Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-10 Thread Victor Sudakov
Markus Moeller wrote: > > > What if the service principal's name in squid's keytab does not > > coincide with the host's primary FQDN (AKA `hostname`)? > > > > E.g. the squid's keytab contains keys for HTTP/proxy.my.domain while > > the server's actual FQDN is fw.my.domain? > > > > Should it cau

Re: [squid-users] blockVirgin Works for CONNECT but Custom Response does not work

2014-10-10 Thread Jatin Bhasin
Hi Alex, I changed my ACL's a bit to see annotations in access.log file. My web browser is point to squid port 3127. So squid.conf is as below: (first two lines are for note logging as you suggested.) - logformat with_note %ts.%03tu %6tr %>a %Ss/%03>Hs

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-10 Thread Markus Moeller
I think it could. Can you try the option -s GSS_C_NO_NAME ? Markus "Victor Sudakov" wrote in message news:20141010113630.ga39...@admin.sibptus.tomsk.ru... Colleagues, What if the service principal's name in squid's keytab does not coincide with the host's primary FQDN (AKA `hostname`)? E.g

Re: [squid-users] I need a help with user permissions credentials

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/10/2014 5:31 a.m., Juan Manuel Perrote wrote: > > Any body can help me ? See my previous answer. When you configure Squid to do something *it happens*. Please do not complain that Squid is doing *exactly* what you configured it to do. Amos

Re: [squid-users] problem with basic_ldap_auth

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/10/2014 5:30 a.m., masterx81 wrote: > I've noticed that also others had problems on 3.4.x with high cpu > usage using ntlm auth, and i would be happy to help and support the > project. But i don't know too much about linux (are only few month > t

Re: [squid-users] SSL bump , high memory usage

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/10/2014 5:26 a.m., Steve Hill wrote: > > I think I've identified the bulk of the memory "leak" I've been > tracking down for the past few days. As it turns out, it doesn't > seem to be a leak, but a problem with the SSL certificate caching. >

Re: [squid-users] unexplained MISSes

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/10/2014 5:00 a.m., Josep Borrell wrote: > Hi, > > I'm trying build a squid server that can cache youtube request for > a school. I'm using squid 3.4.7 compiled from source on Ubuntu > server 14.04 I have a lot of request that are cached, but not

Re: [squid-users] problem with basic_ldap_auth

2014-10-10 Thread masterx81
I've noticed that also others had problems on 3.4.x with high cpu usage using ntlm auth, and i would be happy to help and support the project. But i don't know too much about linux (are only few month that i play with it) and know squid only a bit. I not know if i can be much useful. And the system

[squid-users] I need a help with user permissions credentials

2014-10-10 Thread Juan Manuel Perrote
Any body can help me ? We use external authentification on ldap repository on a remote machine, and have a problem when use a ttl time, the proxy require to validate very frequently to all users. external_acl_type ldap_group %LOGIN /usr/lib/squid3/squid_ldap_group -b "ou=Groups,dc=vs-zmaste

[squid-users] SSL bump , high memory usage

2014-10-10 Thread Steve Hill
I think I've identified the bulk of the memory "leak" I've been tracking down for the past few days. As it turns out, it doesn't seem to be a leak, but a problem with the SSL certificate caching. The certificate cache is set by dynamic_cert_mem_cache_size and defaults to 4MB. Squid assumes an S

[squid-users] unexplained MISSes

2014-10-10 Thread Josep Borrell
Hi, I'm trying build a squid server that can cache youtube request for a school. I'm using squid 3.4.7 compiled from source on Ubuntu server 14.04 I have a lot of request that are cached, but not served from cache and generate a TCP_MISS/200 I'm trying to figure why this requests are not served f

Re: [squid-users] 501 error within a webpage

2014-10-10 Thread Haza1981
If I specify our tmg proxy instead the 500 error does not appear. Instead they have clickable links there. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/500-internal-error-within-a-webpage-tp4667798p4667805.html Sent from the Squid - Users mailing list arc

Re: [squid-users] blockVirgin Works for CONNECT but Custom Response does not work

2014-10-10 Thread Alex Rousskov
On 10/09/2014 11:57 PM, Jatin Bhasin wrote: > adaptation_masterx_shared_names X-Virus-ID > acl toBump note X-Virus-ID yes > ssl_bump client-first toBump OK. > My eCap adapter functions which returns yes for the X-Virus-ID are: > =

Re: [squid-users] problem with basic_ldap_auth

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/10/2014 9:44 p.m., masterx81 wrote: > Nothing to do, seem that if squid fails one of the > negotiate_wrapper methods doesn't use any other method, asking that > password (that as you say isn't a basic auth, as the realm part > isn't displayed). I

Re: [squid-users] 501 error within a webpage

2014-10-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/10/2014 10:56 p.m., Haza1981 wrote: > We are having issues with users using a webpage they require > (ondemand.bond.co.uk). They can log in and see most of what they > use but certain sections of the page just say error 501. > > I have checked

Re: [squid-users] blockVirgin Works for CONNECT but Custom Response does not work

2014-10-10 Thread Jatin Bhasin
Hi Alex, Looking at cache.log I see that X-Virus-ID is set to yes but the eCap adapter functions. But I do not know that how it will be picked up note acl. Please suggest. 2014/10/10 22:50:55.341 kid1| HttpHeader.cc(1272) putExt: 0x7fff1d656f80 adds ext entry X-Virus-ID : yes 2014/10/10 22:50:55

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-10 Thread Victor Sudakov
Colleagues, What if the service principal's name in squid's keytab does not coincide with the host's primary FQDN (AKA `hostname`)? E.g. the squid's keytab contains keys for HTTP/proxy.my.domain while the server's actual FQDN is fw.my.domain? Should it cause the obscure error I have stumbled up

Re: [squid-users] problem with basic_ldap_auth

2014-10-10 Thread masterx81
Ok, i've tried to comment out and leave only one helper at time, and i can get work only one helper. If i have only basic helper, and other commented out, it work (asking the password with the correct realm text), but if i enable other helpers, only work the one that is first in order on the conf f

[squid-users] 501 error within a webpage

2014-10-10 Thread Haza1981
We are having issues with users using a webpage they require (ondemand.bond.co.uk). They can log in and see most of what they use but certain sections of the page just say error 501. I have checked the access log and see the following information in some lines. TCP_MISS/501 295 DELETE (website

Re: [squid-users] redirect all ports to squid

2014-10-10 Thread Squid
Hi, Yes, we can redirect the ports to squid through our firewall rules. Check below lines to redirect the ports. We have some different methods to do. 1. In first Method: First, we need to machine that squid will be running on, You do not need iptables or any special kernel options on this

Re: [squid-users] problem with basic_ldap_auth

2014-10-10 Thread masterx81
Nothing to do, seem that if squid fails one of the negotiate_wrapper methods doesn't use any other method, asking that password (that as you say isn't a basic auth, as the realm part isn't displayed). In the logs i get only negotiate_wrapper events. I've also tried to comment out the pure ntlm and