Re: [squid-users] transparent proxy https and self signed certificate error

2014-10-04 Thread Jason Haar
On 05/10/14 18:44, Amos Jeffries wrote: > PS. Google with Chrome appear these days to be the champions of > unbreakable TLS, their software is continually being updated to > use/invent new TLS features that close loopholes in TLS design which > allow ssl-bump to take place. What worked last month h

Re: [squid-users] transparent proxy https and self signed certificate error

2014-10-04 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/10/2014 1:29 p.m., Robert Watson wrote: > using squid 3.4.8, compiled from source with ./configure flags > --enable-icap-client --enable-ssl --enable-ssl-crtd configured > iptables for transparent proxy (redirect 80 to 3128) and everything > work

[squid-users] RPM Packages

2014-10-04 Thread John Gardner
This question is probably specifically for Eliezer. My question is this, On the RPM repository at http://www1.ngtech.co.il/rpm/ There is an RPM package for version 3.4.5 for Oracle Linux 6. I installed this a few months ago when I was preparing to go live with a new Squid instance and now after a

Re: [squid-users] Best OS for latest squid

2014-10-04 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/10/2014 4:49 p.m., Douglas Davenport wrote: > I'm starting from scratch with an AWS based squid setup, I would > like to be able stay up to date with the latest squid releases to > have all the sslbump fixes. Can someone suggest what is best to >

[squid-users] Best OS for latest squid

2014-10-04 Thread Douglas Davenport
I'm starting from scratch with an AWS based squid setup, I would like to be able stay up to date with the latest squid releases to have all the sslbump fixes. Can someone suggest what is best to use, Centos 6, Ubuntu 14 or another distro? I see a lot of the binary releases lag behind, does squid bu

[squid-users] transparent proxy https and self signed certificate error

2014-10-04 Thread Robert Watson
using squid 3.4.8, compiled from source with ./configure flags --enable-icap-client --enable-ssl --enable-ssl-crtd configured iptables for transparent proxy (redirect 80 to 3128) and everything works fine configured iptables for transparent proxy (redirect 443 to 3127) but can't get transparent pr

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Marcus Kool
I suspect that the language setting is causing it. If $LANG is different from "C" it may have a huge impact on the performance of regular expression evaluation (not only in Squid but also awk, sed etc.) Try this: LANG=C /etc/init.d/squid start and see if Squid improves. Marcus > Hi, > > I have

Re: [squid-users] redirect all ports to squid

2014-10-04 Thread Oleg Motienko
Hello, AFAIK it is possible to use redocks software ( http://darkk.net.ru/redsocks/ ) with squid. On Wed, Oct 1, 2014 at 1:49 AM, James Harper wrote: >> >> It's possible to redirect all ports to squid ? thru iptables ? >> For example port 25 smtp,143 imap, etc... >> Can squid handle that. In tra

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Omid Kosari
Thanks a lot . The latest file with your helps is here http://pastebin.com/8yytTWqA Any other tricks appreciated . -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/High-cpu-usage-by-re-search-internal-tp4667550p4667661.html Sent from the Squid - Users mailin

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/10/2014 4:12 a.m., Amos Jeffries wrote: > On 5/10/2014 3:34 a.m., Omid Kosari wrote: >> Mehdi Sarmadi wrote >>> Hey >>> >>> Alright. About refresh pattern you have a very excessive list >>> IMHO. I don't know about your hardware but generally fo

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/10/2014 3:34 a.m., Omid Kosari wrote: > Mehdi Sarmadi wrote >> Hey >> >> Alright. About refresh pattern you have a very excessive list >> IMHO. I don't know about your hardware but generally for a >> typical general purpose SMB server hardware, t

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Omid Kosari
Mehdi Sarmadi wrote > Hey > > Alright. About refresh pattern you have a very excessive list IMHO. I > don't know about your hardware but generally for a typical general purpose > SMB server hardware, that's too much. If you want to stick with it and > can't reduce the list. > Check, how many core

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Omid Kosari
Thanks . I did it . When all refresh_pattern lines commented except following default ones refresh_pattern ^ftp: 144020% 10080 refresh_pattern ^gopher:14400% 1440 refresh_pattern -i (/cgi-bin/|\?) 0 0% 0 refresh_pattern . 0 20% 4

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/10/2014 1:04 a.m., Omid Kosari wrote: > Hi, > > I have 2 squid boxes . Same version,OS and almost same > config,hardware . Both have same problem also . normally cpu usage > by squid is very high . I have tried this guide > http://wiki.squid-cach

Re: [squid-users] High cpu usage by re_search_internal

2014-10-04 Thread Omid Kosari
Hi, I have 2 squid boxes . Same version,OS and almost same config,hardware . Both have same problem also . normally cpu usage by squid is very high . I have tried this guide http://wiki.squid-cache.org/SquidFaq/SquidProfiling and found more than 85% of cpu usage is by re_search_internal symbol na

Re: [squid-users] redirect all ports to squid

2014-10-04 Thread Squid
Spam detection software, running on the system "master.squid-cache.org", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content p

Re: [squid-users] redirect all ports to squid

2014-10-04 Thread Squid
Spam detection software, running on the system "master.squid-cache.org", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content p

Re: [squid-users] redirect all ports to squid

2014-10-04 Thread Visolve Squid
Spam detection software, running on the system "master.squid-cache.org", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content p