor in the binary package. However I think I can guess what could be inside. Could you look below if that makes sense? Or you can just look

Re: [squid-users] Probléme Squid to Java application

2014-10-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/22/2014 12:38 PM, Yassin CHOUCHANE wrote: i have added on my squid.conf this ACL : acl NoCachedSites dstdomain srv-java.e.t acl our_servers src 2.10.3.1 i have added the ip of server and the dstdomain, but squid continue to block

Re: [squid-users] 3.3.x - 3.4.x: huge performance regression

2014-10-23 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey, What is the network load? how many users? Have you been using workers at all in the past? Can you see the avg requests per second on the cache manager page? Eliezer On 10/22/2014 09:02 AM, Eugene M. Zheganin wrote: Hi. I was using the

Re: [squid-users] Squid 3.5.0.1 beta is available

2014-10-23 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/23/2014 02:40 AM, Amos Jeffries wrote: If you are seeing this old content constantly or round-robin style between page loads you can use west.squid-cache.org temporarily in the URLs instead of www. Amos It's the same issue for me:

Re: [squid-users] Squid 3.5.0.2 beta is available

2014-11-06 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/05/2014 11:56 AM, Odhiambo Washington wrote: Hi Eliezer, That link should be fine, although my system is actually PC-BSD. The version is the same though an old version. My exact version is:

Re: [squid-users] wccp2HandleUdp: fatal error - A WCCP router does not support the forwarding method specified, only GRE supported

2014-11-09 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Two things, - - What cisco device? what IOS? - - What docs in cisco have you tried to use? Eliezer On 11/08/2014 10:18 PM, Ahmed Allzaeem wrote: Hi , Im trying to implemnte wccp/tproxy between squid cisco I have : wccp2HandleUdp: fatal

Re: [squid-users] sslbump working with 3.4.9 but not in intercept mode?

2014-11-10 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Can you send all ssl_bump related settings? There are some missing parts in the settings. If there is a bug\error the full details are needed to analyze the subject. I need: - - OS details - - machine details - - network topology - - cache logs - -

Re: [squid-users] Problem with Squid 3.4 and transparent SSL proxy

2014-11-11 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey, Your configuration seems to not include any iptables and other relevant details. What is this machine details? Eliezer On 11/11/2014 04:20 PM, Job wrote: Hello, i initialize correctly SSL Bump with Squid 3.4.4, following some guides. In

Re: [squid-users] squid-3.4.8 intercept

2014-11-18 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Frank, To understand the issue better I am missing couple things. I filtered the squid.conf (which is a basic thing to do) and the content can be seen here: http://www1.ngtech.co.il/paste/1216/ It seems like you do not understand what and how.

Re: [squid-users] Squid 3.4.9 RPM release

2014-11-18 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/18/2014 12:09 AM, Eliezer Croitoru wrote: HTML version at: http://www1.ngtech.co.il/repo/release-3.4.9.html I am happy to release the new RPMs of squid 3.4.9 and 3.5.0.2 beta for Centos 6.6 64bit. All The Bests, Eliezer Croitoru Addition

[squid-users] Authentication\Authorization using a PAC file?

2014-11-24 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I do know that pac files contains some form of JS and in the past I have seen couple complex PAC files but unsure about the options. I want to know if a PAC file can be used for Authentication\Authorization, maybe even working against another external

Re: [squid-users] Authentication\Authorization using a PAC file?

2014-11-24 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/24/2014 03:24 PM, Kinkie wrote: But what if multiple users share the same IP (e.g. Citrix, X11)? This is another situation which requires authentication... Two users can use the same pac files and be authorized as another user(a regular forward

Re: [squid-users] Authentication\Authorization using a PAC file?

2014-11-24 Thread Eliezer Croitoru
research about it. All The Bests, Eliezer Croitoru On 11/24/2014 10:42 PM, James Harper wrote: Seems like the sort of thing you could test with a minimum of effort... James -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJUc7NcAAoJENxnfXtQ8ZQUb0AH/j1b5RjHNRDVWrLyaItl0Xh0

Re: [squid-users] Authentication\Authorization using a PAC file?

2014-11-25 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/24/2014 10:06 PM, Jason Haar wrote: I think you are confusing proxy authentication with WPAD/PAC files. WPAD knows nothing about proxy authentication: browsers do ie you use WPAD to tell browsers where/if they need to use a proxy and under

Re: [squid-users] https issues for google

2014-12-07 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Glenn, I noticed that in the mean while you have upgraded the system to latest 3.4.9 stable. As Amos mentioned there are couple options about the tunneling issues. I am unsure about the issue since in my environment squid seems to not have any

Re: [squid-users] Squid 3.4.x Videos/Music Booster

2014-12-08 Thread Eliezer Croitoru
for the public list. Eliezer Croitoru On 12/08/2014 01:30 PM, Stakres wrote: Hi All, New build 2.05 https://sourceforge.net/projects/squidvideosbooster - New option -g to enable the Global Generic Patterns acting with not-yet identified websites. This option will do its best to de-duplicate all

Re: [squid-users] Squid 3.4.x Videos/Music Booster

2014-12-08 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The answer to your question can be answered by ldd ##START $ ldd ut-squidbooster linux-vdso.so.1 = (0x7fffc5e0) libdl.so.2 = /lib/x86_64-linux-gnu/libdl.so.2 (0x7f176d3f) libm.so.6 =

Re: [squid-users] https issues for google

2014-12-10 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Glen, Since openssls_client is showing you this error I assume squid received the same response. We do need to verify why the connection is being hangs. For now it seems like not 100% squid related issue. Eliezer On 12/09/2014 01:57 AM,

Re: [squid-users] Existing root certificate not working with SSL Bump (squid 3.3.10)

2014-12-10 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/10/2014 09:25 PM, HaxNobody wrote: The proxy runs on Linux (Ubuntu, I believe), and I'm doing my testing from multiple browsers on Windows 8.1. I have been unable to find a way to use openssl s_client via a proxy, although I was able to run

Re: [squid-users] Caching based on header/etag

2014-12-11 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 If you have access to the apache server it's very simple to remove the headers. I do have a question about the docs: http://www.squid-cache.org/Versions/v3/3.4/cfgman/reply_header_access.html Will the reply_header_access will affect the stored cache

Re: [squid-users] Caching based on header/etag

2014-12-11 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 If you have access to the apache server it's very simple to remove the headers. I do have a question about the docs: http://www.squid-cache.org/Versions/v3/3.4/cfgman/reply_header_access.html Will the reply_header_access will affect the stored cache

Re: [squid-users] Maximum Bandwidth a squid server can Handle

2014-12-11 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/11/2014 05:41 PM, Siva Prakash wrote: Squid configuration - For authentication, it is integrated with AD and lots of ACLs(1000) to block sites. Hey, The acls should not be too much of an effect unless they are binded to an external helper.

Re: [squid-users] squid unable to start on CentOS 6.5

2014-12-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Derek, To verify that these boxes has the same settings I would start running the basic_data.sh script at: http://www1.ngtech.co.il/squid/basic_data.sh This script will might find the culprit with the issue pretty fast. I assume you have used

Re: [squid-users] squid unable to start on CentOS 6.5

2014-12-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/23/2014 12:26 AM, Derek Cole wrote: Hello, Yes it is true I am using the RPM repository to do the install. I have downloaded your script and I will see if I can find any differences that may be the culprit. In the meantime I thought I may

Re: [squid-users] squid unable to start on CentOS 6.5

2014-12-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/23/2014 12:49 AM, Derek Cole wrote: Ok - thanks for saving me from chasing that issue down. I am not currently using selinux: Then make sure that selinux is on not on enforced mode and if so the issue might be because of a missing directory

Re: [squid-users] squid unable to start on CentOS 6.5

2014-12-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OK Amos gave you a suggestion which will cover everything but from reading the squid.conf I would first try to understand: What do you want squid to do for you? You need to remove the all acl line and change the http_port from what it is to the

Re: [squid-users] centos 6.x repo

2014-12-22 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Alex, I am not sure what you mean by your question. I am using latest 6.6 as a build node and am trying to use the most up-to-date CentOS version and libs. Downsides? If someone has a 6.5 or older 6 branch system without enough updates to work

Re: [squid-users] https bug slow browsing

2014-12-23 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/24/2014 02:42 AM, HackXBack wrote: so now we have 2 bug 1st one : when upgrading from 3.4.x to 3.5.0.4 squid crash and always restart automatically 2nd one : browsing on https slow = packet dropped and stop loading until refresh in 3.4.x and

Re: [squid-users] https bug slow browsing

2014-12-24 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/24/2014 01:52 PM, HackXBack wrote: the problem is not from my squid.conf because i try minimal squid.conf with https and the same problems Hey, A minimal squid and https interception or bumping doesn't stand in the same place. A minimal

Re: [squid-users] DiskThreadsDiskFile::openDone squid 3.5.0.4

2014-12-27 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/26/2014 02:22 PM, HackXBack wrote: Hello squid , after using 3.5.0.4 on fresh debian system i see many errors in cache.log Hey There, (leaving aside these errors) As a part of a cache proxy integration I am generally recommending to do it in

Re: [squid-users] Hypothetically comparing SATA\SAS to NAS\SAN for squid.

2015-02-03 Thread Eliezer Croitoru
Hey Omid, I do not have benchmarks. I was actually in the past looking at GlusterFS and NFS for couple purposes. The Gigabit and 10Gb have their difference. The main big thing is that a simple SATA\SAS jack\connector\port supports up to 6Gb and in most cases the machine will not utilize even

Re: [squid-users] ssl-bump doesn't like valid web server

2015-02-02 Thread Eliezer Croitoru
Hey Steve, On what OS are you running squid? is it self compiled one? Eliezer On 02/02/2015 14:09, Steve Hill wrote: I'm pretty sure this is incorrect - I'm running Squid 3.4 without ssl_crtd, configured to bump server-first. The cert= parameter to the http_port line points at a CA

Re: [squid-users] Problems with squid 3.5.1

2015-02-07 Thread Eliezer Croitoru
Hey Stefano, Can you get some access.log output from the time the issue appears\happens? Eliezer On 06/02/2015 15:01, Stefano Ansaloni wrote: Tested with icap disabled: the issue still there. ___ squid-users mailing list

Re: [squid-users] Webpages won't load or load slowly

2015-02-03 Thread Eliezer Croitoru
Hey Rich, I am yet unsure about the issue you are having and even if squid 3.3.8 is not the latest most of these sites should work fine for you throw squid. I believe that this is the place where we can take a look at the squid access.log output while surfing to understand the issue better. If

Re: [squid-users] Hypothetically comparing SATA\SAS to NAS\SAN for squid.

2015-02-05 Thread Eliezer Croitoru
Hey Omid, Before buying any NAS or SAN solution you will need to take in account couple things. Squid has an in memory objects index which requires ram and reduces the amount of in memory objects you can store. You will need to first verify that your current machine memory usage can allow you

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Eliezer Croitoru
Hey Anton, If you use https_port with ssl certificate it will be for one of two options: - interception of ssl traffic - reverse proxy with ssl For both cases the connection between the server and the client in the end will be encrypted while non of them is in a forward proxy mode and there

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Eliezer Croitoru
On 03/02/2015 17:14, Anton Radkevich wrote: so just to be clear the connection flow will look like: browser Encrypted Tunnel Server HTTP or HTTPS connection Destination where Encrypted Tunnel is probably some form of HTTPS connection for support with the browser PAC Hey Anton, Squid do not

Re: [squid-users] ssl-bump doesn't like valid web server

2015-01-21 Thread Eliezer Croitoru
On 21/01/2015 11:21, Steve Hill wrote: but not using ssl_crtd What are using if not ssl_crtd? Eliezer ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Squid not redirecting traffic to the internet

2015-01-17 Thread Eliezer Croitoru
Hey Christopher, The email looks a bit messy and so I and I assume others couldn't understand it. You can paste the config file content at: http://pastie.org/ And please first describe the issue and later add more technical data such as config and dumps. All The Bests, Eliezer On

Re: [squid-users] [squid-announce] Squid 3.5.1 is available

2015-01-19 Thread Eliezer Croitoru
On 19/01/2015 15:56, HackXBack wrote: after upgrading to 3.5.1 i have bug BUG 3279: HTTP reply without Date how to solve it ?? To make sure I understand the issue: Is it crashing squid? or just shows a warning in the logs? Thanks, Eliezer ___

Re: [squid-users] Squid 3.4.11 crashing on FreeBSD 10 (64-bit)

2015-01-20 Thread Eliezer Croitoru
On 20/01/2015 21:39, Odhiambo Washington wrote: I know this. I was just mentioning. I think I believe Yuri that IPFilter isn't in FreeBSD. I think I am going to have to suck it in, because I am happy with it in many servers, working nicely with Squid. Hey, From the FreeBSD handbook a list of

Re: [squid-users] Squid latency at ApacheCon 2014 in comparison between Squid, NGINX, Apache Traffic Server, Varnish and Apache

2015-02-17 Thread Eliezer Croitoru
Hey Anna, Thanks for the links and the detailed comments and thoughts. In most cases I am not a friend of countering others if not really needed. I have yet to implement VARNISH or ATS in production and the blame for this is strictly on me since I am a bit spoiled and a learning curve is not

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
Hey Yuri, I would try first ps -aux just to find out if this is the right way to use ps in solaris. If it works show me the details first and we will see what to do next. Eliezer On 16/02/2015 18:37, Yuri Voinov wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yes. root @ cthulhu /

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
On 16/02/2015 17:27, Yuri Voinov wrote: root @ cthulhu / # top -n 1 -b last pid: 43244; load avg: 0.06, 0.07, 0.07; up 7+22:16:44 21:27:15 62 processes: 61 sleeping, 1 on cpu CPU states: 99.3% idle, 0.5% user, 0.2% kernel, 0.0% iowait, 0.0% swap Kernel: 510 ctxsw, 4 trap, 754 intr,

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
On 16/02/2015 21:10, Yuri Voinov wrote: root @ cthulhu / # ps -e Yuri, Can you find the right ps command that will include user and memory usage by each process? Thanks, Eliezer ___ squid-users mailing list squid-users@lists.squid-cache.org

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
Hey Yuri, I looked eventually at Solaris 11 man pages at: http://docs.oracle.com/cd/E26502_01/html/E29030/ps-1.html#scrolltoc Just to be sure the next command would run: ps -e There is no subject to the discussion yet since the issue is yet to be defined as an issue. You mentioned Android

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
Hey Yuri, You missed the whole point. I didn't wanted you to grep any output. I wanted to see the whole server process list as a whole to understand the issue you see. If you see the server only with grep you might missing something since I have yet to see your server do any swap what so ever

Re: [squid-users] can squid handle indirect request from clients ?

2015-02-16 Thread Eliezer Croitoru
Hey, Squid and any other HTTP proxy cannot support basic authentication when it is being used as an intercept proxy. The only options to do such a thing is to use some kind of a captive portal or an external network system which will identify the user directly in a webserver or another way

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
Hey Yuri, There are couple sides and side-effects to the issue you describe. If it's OK with you I will for a sec look aside squid and the helpers code to another issue in Computer Science. Let say we are running some server\software which it's purpose is to calculate the distance from point

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
Hey Yuri, OK I have seen something... Now we might need also the virtual memory which might be vsz. And the cachemgr output is not from squidview.. The last image I have seen from cachemgr was much helpful(with 10 helpers). From what I have seen until now squidGuard uses about 13 MB of ram

Re: [squid-users] Is Squid can shutdown unused idle redirector's children?

2015-02-16 Thread Eliezer Croitoru
On 16/02/2015 15:23, Yuri Voinov wrote: http://i58.tinypic.com/rsqwxh.png 0 shutting down. Always. During nights and weekends. Are you talking about these 10? I am unsure I understand the issue yet..(I need to understand a bit more), is this the situation which stays forever? Eliezer

Re: [squid-users] cache peer load balancing round robin problem

2015-02-16 Thread Eliezer Croitoru
Hey, There are couple things to consider while using multiple IPs for the same network\user. It is possible to do what you want in the OS level and in a way using squid. You should consider first what is the exact effect you want\need and if it can meet reality in usability level. It is not

Re: [squid-users] assertion failed: client_side.cc:1515: connIsUsable(http-getConn())

2015-02-19 Thread Eliezer Croitoru
Hey Dan, The basic rule of thumb in programming lands is script vs compiled code. Where compiled code can be considered very reliable and in most cases tested much more then scripts. I am fearing that there is some race between all sorts of things on runtime which might lead to this failed

Re: [squid-users] assertion failed: client_side.cc:1515: connIsUsable(http-getConn())

2015-02-19 Thread Eliezer Croitoru
the result twice to alter the EXT_LOG and then have the result cached against the altered EXT_LOG. Cheers Dan On 11 Feb 2015, at 11:09 pm, Eliezer Croitoru elie...@ngtech.co.il wrote: Hey Dan, First I must admit that this squid.conf is quite complicated but kind of self explanatory. I have

Re: [squid-users] Squid-3.5.2 and FreeBSD 10.1

2015-02-20 Thread Eliezer Croitoru
On 19/02/2015 11:49, Odhiambo Washington wrote: I have been hoping that 3.5.2 would possibly help address my problems with ACLs, but alas! Sorry for hijacking the thread but the wiki freebsd buildfarm node install page: http://wiki.squid-cache.org/BuildFarm/FreeBsdInstall Doesn't include

Re: [squid-users] can squid handle indirect request from clients ?

2015-02-17 Thread Eliezer Croitoru
Hey, There are couple ways to look at authentication and some would sometimes trade authorization to authentication and vise versa. In some environments there is a mix of both terms which is required to build a logical service unit. I do not have all my archives but I remember that someone

Re: [squid-users] Fwd: Squid 3.4.10 RPMs release for CentOS 32 and 64 bit.

2015-01-24 Thread Eliezer Croitoru
Hey Daniel, If it was not mentioned anywhere else then this thread is the place: CentOS 7 packages are in the Testing phase and will might not be stable enough for production. If you may look at the RPMs my packaging of squid is a bit different then the mainstream. One of the main differences

Re: [squid-users] assertion failed: client_side.cc:1515: connIsUsable(http-getConn())

2015-02-01 Thread Eliezer Croitoru
Hey Dan, Just to get around the environment, can you share your squid.conf?(censuring confidential data) Thanks, Eliezer On 02/02/2015 01:14, Dan Charlesworth wrote: Bumping this one for the new year 'cause I still don't understand squid traces and because it's still happening with v3.4.11.

Re: [squid-users] Squid Authentication

2015-02-02 Thread Eliezer Croitoru
Hey Raju, For how many users? Eliezer On 02/02/2015 06:27, Raju M K wrote: Need squid Authentication syntax for local users in Windows 7/8 workgroup Presently using squid 2.7 stable 8 -- Regards, M K Raju. ___ squid-users mailing list

Re: [squid-users] Squid 3 SSL bump: Google drive application could not connect

2015-01-05 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/05/2015 05:18 PM, Yuri Voinov wrote: We haven't filtering non_HTTP over port-443. Just recognize and pass. So let's separate security which is one of the goals of squid and which some like and other don't. For now squid 3.4 is stable and 3.5

Re: [squid-users] Debugging slow access

2015-01-05 Thread Eliezer Croitoru
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey Steve, Can you share the squid -v output and the OS you are using? Eliezer On 01/05/2015 06:29 PM, Steve Hill wrote: On 10.12.14 17:09, Amos Jeffries wrote: I'm looking for advice on figuring out what is causing intermittent high CPU

Re: [squid-users] ssl cert wiki

2015-01-12 Thread Eliezer Croitoru
Can you try to use openssl s_client? an exapmple: openssl s_client -connect facebook.com:443 Eliezer On 12/01/2015 11:41, HackXBack wrote: hello, according to this chapter http://wiki.squid-cache.org/ConfigExamples/Reverse/SslWithWildcardCertifiate i bought signed certificate but no one

Re: [squid-users] ssl cert wiki

2015-01-12 Thread Eliezer Croitoru
Are you using the command with facebook.com??? You should use your own server... Eliezer On 12/01/2015 13:02, HackXBack wrote: openssl s_client -connect facebook.com:443 -CApath /var/squid/ssl_db/certs CONNECTED(0003) depth=2 C = US, O = DigiCert Inc, OU =www.digicert.com, CN = DigiCert

Re: [squid-users] ssl cert wiki

2015-01-12 Thread Eliezer Croitoru
Just to make sure I understand it right. The certificate is for a reverse proxy? Eliezer On 12/01/2015 11:41, HackXBack wrote: hello, according to this chapter http://wiki.squid-cache.org/ConfigExamples/Reverse/SslWithWildcardCertifiate i bought signed certificate but no one accept rsa:1024

Re: [squid-users] ssl cert wiki

2015-01-12 Thread Eliezer Croitoru
Hey, This is not a reverse proxy... It's a ssl-bump server and which you cannot use any bought certificate for it. Eliezer On 12/01/2015 13:20, HackXBack wrote: https_port 3127 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_cert/CA.pem

Re: [squid-users] ssl cert wiki

2015-01-12 Thread Eliezer Croitoru
Hey hack, From the comments in the past I am unsure what you are after... If you are using ssl-bump you should first learn about how ssl works and about the differences between encrypted traffic to verification of a public key. I must admit that these topic are not marked as an easy one.

Re: [squid-users] {Disarmed} Re: site cannot be accessed

2015-01-12 Thread Eliezer Croitoru
Hey, Did you had the chance to see this page: http://findproxyforurl.com/example-pac-file/ Eliezer On 13/01/2015 06:22, Simon Dcunha wrote: Dear Sarfraz, appreciate your immediate reply Heres attached is my pac file i am accessing the 10.101.101.10 server regards simon

Re: [squid-users] {Disarmed} Re: site cannot be accessed

2015-01-13 Thread Eliezer Croitoru
Hey, Since you provided the pac file I had the chance to convert it into a more suitable format to my flavor. Can you try the wpad file at: http://www1.ngtech.co.il/tests/wpad.dat Eliezer On 13/01/2015 06:22, Simon Dcunha wrote: Dear Sarfraz, appreciate your immediate reply Heres attached

Re: [squid-users] Problems with squid 3.5.1

2015-02-11 Thread Eliezer Croitoru
On 11/02/2015 12:17, Yuri Voinov wrote: Fred, this is no matter. Millions of files can remove with one piped command: *find . |xargs rm :) * And it should be used wisely! Any recommendation to run rm should take in account that the rm can in a way wipe out files which you might not

Re: [squid-users] Problems with squid 3.5.1

2015-02-11 Thread Eliezer Croitoru
On 05/02/2015 11:17, FredB wrote: Squid Cache: Version 3.5.1-20150201-r13744 Service Name: squid configure options: '--build=x86_64-linux-gnu' '--prefix=/' '--includedir=${prefix}/include' '--mandir=${prefix}/share/man' '--infodir=${prefix}/share/info' '--sysconfdir=/etc'

Re: [squid-users] assertion failed: client_side.cc:1515: connIsUsable(http-getConn())

2015-02-11 Thread Eliezer Croitoru
Hey Dan, First I must admit that this squid.conf is quite complicated but kind of self explanatory. I have tried to understand the next lines: # File size (download) restrictions acl response_size_100 external response_size_type 100 192.168.0.10 http_access allow response_size_100

Re: [squid-users] kid registration timed out

2015-02-08 Thread Eliezer Croitoru
On 08/02/2015 01:32, Alfredo Rezinovsky wrote: Specially in servers with 6 workers and 6 cache discs (Each worker has a cache_dir in each disc for IO balancing) What cache_dir settings are you using there? Eliezer ___ squid-users mailing list

Re: [squid-users] ssl proxy error: No valid signing SSL certificate configured for https_port [::]:3127

2015-02-15 Thread Eliezer Croitoru
On 15/02/2015 23:36, Alan Palmer wrote: I'm trying to get squid 3.4.11 on openbsd 5.6 to act as a transparent ssl proxy. I've rebuilt squid with --enable-ssl-crtd, generated my own self signed cert (ala http://www.akadia.com/services/ssh_test_certificate.html) and have the following config

Re: [squid-users] Problems with squid 3.5.1

2015-02-04 Thread Eliezer Croitoru
Is it happening on all websites? or a specific one? I am using 3.4.11 for most of my daily uses now. In order to reproduce it I will need the OS and version, and if I assume it is a self compiled so the squid -v details. Eliezer On 04/02/2015 12:22, FredB wrote: I have some issue with

Re: [squid-users] Debugging slow access

2015-01-07 Thread Eliezer Croitoru
Hey Steve, First of all thanks for all the notes. You made it possible to look at the bug before I understood how to reproduce it. I would like for the record to make sure we can reproduce it just for the tests list that I will add later to newer releases. Can you give me the details about

Re: [squid-users] Growing cache.log

2015-01-07 Thread Eliezer Croitoru
Hey (Is it Jerome? or Vernet?), Is there a chance you can test it with a newer version of squid? What OS are you using? Can you share your squid.conf? Eliezer On 06/01/2015 14:38, Vernet Jerome wrote: Hi, Since yesterday, my Squid cache.log grow very fast, about 250Mb per hour. Lot of

Re: [squid-users] Debugging slow access

2015-01-05 Thread Eliezer Croitoru
it as the source. If you can add the new details about the issue in the bug report it will help a lot. Eliezer On 01/05/2015 07:48 PM, Steve Hill wrote: On 05.01.15 16:35, Eliezer Croitoru wrote: Can you share the squid -v output and the OS you are using? Scientific Linux 6.6, see below for the squid -v

Re: [squid-users] Squid 3 SSL bump: Google drive application could not connect

2015-01-04 Thread Eliezer Croitoru
but... a NFQUEUE helper that can verify if to FORWARD or BUMP the connection would be a better suited solution to my opinion. All The Bests, Eliezer Croitoru On 01/05/2015 03:07 AM, Douglas Davenport wrote: Seems to me it would be more useful as an external ACL so that a decision could be made based

Re: [squid-users] Squid will not authenticate NTLM/Kerberos when behind a haproxy load balancer

2015-03-19 Thread Eliezer Croitoru
Hey Samuel, Not related to your post at squid-cache, I have tried to access your site from my testing grounds and I do not seem to be able to access it. Not even an ICMP echo ping. It is maybe something in the route between my client to your server but I was wondering if I should contact my

Re: [squid-users] WARNING: 1 swapin MD5 mismatches and BUG 3279: HTTP reply without Date:

2015-03-19 Thread Eliezer Croitoru
Hey Dan and John, If indeed this bug is only for UFS\AUFS cache_dir then I would try to make sure that large-rock will not sustain the same issue. I have not seen in any of the bug reports anything that would reproduce the issue. To make sure the issue is understood and can or cannot be

Re: [squid-users] WARNING: 1 swapin MD5 mismatches and BUG 3279: HTTP reply without Date:

2015-03-21 Thread Eliezer Croitoru
Alberto, What are the details of the machine? Can you run the next script on the machine? http://ngtech.co.il/squid/basic_data.sh Eliezer On 20/03/2015 05:37, Alberto Perez wrote: Another one here not using SMP, and using aufs. I stopped seen this issue frequently when I reduced my cache

Re: [squid-users] Access Problem to VMWARE, IBM and Truste.com through Squid

2015-03-16 Thread Eliezer Croitoru
infrastructure is designed and implemented and which I know nobody planned to show me. All The Bests, Eliezer Croitoru On 03/10/2013 13:26, Babelo Gmvsdm wrote: Hi, First of all Thx Amos for your enlightenment, even if I had to admit that it's not yet all clear for me, My knowledge of proxy is very light

Re: [squid-users] Whether squid 3.5.2 can support rock at wccp tproxy environment really ?

2015-03-11 Thread Eliezer Croitoru
Hey, I was left in the dark and still unsure what the situation is?? Did you made it work fine? Eliezer On 11/03/2015 11:09, johnzeng wrote: Hello Amos: Ok, I see Thanks again. Have a good day with

Re: [squid-users] One Time Password with squid, exists?

2015-03-13 Thread Eliezer Croitoru
On 13/03/2015 05:22, Daniel Greenwald wrote: Ah that would be a clever way to implement pki authentication but i was thinking of something more that browser natively support.. Hey Daniel, What is the direction of what you are thinking about? I do not know about a browser natively support

Re: [squid-users] One Time Password with squid, exists?

2015-03-12 Thread Eliezer Croitoru
Hey Hack, I wsa talking about radius server like free radius. Which by the way dmasoftlab uses in their product\s. Eliezer On 12/03/2015 07:14, HackXBack wrote: are you talking about radius server like free radius ? or like dmasoftlab.com ? ___

Re: [squid-users] One Time Password with squid, exists?

2015-03-11 Thread Eliezer Croitoru
Thanks Amos, So NTLM has two steps authentication which means that there is a basic negotiation over the http connection to the proxy which makes it less secure then kerberos. (speculating) The main reason it's less secure then kerberos is that every part of the password negotiation steps

[squid-users] One Time Password with squid, exists?

2015-03-11 Thread Eliezer Croitoru
wrong passwords should be considered a cracking trial? If you have more ideas about the subject I would be happy to see them here. Thanks In Advance, Eliezer Croitoru ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org

Re: [squid-users] i want to block images with size more than 40 KB

2015-03-24 Thread Eliezer Croitoru
and we are here to help them and all the other humans that are on the plant in this case that a mistake is happening. Eliezer Croitoru On 24/03/2015 23:46, Yuri Voinov wrote: So far, this has not been done. You can be the first!;) ___ squid-users

Re: [squid-users] mmap() in squid

2015-03-31 Thread Eliezer Croitoru
Hey Eugene, Since I do not have the full details about the issue and related areas I cannot answer and I think later others will answer this better then me. But as for the last question about squid being a DB. Squid in a way is also a DB like any OS is a DB. Due to the fact that squid is kind

Re: [squid-users] i meet a problem , --- Unsupported Request Method and Protocol'' for such connections ( non-HTTP connections ) based 80 port ----, if possible , please give me some advisement or hel

2015-02-28 Thread Eliezer Croitoru
confidential information) All The Bests, Eliezer Croitoru On 28/02/2015 05:18, johnzeng wrote: Hi all : i meet a problem ,Squid cannot currently deal with such connections ( non-HTTP connections ) based 80 port , and We get some error , Unsupported Request Method and Protocol'' for https URLs

Re: [squid-users] 3.5.2 Basic LDAP auth is missing

2015-02-27 Thread Eliezer Croitoru
Hey Donny, What OS are you using? Eliezer On 27/02/2015 06:41, Donny Vibianto wrote: is there any change in 3.5.2 regarding basic ldap auth? i cant find ldap helpder in my helper list. Squid Cache: Version 3.5.2 Service Name: squid configure options: '--enable-basic=LDAP'

Re: [squid-users] TProxy and client_dst_passthru

2015-03-03 Thread Eliezer Croitoru
Hey Fred, It is unclear what doesn't work for you. What would you expect to work and how it works or doesn't work from a user perspective rather then an admin? Is there any trouble from the user side about this issue? Eliezer On 04/03/2015 00:14, Stakres wrote: Hi All, Does someone know

Re: [squid-users] question about encrypted connection between https client and Squid

2015-03-01 Thread Eliezer Croitoru
Hey Yuri, On 01/03/2015 20:17, Yuri Voinov wrote: Normally you never use CONNECT method over HTTP ports. This is prohibited by squid basic security requirements. The above statement is true only if the proxy admin prohibit this. A CONNECT method can be allowed and can be used for any purpose

Re: [squid-users] squid 3.5.2 compile error on openbsd5.6

2015-02-21 Thread Eliezer Croitoru
Hey Alan, I am unsure but is this SSL library headers files are compatible with OpenSSL or it would require some existing OpenSSL APIs calls changes? Eliezer On 21/02/2015 17:00, Alan Palmer wrote: [apalmer]:/data/src/squid-3.5.2# openssl version LibreSSL 2.0 Alan Palmer DO NOT SPAM

Re: [squid-users] One Squid proxy for multi-tenant environment

2015-02-21 Thread Eliezer Croitoru
On 22/02/2015 02:47, maxt wrote: Each tenant has a unique domain that has a trust relationship with our management domain. They also have a unique IP address range so there is no need for VLANS. Hey Max, You can use deny_info with a specific ip range or ip list and somehow make acls that

Re: [squid-users] Need tips in order to force youtube in HTTP only

2015-02-22 Thread Eliezer Croitoru
On 22/02/2015 13:56, Amos Jeffries wrote: The google page about forcing safesearch currently recommends hijacking DNS. Which may also work for YouTube but its not clear. I must mention also: If only youtube is the issue, there is an idea to pre-identify these dns requests and only ssl-bump

  1   2   3   4   5   6   7   8   9   10   >