Re: [squid-users] SSTP_DUPLEX_POST method

2015-12-14 Thread Eliezer Croitoru
Isn't SSTP is some kind of secure VPN service? which is based on SSL? Why would you want to put a reverse proxy in front of a VPN service? There are many things to do in the IP level but not much to do in the HTTP level. Eliezer On 15/12/2015 07:20, Wayne Gillan wrote: Hi all, I am trying t

[squid-users] SSTP_DUPLEX_POST method

2015-12-14 Thread Wayne Gillan
Hi all, I am trying to configure squid as a reverse proxy in front of a Microsoft SSTP VPN server but squid does not appear to be forwarding the requests. I think it may have something to do with this custom verb/method that Microsoft use. See https://msdn.microsoft.com/en-us/library/cc247364.a

Re: [squid-users] Problems filtering specific plus.google.com (application/x-www-form-urlencoded)

2015-12-14 Thread Michael Pelletier
When trying to filter a sepcific site in plus.google.com (for example https://plus.google.com/114/), I see the request header going out to plus.google.com without any reference to the url. So it does not match the black list rule I have. On Mon, Dec 14, 2015 at 5:29 PM, Amos Jeffries

Re: [squid-users] issue with video

2015-12-14 Thread Amos Jeffries
On 15/12/2015 2:09 p.m., Eliezer Croitoru wrote: > I am not sure it's any squid issue since it is unclear what you are > referring to as "not working". > The logs can show couple things but cannot record what is the issue in > the client level. > I have tried to read them but have not seen the vide

Re: [squid-users] issue with video

2015-12-14 Thread Eliezer Croitoru
I am not sure it's any squid issue since it is unclear what you are referring to as "not working". The logs can show couple things but cannot record what is the issue in the client level. I have tried to read them but have not seen the video request. It could be a client issue rather then squid.

Re: [squid-users] Using subordinate CA for SSL Bump

2015-12-14 Thread Marcus Kool
On 12/14/2015 09:16 PM, Amos Jeffries wrote: With all that looking hopeful, and the certs identified as the secondary chain being attached (everything except the firstprimary/signing cert). I'm not actually finding anywhere sending the actual signing certificate itself during the bumping steps

Re: [squid-users] Using subordinate CA for SSL Bump

2015-12-14 Thread Amos Jeffries
On 15/12/2015 10:26 a.m., Yuri Voinov wrote: > > Hi all. > > Does anybody can tell me - is it possible to use subordinate secondary > CA in squid for SSL Bumping purpose? > > I.e., we have self-signed primary CA for issue subordinate CA, > > subordinate CA we install in squid's setup, > > prim

Re: [squid-users] Problems filtering specific plus.google.com (application/x-www-form-urlencoded)

2015-12-14 Thread Amos Jeffries
On 15/12/2015 10:59 a.m., Michael Pelletier wrote: > Hello, > Today we found a site that needed to be blocked while allowing the rest at > plus.google.com. I went to block the URL but it did not block. I looked > deeper into the problem and it seems application/x-www-form-urlencoded > never sends t

[squid-users] Problems filtering specific plus.google.com (application/x-www-form-urlencoded)

2015-12-14 Thread Michael Pelletier
Hello, Today we found a site that needed to be blocked while allowing the rest at plus.google.com. I went to block the URL but it did not block. I looked deeper into the problem and it seems application/x-www-form-urlencoded never sends the url so I can't block it. Can someone help? Michael --

[squid-users] Using subordinate CA for SSL Bump

2015-12-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi all. Does anybody can tell me - is it possible to use subordinate secondary CA in squid for SSL Bumping purpose? I.e., we have self-signed primary CA for issue subordinate CA, subordinate CA we install in squid's setup, primary CA certificat

Re: [squid-users] Peek and splice without replacing the certificates

2015-12-14 Thread Amos Jeffries
On 15/12/2015 5:52 a.m., Marcus Kool wrote: > > > On 12/14/2015 06:43 AM, Парфенович Н.А. wrote: >> Hello! Show you how to use Squid in transparent mode for tracking >> HTTPS without replacing the certificates? >> My squid.conf: http://pastebin.ru/AWU8LXvK. If such a configuration file >> to use

Re: [squid-users] URL Cacheing Question

2015-12-14 Thread Amos Jeffries
On 14/12/2015 11:07 p.m., Igor Dzombic wrote: > Hallo Squid Team, > > i have one Question, i’m trying to Configure Squid-Proxy-Server and i need > your help. It should work like this: > > - i should cache one URL (like > http://backend.my-server.net/servlets/fgi/onepage.php) and refrashe

Re: [squid-users] Transfer-Encoding tag not delivered to c-icap server

2015-12-14 Thread Alex Rousskov
On 12/14/2015 08:33 AM, Giray Simsek wrote: > I am using squid + c-icap for content adaptation. > On a client machine, I am trying to download a pdf file from docs.google.com. > Looks like the google servers are sending the response as chunked as the http > headers look like below: > Transfer-E

Re: [squid-users] Peek and splice without replacing the certificates

2015-12-14 Thread Marcus Kool
On 12/14/2015 06:43 AM, Парфенович Н.А. wrote: Hello! Show you how to use Squid in transparent mode for tracking HTTPS without replacing the certificates? My squid.conf: http://pastebin.ru/AWU8LXvK. If such a configuration file to use version 3.5.8 squid compiled using Libressl, everything wor

[squid-users] Transfer-Encoding tag not delivered to c-icap server

2015-12-14 Thread Giray Simsek
Hi, I am using squid + c-icap for content adaptation. On a client machine, I am trying to download a pdf file from docs.google.com. Looks like the google servers are sending the response as chunked as the http headers look like below: Access-Control-Allow-Credentials:false Access-Control-Allow-

Re: [squid-users] Peek and splice without replacing the certificates

2015-12-14 Thread Matus UHLAR - fantomas
On 14.12.15 13:43, Парфенович Н.А. wrote: Hello! Show you how to use Squid in transparent mode for tracking HTTPS without replacing the certificates? Not possible. Either you replace the certificates, or you CAN NOT track trhe session. the "s" part in https means that proxy can not see the en

Re: [squid-users] issue with video

2015-12-14 Thread Magic Link
Any ideas ? Thanks ! From: magicl...@outlook.com To: yvoi...@gmail.com; squid-users@lists.squid-cache.org Date: Fri, 11 Dec 2015 11:40:01 +0100 Subject: Re: [squid-users] issue with video https://drive.google.com/file/d/0B5u1WrFLUfPiNWhXLVRJZnJETzA/view?usp=sharing I test with squid 3.5.10 (fr

[squid-users] URL Cacheing Question

2015-12-14 Thread Igor Dzombic
Hallo Squid Team, i have one Question, i’m trying to Configure Squid-Proxy-Server and i need your help. It should work like this: - i should cache one URL (like http://backend.my-server.net/servlets/fgi/onepage.php) and refrashe it every 5 min. on a Squid-Proxy Server - My Clie

Re: [squid-users] blocking certain file types by content

2015-12-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.12.15 11:57, Amos Jeffries пишет: > On 14/12/2015 10:39 a.m., Markus wrote: >> Yuri Voinov wrote: >> >>> Think more. ALL ICAP solutions checks content. Diladele is not only solution which checks content. >> [...] >> >>> You really think execut

[squid-users] Peek and splice without replacing the certificates

2015-12-14 Thread Парфенович Н . А .
Hello! Show you how to use Squid in transparent mode for tracking HTTPS without replacing the certificates? My squid.conf: http://pastebin.ru/AWU8LXvK. If such a configuration file to use version 3.5.8 squid compiled using Libressl, everything works fine. But if you use version 3.5.9 and above, Sq