Re: [squid-users] squid 2.7 TPROXY not working

2014-10-20 Thread saleh madi
Hello Amos, Many thanks for your reply. Before two years I have tested squid 2.7 it's very stable and in the high http traffic request is very stable no crash. But for squid-3 I see too many different releases 3.0.x , 3.1.x, 3.2.x, 3.3.x and the current 3.4.x. What is the stable release in squi

Re: [squid-users] R: Re: Skype settings

2014-10-20 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 21/10/2014 7:04 p.m., Riccardo Castellani wrote: > I'm saying about Skype settings in 'tools' - 'connection options' > menu, I'm confused how to set Skype ports if I'm using Squid as > proxy server. If you need other info I'm ready to explain ... A

Re: [squid-users] squid 2.7 TPROXY not working

2014-10-20 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 21/10/2014 6:55 p.m., saleh madi wrote: > Hello, > > I have compiled squid 2.7stable9 with TPROXY patch, but the TPROXY > seem not working. Er, yes. The "TPROXY patch" is not a Squid patch, it is a Linux kernel patch adding TPROXY/cttproxy support

[squid-users] R: Re: Skype settings

2014-10-20 Thread Riccardo Castellani
I'm saying about Skype settings in 'tools' - 'connection options' menu, I'm confused how to set Skype ports if I'm using Squid as proxy server. If you need other info I'm ready to explain ... >Messaggio originale >Da: squ...@treenet.co.nz >Data: 21-ott-2014 7.39 >A: >Ogg: Re: [squid-us

[squid-users] squid 2.7 TPROXY not working

2014-10-20 Thread saleh madi
Hello, I have compiled squid 2.7stable9 with TPROXY patch, but the TPROXY seem not working. The traffic arrived to squid, but when I try to open a website from the client browser I got no response "time Out". Note: traffic forwarder is Cisco Router with PBR (Policy Based Routing). Please see

Re: [squid-users] Skype settings

2014-10-20 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 21/10/2014 6:25 p.m., Riccardo Castellani wrote: > I'm using Squid and it's unique access to go out to Internet. I > created rules for Skype traffic but I'd like to understand how to > set its ports because my unique access way to Intenret is proxy

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-20 Thread Victor Sudakov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Eliezer Croitoru wrote: > > Hopefully I can interest our Windows admin to enable Kerberos > > event logging per KB262177. > > > > But for the present I have found an ugly workaround. In squid's > > keytab, I created another principal called 'squiduser

[squid-users] Skype settings

2014-10-20 Thread Riccardo Castellani
I'm using Squid and it's unique access to go out to Internet. I created rules for Skype traffic but I'd like to understand how to set its ports because my unique access way to Intenret is proxy on 3128. I have firewall which is block all ports. My settings: Use port X for incoming connecti

[squid-users] Squid 3.5.0.1 beta is available

2014-10-20 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The Squid Software Foundation is very pleased to announce the availability of the Squid-3.5.0.1 beta release! Thats right! The Squid Software Foundation is now formally in place as copyright representative (Squid remains GPLv2+ with hundreds

Re: [squid-users] question on compile squid 3.3.3 with --enable-ecap option on cygwin

2014-10-20 Thread lionx...@gmail.com
Thank you very much. I made it. I installed pkg-configļ¼Œthen I copy libecap.pc to /lib/pkgconfig dir. Next, I will test it. PS. You are right. It's not a good idea. I remember. lionx...@gmail.com From: Amos Jeffries Date: 2014-10-21 09:28 To: squid-users Subject: Re: [squid-users] question o

Re: [squid-users] question on compile squid 3.3.3 with --enable-ecap option on cygwin

2014-10-20 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 20/10/2014 7:59 p.m., lionxyes wrote: > > Hi. > > A few days ago I compiled squid-3.3.3 successfully on cygwin , then > I also compiled ecap-0.2.0 successfully on cygwin because I want > compiled squid-3.3.3 with --enable-ecap option on cygwin. >

Re: [squid-users] infinite loop on using SSL to connect to squid with ssl-bump

2014-10-20 Thread Jason Haar
On 21/10/14 12:24, Alex Rousskov wrote: > On 10/20/2014 04:22 PM, Jason Haar wrote: > >> Both Chrome and Firefox support talking to proxies using SSL (wpad type >> "HTTPS" instead of "PROXY"). > I did not know that support was added to major browsers. Any pointers to > the relevant configuration k

Re: [squid-users] infinite loop on using SSL to connect to squid with ssl-bump

2014-10-20 Thread Alex Rousskov
On 10/20/2014 04:22 PM, Jason Haar wrote: > Both Chrome and Firefox support talking to proxies using SSL (wpad type > "HTTPS" instead of "PROXY"). I did not know that support was added to major browsers. Any pointers to the relevant configuration knobs? Can it be configured without WPAD? > I'm

[squid-users] infinite loop on using SSL to connect to squid with ssl-bump

2014-10-20 Thread Jason Haar
Hi there Both Chrome and Firefox support talking to proxies using SSL (wpad type "HTTPS" instead of "PROXY"). I'm trying to test that out against my ssl-bump enabled squid proxy and it's causing an infinite loop Basically if I do something like (sleep 2;echo -ne "GET http://slashdot.org/ HTTP/1.

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-20 Thread Eugene M. Zheganin
Hi. On 20.10.2014 22:29, Victor Sudakov wrote: That's what we did. 1. Created an AD user called squiduser. 2. Extracted its keytab with something like ktpass -princ HTTP/proxy.sibptus.transneft...@sibptus.transneft.ru -mapuser squiduser +rndPass -out squid.keytab -ptype KRB5_NT_PRINCIPAL /t

Re: [squid-users] Squid, Kerberos and FireFox (Was: Re: leaking memory in squid 3.4.8 and 3.4.7.)

2014-10-20 Thread Victor Sudakov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Eugene M. Zheganin wrote: > > > > Hopefully I can interest our Windows admin to enable Kerberos event > > logging per KB262177. > > > > But for the present I have found an ugly workaround. In squid's keytab, I > > created another principal called 'squi

Re: [squid-users] Negotiate bug in squidclient ?

2014-10-20 Thread Victor Sudakov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Amos Jeffries wrote: > > That is a bug. Please add to bugzilla. http://bugs.squid-cache.org/show_bug.cgi?id=4123 - -- Victor Sudakov, VAS4-RIPE, VAS47-RIPN sip:suda...@sibptus.tomsk.ru -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGB

Re: [squid-users] TCP_DENIED/403 after Upgrading from 3.4.4 to 3.4.7 (ssl_bump enabled)

2014-10-20 Thread Tom Tom
Entry created in bugzilla: http://bugs.squid-cache.org/show_bug.cgi?id=4122 On Mon, Oct 20, 2014 at 7:25 AM, Amos Jeffries wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 20/10/2014 6:18 p.m., Tom Tom wrote: >> Hi Amos >> >> Do you have new findings? Should I open a bug for bett

[squid-users] question on compile squid 3.3.3 with --enable-ecap option on cygwin

2014-10-20 Thread lionx...@gmail.com
Hi. A few days ago I compiled squid-3.3.3 successfully on cygwin , then I also compiled ecap-0.2.0 successfully on cygwin because I want compiled squid-3.3.3 with --enable-ecap option on cygwin. Firstly, I edit squid.cygport file to add --enable-ecap option. https://onedrive.live.com/redir?