Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Amos Jeffries
On 17/10/2015 9:15 a.m., Yuri Voinov wrote: > > In my setup exists these helpers: > > http://i.imgur.com/mbfhojY.png > > with this configuration: > > ./configure '--prefix=/usr/local/squid' '--enable-translation' ... > '--enable-cache-digests' '--with-dl' '--enable-auth-negotiate=none' > '--dis

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 In my setup exists these helpers: http://i.imgur.com/mbfhojY.png with this configuration: ./configure '--prefix=/usr/local/squid' '--enable-translation' '--enable-external-acl-helpers=none' '--enable-icap-client' '--enable-ecap' '--enable-ipf-tr

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Sebastien.Boulianne
How should I select it ? :( Thanks Yuri! De : squid-users [mailto:squid-users-boun...@lists.squid-cache.org] De la part de Yuri Voinov Envoyé : 16 octobre 2015 15:28 À : squid-users@lists.squid-cache.org Objet : Re: [squid-users] Replacing Microsoft TMG by Squid. -BEGIN PGP SIGNED MESSAGE-

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I have no sources right now, but looks like pure LDAP auth helper does not selected 17.10.15 1:10, sebastien.boulia...@cpu.ca пишет: > I builded my own version too… > > I used these options. > > squid -v > Squid Cache: Version 3.5.10-20151001-

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Sebastien.Boulianne
I builded my own version too… I used these options. squid -v Squid Cache: Version 3.5.10-20151001-r13933 Service Name: squid configure options: '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbi

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 To do custom build, you must build Squid from source yourself, and not get from any repos, which is it's owner preferences impress. 17.10.15 1:06, sebastien.boulia...@cpu.ca пишет: > I dont have any /usr/lib/squid/squid_ldap_auth. > > There is no

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The set of auth helper depending from your configuration options. 17.10.15 1:06, sebastien.boulia...@cpu.ca пишет: > I dont have any /usr/lib/squid/squid_ldap_auth. > > There is no /usr/lib/squid directory. > > De : squid-users [mailto:squid-users

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Sebastien.Boulianne
I dont have any /usr/lib/squid/squid_ldap_auth. There is no /usr/lib/squid directory. De : squid-users [mailto:squid-users-boun...@lists.squid-cache.org] De la part de Yuri Voinov Envoyé : 16 octobre 2015 15:03 À : squid-users@lists.squid-cache.org Objet : Re: [squid-users] Replacing Microsoft T

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 http://wiki.squid-cache.org/Features/Authentication 17.10.15 1:01, sebastien.boulia...@cpu.ca пишет: > Is squid_ldap_auth was replaced by digest_ldap_auth ? > > Thanks! > > Sébastien Boulianne > Administrateur réseau & système / Network & System A

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Sebastien.Boulianne
Is squid_ldap_auth was replaced by digest_ldap_auth ? Thanks! Sébastien Boulianne Administrateur réseau & système / Network & System Administrator. Gestion des infrastructures / Infrastructure Management. CCNA / CompTIA Server+ / Spécialiste en monitoring. sebastien.boulia...@cpu.ca

Re: [squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Start from here: http://wiki.squid-cache.org/ConfigExamples/Authenticate/Ldap 16.10.15 23:51, sebastien.boulia...@cpu.ca пишет: > Hi all, > > Like you know, Microsoft discountinued the TMG. > The TMG was used as a reverse proxy. > Since many days

Re: [squid-users] normal squid , can we cahce fcebook vidoes ?

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Feel free to check out our Wiki: http://wiki.squid-cache.org/ConfigExamples/DynamicContent/Coordinator http://wiki.squid-cache.org/ConfigExamples/DynamicContent http://wiki.squid-cache.org/ConfigExamples/DynamicContent/YouTube/Discussion You can

[squid-users] Replacing Microsoft TMG by Squid.

2015-10-16 Thread Sebastien.Boulianne
Hi all, Like you know, Microsoft discountinued the TMG. The TMG was used as a reverse proxy. Since many days, I work to replace our TMG by a Squid server v3.5.10 with Oracle Linux 7 x64. I moved some sites this week but I have a little problem now. How can I ask LDAP credentials for a user who wa

Re: [squid-users] normal squid , can we cahce fcebook vidoes ?

2015-10-16 Thread Ahmad Alzaeem
Thanks amos , What about if it was for ISP and the ssl pump is impossible since it will break the privacy and will need user end user agreement to pass the websites . Im asking regarding facebook since its 100 % https And asking about youtube videos since its 100 % https I don’t know how com

Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Amos Jeffries
On 17/10/2015 3:11 a.m., Luis Daniel Lucio Quiroz wrote: > Your domainavlweb declaration it's wrong. Put something like .domain.qc.CA Yes ... acl domainwebacl dstdomain www.domain.qc.ca ... only (and exactly) www.domain.qc.ca http_access allow www80 domainwebacl cache_peer_access

Re: [squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Amos Jeffries
On 17/10/2015 12:30 a.m., Gianluca Bergamo wrote: > Ok thanks. > Will that change the behavior of the proxy? Of course. It will make it behave the way you apparently need it to. Amos ___ squid-users mailing list squid-users@lists.squid-cache.org http:/

Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Ron Wheeler
Have you looked in the web server logs? What happens when Squid is not used? Ron On 16/10/2015 10:00 AM, sebastien.boulia...@cpu.ca wrote: Hi, When I try to access www.domain.qc.ca it works perfectly BUT when I try domain.domain.qc.ca, it fails. 1445003869.430

Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Luis Daniel Lucio Quiroz
Your domainavlweb declaration it's wrong. Put something like .domain.qc.CA Le 16 oct. 2015 10:03 AM, "Yuri Voinov" a écrit : > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Web-server. > > DNS, which serves this zone, has not PTR record without www for domain, or > web-server itself has

Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Web-server. DNS, which serves this zone, has not PTR record without www for domain, or web-server itself has not rewrite rule for hostname without www. 16.10.15 20:00, sebastien.boulia...@cpu.ca пишет: > Hi, > > When I try to access www.domain.qc

[squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Sebastien.Boulianne
Hi, When I try to access www.domain.qc.ca it works perfectly BUT when I try domain.domain.qc.ca, it fails. 1445003869.430 4 65.94.187.169 TCP_MISS/200 9269 GET http://www.domain.qc.ca/ - FIRSTUP_PARENT/xx.xx.xx.xx text/html 1445003436.890 0 m.y.i.p TCP_DENIED

Re: [squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Gianluca Bergamo
Ok thanks. Will that change the behavior of the proxy? On Fri, Oct 16, 2015 at 12:29 PM, Amos Jeffries wrote: > On 16/10/2015 11:16 p.m., Gianluca Bergamo wrote: > > Hi Amos, > > > > Thank you for the support. > > This is my squid.conf > > http://pastebin.com/hNmnck27 > > > > I was right. You do

squid-users@lists.squid-cache.org

2015-10-16 Thread Бараблин Дмитрий
Thank you for answer! what i have to add in config to filter (by Whitelist) http sites in intercept ? On 15.10.2015 09:25, Бараблин Дмитрий wrote: Hello all! im trying to configure squid 3.5.8 as intercept with Whitelist ACLs on HTTP and HTTPS. what my config: acl localnet src 10.0.0.0/8

Re: [squid-users] normal squid , can we cahce fcebook vidoes ?

2015-10-16 Thread Amos Jeffries
On 16/10/2015 5:15 a.m., Ahmad Alzaeem wrote: > Hello Guys > > > In the past , the videos were http in youtube & facebook > > Im asking simple question here > > Is it possible for me as a normal squid user to be able to cache youtube & > facebook vidoes in https ? > That depends on whether

Re: [squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Amos Jeffries
On 16/10/2015 11:16 p.m., Gianluca Bergamo wrote: > Hi Amos, > > Thank you for the support. > This is my squid.conf > http://pastebin.com/hNmnck27 > I was right. You dont have a reverse-proxy. You have a explicit/forward proxy that happens to be listening on port 80. To make it a reverse-proxy

Re: [squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Gianluca Bergamo
Hi Amos, Thank you for the support. This is my squid.conf http://pastebin.com/hNmnck27 We use squid as external access to hosts services (port 80) that are in a vpn, so this should be the classical use of a reverse proxy. What do you think? Thank you. Gian On Fri, Oct 16, 2015 at 11:53 AM, Amo

Re: [squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Amos Jeffries
On 16/10/2015 9:23 p.m., Gianluca Bergamo wrote: > Hi everyone, > > I've just discovered that making requests to our reverse proxy using a > Vodafone umts connection does not work. > I get a bad request, and the problem is that in the http header the GET > line does not include the full path but j

[squid-users] Fwd: http get requests to squid with relative path

2015-10-16 Thread Gianluca Bergamo
Hi everyone, I've just discovered that making requests to our reverse proxy using a Vodafone umts connection does not work. I get a bad request, and the problem is that in the http header the GET line does not include the full path but just the relative one. The "Host:" parameter in the header is