Re: [squid-users] Slow read for ICAP REQMOD body

2015-11-16 Thread Eliezer Croitoru
On 16/11/2015 17:13, David Smith wrote: Thanks Alex. I'd much rather not write my own but for*reasons* I need an implementation that runs on .NET and I couldn't find one. I only need a pretty small subset of the protocol. Both those bugs are for squid >= 3.5. I'm on 3.3.8 Perhaps I should tr

Re: [squid-users] Delay Pools Parameters

2015-11-16 Thread Amos Jeffries
On 17/11/2015 7:51 a.m., Tecnologia Charne.Net wrote: >>> Feel free to read Squid Wiki: >>> http://wiki.squid-cache.org/Features/DelayPools >> I think this is a little unfair on the original poster. >> Yes, the document the original poster was reading *was* the fine manual :-P >> The arithmetic

Re: [squid-users] Active Directory Authentication failing at the browser

2015-11-16 Thread Rafael Akchurin
Hello all, If I am not terribly mistaken when you have a Kerberos auth scheme active - you are actually using SSO - i.e. when everything is configured normally you should *never* see the popup box - the fact that you see it means Kerberos is not working. What I would check first is that you se

Re: [squid-users] How To Deploy Squid Proxy Connection For External Use?

2015-11-16 Thread Amos Jeffries
On 17/11/2015 10:10 a.m., Casey Stellar wrote: > Hello, > > I've managed to get Squid working on my PC using localhost:8080. I'm now > trying to learn setting it up for deployment for external clients. The only > tutorials I could find demonstrate setting up for local network.. > Please explain

Re: [squid-users] Active Directory Authentication failing at the browser

2015-11-16 Thread Amos Jeffries
On 17/11/2015 9:17 a.m., Amos Jeffries wrote: > On 17/11/2015 3:19 a.m., Eugene M. Zheganin wrote: >> Hi. >> >> On 16.11.2015 18:46, dolson wrote: >>> >>> Squid Version: Squid 3.4.8 >>> >>> OS Version: Debian 8 (8.2) >>> >>> I have installed Squid on a server using Debian 8 and seem to have the

[squid-users] How To Deploy Squid Proxy Connection For External Use?

2015-11-16 Thread Casey Stellar
Hello, I've managed to get Squid working on my PC using localhost:8080. I'm now trying to learn setting it up for deployment for external clients. The only tutorials I could find demonstrate setting up for local network.. ___ squid-users mailing list squ

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Amos Jeffries
On 17/11/2015 4:48 a.m., Eugene M. Zheganin wrote: > Hi, > > On 16.11.2015 19:51, Matej Kotras wrote: >> Thank you for your response, as this is my first try with Squid, and >> fairly newb in Linux. >> I do not understand at all differences between basic/ntlm/gss-spnego >> auths so I will do my ho

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Amos Jeffries
On 16/11/2015 10:29 p.m., Matej Kotras wrote: > Hi guys > > I've managed squid to work with AD, and authorize users based on what AD > group they are in. I use Squid-Analyzer for doing reports from access.log. > I've found 2 anomalies with authorization so far. In access log, I see that > user is

Re: [squid-users] Active Directory Authentication failing at the browser

2015-11-16 Thread Amos Jeffries
On 17/11/2015 3:19 a.m., Eugene M. Zheganin wrote: > Hi. > > On 16.11.2015 18:46, dolson wrote: >> >> Squid Version: Squid 3.4.8 >> >> OS Version: Debian 8 (8.2) >> >> I have installed Squid on a server using Debian 8 and seem to have the >> basics >> operating, at least when I start the squid

Re: [squid-users] Delay Pools Parameters

2015-11-16 Thread Tecnologia Charne.Net
>> Feel free to read Squid Wiki: >> http://wiki.squid-cache.org/Features/DelayPools > I think this is a little unfair on the original poster. > > The arithmetic in the documentation does appear to be incorrect - look at the > units: > > [...] > Therefore I believe the correct calculations should

Re: [squid-users] sslBump adventures in enterprise production environment

2015-11-16 Thread Alex Rousskov
On 11/15/2015 11:13 PM, Eugene M. Zheganin wrote: > On 16.11.2015 00:39, Alex Rousskov wrote: >> Squid currently supports two kinds of CONNECT tunnels: >> >> 1. A regular opaque tunnel, as intended by HTTP specifications. >> >> 2. An inspected tunnel containing SSL/TLS-encrypted HTTP traffic. >

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Rafael Akchurin
Hello Matej, Eugene, Hope our humble tutorial for Squid <-> Active Directory integration with Kerberos SSO, Basic(LDAP) auth is also useful - http://docs.diladele.com/administrator_guide_4_3/active_directory/index.html No NTLM though!!! Best regards, Rafael Akchurin Diladele B.V. -- Please ta

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Eugene M. Zheganin
Hi, On 16.11.2015 19:51, Matej Kotras wrote: > Thank you for your response, as this is my first try with Squid, and > fairly newb in Linux. > I do not understand at all differences between basic/ntlm/gss-spnego > auths so I will do my homework and read about them. I've managed to > get this workin

Re: [squid-users] Slow read for ICAP REQMOD body

2015-11-16 Thread David Smith
Thanks Alex. I'd much rather not write my own but for *reasons* I need an implementation that runs on .NET and I couldn't find one. I only need a pretty small subset of the protocol. Both those bugs are for squid >= 3.5. I'm on 3.3.8 Perhaps I should try a more recent version. -Original Me

Re: [squid-users] Slow read for ICAP REQMOD body

2015-11-16 Thread Alex Rousskov
On 11/16/2015 07:30 AM, David Smith wrote: > I’m in the middle of writing an ICAP server. If you are not too far along down this path, consider writing an adapter for one of the existing ICAP servers and/or eCAP. ICAP is far more complex than it seems, and, in most cases, reinventing that [comple

Re: [squid-users] Delay Pools Parameters

2015-11-16 Thread Antony Stone
> 16.11.15 20:49, Tecnología CHARNE.NET пишет: > > Hello! > > > > I'm configuring delay pools on squid 3.5 > > > > I don't understand online doc > > [http://www.squid-cache.org/Versions/v3/3.5/cfgman/delay_parameters.html] > > about delay_parameters > > > > > > "Note that 8 x 32000 KByte/se

Re: [squid-users] Delay Pools Parameters

2015-11-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Feel free to read Squid Wiki: http://wiki.squid-cache.org/Features/DelayPools 16.11.15 20:49, Tecnología CHARNE.NET пишет: > Hello! > > I'm configuring delay pools on squid 3.5 > > I don't understand online doc > [http://www.squid-cache.org/Versi

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Matej Kotras
Thank you for your response, as this is my first try with Squid, and fairly newb in Linux. I do not understand at all differences between basic/ntlm/gss-spnego auths so I will do my homework and read about them. I've managed to get this working after few weeks of "trial and error" method (I know, I

Re: [squid-users] Delay Pools Parameters

2015-11-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 16.11.15 20:49, Tecnología CHARNE.NET пишет: > Hello! > > I'm configuring delay pools on squid 3.5 > > I don't understand online doc > [http://www.squid-cache.org/Versions/v3/3.5/cfgman/delay_parameters.html] about > delay_parameters > > > "

Re: [squid-users] Slow read for ICAP REQMOD body

2015-11-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I think, better to ask this question in c-icap list, and not squid. Also take look on typical squid icap-related config: http://vgy.me/6xrcxK.png As you can see, this is _always_ uses reqmod_precache. How you think - why? :) 16.11.15 20:30, Da

[squid-users] Delay Pools Parameters

2015-11-16 Thread Tecnología CHARNE . NET
Hello! I'm configuring delay pools on squid 3.5 I don't understand online doc [http://www.squid-cache.org/Versions/v3/3.5/cfgman/delay_parameters.html] about delay_parameters "Note that 8 x 32000 KByte/sec -> 256Kbit/sec. 8 x 8000 KByte/sec -> 64Kbit/sec. 8 x

[squid-users] Slow read for ICAP REQMOD body

2015-11-16 Thread David Smith
Hi, I'm in the middle of writing an ICAP server. Reading the encapsulated body of a REQMOD message from Squid is taking 300ms. Reading the ICAP headers / HTTP headers is extremely quick. When I send a test message to the server it takes under 30ms so I don't think this is my implementation (obvi

Re: [squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Eugene M. Zheganin
On 16.11.2015 14:29, Matej Kotras wrote: > Hi guys > > I've managed squid to work with AD, and authorize users based on what > AD group they are in. I use Squid-Analyzer for doing reports from > access.log. I've found 2 anomalies with authorization so far. In > access log, I see that user is author

Re: [squid-users] Active Directory Authentication failing at the browser

2015-11-16 Thread Eugene M. Zheganin
Hi. On 16.11.2015 18:46, dol...@ihcrc.org wrote: > > Squid Version: Squid 3.4.8 > > OS Version: Debian 8 (8.2) > > > > I have installed Squid on a server using Debian 8 and seem to have the > basics operating, at least when I start the squid service, I have am > no longer getting any error mes

[squid-users] Active Directory Authentication failing at the browser

2015-11-16 Thread dolson
Squid Version: Squid 3.4.8 OS Version: Debian 8 (8.2) I have installed Squid on a server using Debian 8 and seem to have the basics operating, at least when I start the squid service, I have am no longer getting any error messages. At this time, the goal is to authenticate users from Active

Re: [squid-users] affinity session load balancing

2015-11-16 Thread Antony Stone
On Monday 16 November 2015 at 12:17:49, Patrick Chemla wrote: > Hi, > > This is exactly the problem. > > When users connect to the application, they go through the squid, then > reach a login page where they enter login/passwd. > > The application creates cookies including a PHPSESSION cookie.

Re: [squid-users] affinity session load balancing

2015-11-16 Thread Patrick Chemla
Hi, This is exactly the problem. When users connect to the application, they go through the squid, then reach a login page where they enter login/passwd. The application creates cookies including a PHPSESSION cookie. Can squid use such cookie? Patrick On 16/11/2015 12:49, Antony Stone wro

Re: [squid-users] affinity session load balancing

2015-11-16 Thread Antony Stone
On Monday 16 November 2015 at 11:32:31, Patrick Chemla wrote: > I am doing load balancing as sourcehash, so on IP source. > > The problem is that about 80% of clients come from the same IP, so I > have a highly loaded backend, while other are sleeping. > > So whatever you call it, on haproxy the

Re: [squid-users] affinity session load balancing

2015-11-16 Thread Patrick Chemla
Hi Antony, Thanks for your answer. Actually, I am doing load balancing as sourceash, so on IP source. The problem is that about 80% of clients come from the same IP, so I have a highly loaded backend, while other are sleeping. So whatever you call it, on haproxy they call it session affinity

Re: [squid-users] affinity session load balancing

2015-11-16 Thread Antony Stone
On Monday 16 November 2015 at 10:35:39, Patrick Chemla wrote: > Hi, > > I am using squid for years, maybe with basic features, and I have a > problem today with an app where I need to manage multiple backends, be > sure that a user is always sent to the same one because the app writes > on local

[squid-users] affinity session load balancing

2015-11-16 Thread Patrick Chemla
Hi, I am using squid for years, maybe with basic features, and I have a problem today with an app where I need to manage multiple backends, be sure that a user is always sent to the same one because the app writes on local disk, and I have 80% users coming from same IP. So I need to load bal

[squid-users] Fwd: NTLM LDAP authentication problem

2015-11-16 Thread Matej Kotras
Hi guys I've managed squid to work with AD, and authorize users based on what AD group they are in. I use Squid-Analyzer for doing reports from access.log. I've found 2 anomalies with authorization so far. In access log, I see that user is authorized based on his PC name(not desired) and not on th

Re: [squid-users] sslBump adventures in enterprise production environment

2015-11-16 Thread Yuri Voinov
16.11.15 12:00, Eugene M. Zheganin пишет: Hi. On 16.11.2015 00:14, Yuri Voinov wrote: It's common knowledge. Squid is unable to pass an unknown protocol on the standard port. Consequently, the ability to proxy this protocol does not exist. If it was simply a tunneling ... It is not https. A