Re: [squid-users] Why is overlapping dstdomains a FATAL error now?

2015-08-06 Thread Dan Charlesworth
Huh! Thanks for that, Amos. Our software actually flags the redundant entries and doesn't write those ones out, just that I realised I didn’t really understand “why” squid does that and why we need to work around it in the first place. Doing a `-k parse` before loading any new changes is super

Re: [squid-users] Why is overlapping dstdomains a FATAL error now?

2015-08-06 Thread Amos Jeffries
On 7/08/2015 11:48 a.m., Benjamin E. Nichols wrote: > Agreed, whoever decided it was a wise decision to make this a stop error > should be fired or at the very least, slapped in the back of the head. > > On 8/6/2015 6:44 PM, Dan Charlesworth wrote: >> This used to just cause a WARNING right? Is th

Re: [squid-users] Why is overlapping dstdomains a FATAL error now?

2015-08-06 Thread Benjamin E. Nichols
Agreed, whoever decided it was a wise decision to make this a stop error should be fired or at the very least, slapped in the back of the head. On 8/6/2015 6:44 PM, Dan Charlesworth wrote: This used to just cause a WARNING right? Is this really a good enough reason to stop Squid from starting u

[squid-users] Why is overlapping dstdomains a FATAL error now?

2015-08-06 Thread Dan Charlesworth
This used to just cause a WARNING right? Is this really a good enough reason to stop Squid from starting up? 2015/08/07 09:25:43| ERROR: '.ssl.gstatic.com ' is a subdomain of '.gstatic.com ' 2015/08/07 09:25:43| ERROR: You need to remove '.ssl.gstati

Re: [squid-users] I want to display indirect_client_address on error page.

2015-08-06 Thread Amos Jeffries
On 6/08/2015 5:27 p.m., Kazuhiro Asakura wrote: > Thank you Amos, > > From: Amos Jeffries >>> I use "follow-x-forwarded-for" feature, and logged end point IP address. >>> Also, I created customized error page for end user. but, env %i of >>> error page does not be translate to end point IP address

Re: [squid-users] LDAP related question.

2015-08-06 Thread Eliezer Croitoru
I also now found that the example for ldap search in squidguard is similar to my conclusion. http://www.squidguard.org/Doc/authentication.html ##START ldapbinddn cn=root, dc=example, dc=com ldapbindpass myultrasecretpassword # ldap cache time in seconds ldapcachetime 300 src my_user

Re: [squid-users] [squid-announce] Squid 3.5.7 is available

2015-08-06 Thread Amos Jeffries
[ cc'ing squid-users in case anyone gets confused ] On 6/08/2015 4:47 p.m., Amos Jeffries wrote: > > * Perl pod2man is now optional > > Several of the perl based helpers bundled with Squid have previously > been requiring the pod2man documentation generator before they will build. > > Since it i

[squid-users] [squid-announce] Squid 3.5.7 is available

2015-08-06 Thread Amos Jeffries
The Squid HTTP Proxy team is very pleased to announce the availability of the Squid-3.5.7 release! This release is a bug fix release resolving several issues found in the the prior Squid releases. The major changes to be aware of: * Regression Bug 4227: assertions in AuthUserHashPointer This

[squid-users] [squid-announce] Squid 3.4.14 is available

2015-08-06 Thread Amos Jeffries
The Squid HTTP Proxy team is very pleased to announce the availability of the Squid-3.4.14 release! This release is a security fix release resolving a vulnerability and some bugs found in the prior releases. REMINDER: This and older releases are already deprecated by Squid-3.5

Re: [squid-users] [squid-announce] [ADVISORY] SQUID-2015:2 Improper Protection of Alternate Path

2015-08-06 Thread Amos Jeffries
This is a courtesy announcement for users and distributors of Squid-3.1 that the advisory SQUID-2015:2 also known as CVE-2015-5400 has been updated to include a patch for Squid-3.1. The latest advisory document can be downloaded from The pa