[squid-users] hi , i don't receive any info from squid-users@lists.squid-cache.org now

2015-04-06 Thread johnzeng
HI Amos : hi , i don't receive any info from squid-users@lists.squid-cache.org now , if possible , please help me to check . Best Regards john ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid

[squid-users] help with tcp_outgoing_address trying to balace traffic based on username

2015-04-06 Thread Alberto Perez
Hi everyone I've been trying to make a traffic load balancing between two links based on username using tcp_outgoing_address My squid setup only use authorization with an external_acl which returns the username based on the client ip. In my first failure trying to setup this, I found (with the he

Re: [squid-users] Possible-Spam a question about Dns lookup

2015-04-06 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yep, especially with Unbound :) 07.04.15 2:29, Lawrence Pingree пишет: > > Unless you are doing authoritative DNS lookups, you may only want to use a caching forwarder like dnsmasq. Also, squid's ipcache_size parameter can be tweaked to cache mor

Re: [squid-users] Possible-Spam a question about Dns lookup

2015-04-06 Thread Lawrence Pingree
Unless you are doing authoritative DNS lookups, you may only want to use a caching forwarder like dnsmasq. Also, squid's ipcache_size parameter can be tweaked to cache more dns responses. Disabling internal DNS would actually hinder performance in most cases. -Original Message- From:

Re: [squid-users] Random SSL bump DB corruption

2015-04-06 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: This line: ssl_bump server-first all in config is from 3.4.x, in 3.5.x you must use new bump syntax. Also: - -what openssl/gnutls version used to build squid? - -Is sslproxy_capath contains really complete set of root/intermediate CA's c

Re: [squid-users] Random SSL bump DB corruption

2015-04-06 Thread Stakres
Hi All, Yury, Facing the same problem at the moment with the squid 3.5.3, around 150 req/sec. The SSL crash 5 min later with the error. index.txt: V 15062300Z 7EE07E84896D06865495B87A061C4C55D03E428D unknown /C=US/ST=California/L=Mountain View/O=Google Inc/CN=*.appspot

Re: [squid-users] TProxy and client_dst_passthru

2015-04-06 Thread Stakres
Hi Amos, We have done additional tests in production with ISPs and the ORIGINAL_DST in tproxy cannot be cached. In normal mode (not tproxy), ORIGINAL_DST can be cached, no problem. But once in tproxy (http_port 3128 tproxy), no way, it's impossible to get TCP_HIT. We have played with the client_d