Re: [squid-users] Local port number logging woes

2015-01-22 Thread Carl-Daniel Hailfinger
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Amos, thanks a lot for your answer. On 22.01.2015 05:22, Amos Jeffries wrote: > On 22/01/2015 7:00 a.m., Carl-Daniel Hailfinger wrote: > > I'm using cascaded/hierarchical Squid instances, one per machine. > > [...] > > > This works great except f

[squid-users] SOLVED / Re: squid-3.5.x / Ipc::Mem::Segment::create failed to shm_open(/squid-cf__metadata.shm): (38) Function not implemented

2015-01-22 Thread Frank Reppin
Hi all, ok - got it sorted after digging through older linux vserver irclogs... Solution was to add: none /dev/shm tmpfs rw,nosuid,nodev,noexec 0 0 to '/etc/vservers/testbed/fstab' and to obviously restart the vserver afterwards. It now starts up just fine (and seems to work). cheers, fra

[squid-users] squid-3.5.x / Ipc::Mem::Segment::create failed to shm_open(/squid-cf__metadata.shm): (38) Function not implemented

2015-01-22 Thread Frank Reppin
Hi all, we're following 3.4.x (currently 3.4.11) closely and decided to upgrade to 3.5.1 in a test environment today: Environment (test+production) is linux vserver based: host system: Debian Wheezy 7.8 x64 guest system:Debian Wheezy 7.8 x64 kernel+vs patch: 3.14.27-vs2.3.6.14 an

Re: [squid-users] FATAL: The ssl_crtd helpers are crashing too rapidly, need help!

2015-01-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Many? This can be word length of 32/64 bits issue. Check with file and ldd utilities your ssl_crtd openssl, openssl libraries and correct LD_LIBRARY_PATH if necessary. 22.01.2015 18:17, HackXBack пишет: > hello, > every day i found this error and m

[squid-users] FATAL: The ssl_crtd helpers are crashing too rapidly, need help!

2015-01-22 Thread HackXBack
hello, every day i found this error and my cache stop then i remove the ssl database then restart squid next day the problem happen again , am using squid 3.4.11 what may cause this problem ? thanks. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/FATAL-

Re: [squid-users] Squid as reverse proxy and image theft protection

2015-01-22 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 22/01/2015 10:25 p.m., th...@sdf.org wrote: > Dear Jeffries, > > I thank you for your answer. Is possible in your opinion manage > also Cookie with an expiration time? Because if I understood > correctly your suggestion works great until the users

Re: [squid-users] Squid as reverse proxy and image theft protection

2015-01-22 Thread thane
Dear Jeffries, I thank you for your answer. Is possible in your opinion manage also Cookie with an expiration time? Because if I understood correctly your suggestion works great until the users share with some attacker the cookie. The attacker could reuse this cookie to download freely the images

Re: [squid-users] ssl-bump doesn't like valid web server

2015-01-22 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 22/01/2015 8:20 p.m., Steve Hill wrote: > On 21/01/15 18:39, Eliezer Croitoru wrote: > >>> but not using ssl_crtd >> What are using if not ssl_crtd? > > Squid generates the certificates internally if ssl_crtd isn't > turned on at compile time. I'