Re: [squid-users] Error Resolution (TunnelStateData::Connection:: error )

2015-06-11 Thread Iruma Keisuke
Thank you Amos. I really appreciate your response. We analyzed the trend of FD an error has occurred. 2015/06/01_08:52:35 nsu01pint-int01 [cache]2015/06/01 08:52:32| TunnelStateData::Connection:: error : FD 81: read/write failure: (110) Connection timed out Active file descriptors: File Type T

Re: [squid-users] mimeInit: /etc/squid/mime.conf: (13) Permission denied

2015-06-11 Thread yashvinder hooda
Hi, Sir, I am ‎using squid on openwrt , so I guess Selinux or AppArmor shouldn't be an issue there. Regards, Yashvinder   Original Message   From: Amos Jeffries Sent: Friday 12 June 2015 7:07 AM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] mimeInit: /etc/squid/mime.conf: (1

Re: [squid-users] cgi-bin

2015-06-11 Thread Amos Jeffries
On 11/06/2015 8:55 a.m., Marcel Fossua wrote: > Hi Mate > I have this set on my squid.conf > but seems that this is obsolete so how can nicely convert that for that > version is true that log suggest > always_direct > > hierarchy_stoplist cgi-bin ? .js .jsp > acl QUERY urlpath_regex cgi-bin \?

Re: [squid-users] mimeInit: /etc/squid/mime.conf: (13) Permission denied

2015-06-11 Thread Amos Jeffries
On 11/06/2015 4:47 p.m., yashvinder hooda wrote: > Squid log says Permission denied for the file /etc/squid/mime.conf > While permission on it is > > -rwxrwxrwx1 nobody root 11364 May 9 15:40 mime.conf > And the SELinux or AppArmor permissions? Amos __

Re: [squid-users] How to mark trafic from squid and squidguard

2015-06-11 Thread Amos Jeffries
On 12/06/2015 12:28 a.m., CIROBOTICS wrote: > Hi dear is there a mean to mark trafic from squid/squidguard? > I'd like for example mark all trafic to pornsite instead of redirecting it > with squidguard. No. SG is too outdated for any of the Squid features that might allow that (helper annotations

Re: [squid-users] forwarded_for

2015-06-11 Thread Amos Jeffries
On 12/06/2015 1:38 a.m., Snyder, Brian wrote: > Hello All, > I am running squid 3.3.8 on CentOS 7.1. > The kernel is 3.10.0-229.4.2.el7.x86_64. > > I am having an issue where the forwarded_for directive is not > working correctly in squid.conf. I initially started the server hiding the client IP

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Amos Jeffries
On 12/06/2015 11:07 a.m., Tory M Blue wrote: > Okay well I took the RPM from your counter parts link and it gave me > > http://wiki.squid-cache.org/KnowledgeBase/CentOS > > squid-3.5.0.4-1.el6.x86_64.rpm > > > So am I using the wrong version? Yeah, I see squid-3.5.5-1.el6.src.rpm at the bottom

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Tory M Blue
Okay well I took the RPM from your counter parts link and it gave me http://wiki.squid-cache.org/KnowledgeBase/CentOS squid-3.5.0.4-1.el6.x86_64.rpm So am I using the wrong version? Thank you sir! :) Tory On Thu, Jun 11, 2015 at 3:56 PM, Amos Jeffries wrote: > On 12/06/2015 10:26 a.m., Tor

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Amos Jeffries
On 12/06/2015 10:26 a.m., Tory M Blue wrote: > On Thu, Jun 11, 2015 at 3:21 PM, Amos Jeffries wrote: > >> On 12/06/2015 9:48 a.m., Tory M Blue wrote: >>> On Thu, Jun 11, 2015 at 12:51 PM, Tory M Blue wrote: >>> On Thu, Jun 11, 2015 at 12:25 PM, Eliezer Croitoru < >> elie...@ngtech

Re: [squid-users] Patch for CVE-2014-7141 and CVE-2014-7142

2015-06-11 Thread Amos Jeffries
On 12/06/2015 4:30 a.m., Stacy Yeh wrote: > Hello, > > I am attempting to patch the security issues from CVE-2014-7141 and > CVE-2014-7142 for Squid 3.1.23 using the 3.1 patch provided here: > http://www.squid-cache.org/Advisories/SQUID-2014_4.txt > > I am running into the following error when I

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Tory M Blue
On Thu, Jun 11, 2015 at 3:21 PM, Amos Jeffries wrote: > On 12/06/2015 9:48 a.m., Tory M Blue wrote: > > On Thu, Jun 11, 2015 at 12:51 PM, Tory M Blue wrote: > > > >> > >> > >> On Thu, Jun 11, 2015 at 12:25 PM, Eliezer Croitoru < > elie...@ngtech.co.il> > >> wrote: > >> > >>> What is the issue??

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Amos Jeffries
On 12/06/2015 9:48 a.m., Tory M Blue wrote: > On Thu, Jun 11, 2015 at 12:51 PM, Tory M Blue wrote: > >> >> >> On Thu, Jun 11, 2015 at 12:25 PM, Eliezer Croitoru >> wrote: >> >>> What is the issue?? >>> Did you tried the latest RPM's ?? >>> http://wiki.squid-cache.org/KnowledgeBase/CentOS >>> >>>

Re: [squid-users] no fallback to ipv4 if ipv6 remote address is non-functional

2015-06-11 Thread Amos Jeffries
On 12/06/2015 9:56 a.m., Brian J. Murrell wrote: > At least from here, irc.bcwireless.net:6667 is non-functional > (connection times out) on IPv6 but works on IPv4: > > # telnet irc.bcwireless.net 6667 > Trying fcaa:8ef7:51b9:8f04:58f1:7364:e16e:fe2f... > telnet: connect to address fcaa:8ef7:51b9:

[squid-users] no fallback to ipv4 if ipv6 remote address is non-functional

2015-06-11 Thread Brian J. Murrell
At least from here, irc.bcwireless.net:6667 is non-functional (connection times out) on IPv6 but works on IPv4: # telnet irc.bcwireless.net 6667 Trying fcaa:8ef7:51b9:8f04:58f1:7364:e16e:fe2f... telnet: connect to address fcaa:8ef7:51b9:8f04:58f1:7364:e16e:fe2f: Connection timed out Trying 198.27

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Tory M Blue
On Thu, Jun 11, 2015 at 12:51 PM, Tory M Blue wrote: > > > On Thu, Jun 11, 2015 at 12:25 PM, Eliezer Croitoru > wrote: > >> What is the issue?? >> Did you tried the latest RPM's ?? >> http://wiki.squid-cache.org/KnowledgeBase/CentOS >> >> Eliezer >> >> > I spun my own as there were no precompile

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Tory M Blue
On Thu, Jun 11, 2015 at 12:25 PM, Eliezer Croitoru wrote: > What is the issue?? > Did you tried the latest RPM's ?? > http://wiki.squid-cache.org/KnowledgeBase/CentOS > > Eliezer > > I spun my own as there were no precompiled versions when I started with 3.5.x. I'll look at your rpms and test tho

[squid-users] Centos7 rpms?

2015-06-11 Thread Alex Crow
On 11/06/15 20:25, Eliezer Croitoru wrote: What is the issue?? Did you tried the latest RPM's ?? http://wiki.squid-cache.org/KnowledgeBase/CentOS Eliezer Hi, Are there any plans to build centos/rhev7 packages? Native LVM caching on SSD is something that may well benefit Squid performance.

Re: [squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Eliezer Croitoru
What is the issue?? Did you tried the latest RPM's ?? http://wiki.squid-cache.org/KnowledgeBase/CentOS Eliezer On 11/06/2015 21:29, Tory M Blue wrote: I've got logs and now finally a core (the whole "'squid' isn't signed with proper key") thang took a bit to get around. Rather not post the cor

[squid-users] 3.5.0.2 core, constant under heavy load.

2015-06-11 Thread Tory M Blue
I've got logs and now finally a core (the whole "'squid' isn't signed with proper key") thang took a bit to get around. Rather not post the core here, is there a better place, not sure it's a bug yet so opening a bug seems premature? Thanks Tory 3.5.0.2 CentOS I've tried using the -N option and

[squid-users] Patch for CVE-2014-7141 and CVE-2014-7142

2015-06-11 Thread Stacy Yeh
Hello, I am attempting to patch the security issues from CVE-2014-7141 and CVE-2014-7142 for Squid 3.1.23 using the 3.1 patch provided here: http://www.squid-cache.org/Advisories/SQUID-2014_4.txt I am running into the following error when I attempt to build Squid: /builds/skyeh/squid-component/c

[squid-users] Properly filtering http and https traffic in a transparent proxy environment

2015-06-11 Thread James Lay
Resending this with photobucket links instead of including images: http://i290.photobucket.com/albums/ll269/DigiDemon/allowed.png http://i290.photobucket.com/albums/ll269/DigiDemon/terminate.png Hey All, Sohere's what I have for filtering http and https in the same instance. This is using

Re: [squid-users] forwarded_for

2015-06-11 Thread Eliezer Croitoru
Hey Brian, Can you test this issue with the 3.5.x or 3.4.x RPM's I released? I have couple production servers running with 3.4 and 3.5 with "truncate" option to allow the backhand servers "see" the client IP. Eliezer * http://wiki.squid-cache.org/KnowledgeBase/CentOS On 11/06/2015 16:38, Sny

[squid-users] forwarded_for

2015-06-11 Thread Snyder, Brian
Hello All, I am running squid 3.3.8 on CentOS 7.1. The kernel is 3.10.0-229.4.2.el7.x86_64. I am having an issue where the forwarded_for directive is not working correctly in squid.conf. I initially started the server hiding the client IP using the "delete" setting. We have now changed direction

[squid-users] How to mark trafic from squid and squidguard

2015-06-11 Thread CIROBOTICS
Hi dear is there a mean to mark trafic from squid/squidguard? I'd like for example mark all trafic to pornsite instead of redirecting it with squidguard. regards. ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/

Re: [squid-users] ssl_crtd breaks after short time

2015-06-11 Thread Klavs Klavsen
James Lay wrote on 06/10/2015 03:18 PM: [CUT] I'm going to spin this off into a new thread..."Filtering http and https traffic" sometime later today. I have some questions, and maybe solutions. Much appreciated and much looked forward to.. hoping I can get what I had working with 3.4.12 - work