Re: [squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-16 Thread Jok Thuau
Blocking YouTube (appear to be on your list) is tricky, if the browser is chrome: https://en.m.wikipedia.org/wiki/QUIC If you click on the 'green lock' and look at the connection you will see it's not using https (funnily enough, the ads there do!). Look at the wiki for more info on how to blo

[squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-16 Thread Sergio Belkin
Hi, I cannot block some sites using squid 3.4.8, this the configuration. On Firefox, blocking works, browser says: `Error code: SSL_ERROR_RX_RECORD_TOO_LONG` But on Chromium Versión 49.0.2623.108, browser is not affected by the blocking acl's, despite access_logs says: 192.168.80.250 - - [

Re: [squid-users] Squid 4: Cloudflare SSL connection problem

2016-04-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 So. Still has no ideas? 16.04.16 22:50, Yuri Voinov пишет: > > 3.5.16 on *NIX is also has this issue. > > Only 3.5.16 Win64 is works like sharm. > > 16.04.16 17:18, Yuri Voinov пишет: > > mozilla.org now has the same issue on Squid 4 like CloudFl

Re: [squid-users] Squid 4: Cloudflare SSL connection problem

2016-04-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 3.5.16 on *NIX is also has this issue. Only 3.5.16 Win64 is works like sharm. 16.04.16 17:18, Yuri Voinov пишет: > mozilla.org now has the same issue on Squid 4 like CloudFlare: > > https://i1.someimage.com/P03GmSY.png > > All ok but handshake do

Re: [squid-users] High CPU usage

2016-04-16 Thread Amos Jeffries
On 16/04/2016 6:41 a.m., Mohammad Sadegh Nasiri wrote: > Thanks Amos for your reply. > > > This reaches 800 Mbps with Squid still spending a measurable chunk of its >> time (~30%) waiting for something to do. > > How do you discovered to this numbers (800Mbps and ~30%)? I explained the 800 Mbps

Re: [squid-users] Transition from Squid to bluecoat ProxySG

2016-04-16 Thread Brendan Kearney
On 04/16/2016 09:39 AM, asad wrote: Hello, I'm in the process of helping a friend who works in a bank whose management have decided to move from Squid infra to bluecoat PorxySG solution. I want to know what are the pitfalls that must be imagined from project management as on technical end.

[squid-users] Transition from Squid to bluecoat ProxySG

2016-04-16 Thread asad
Hello, I'm in the process of helping a friend who works in a bank whose management have decided to move from Squid infra to bluecoat PorxySG solution. I want to know what are the pitfalls that must be imagined from project management as on technical end. Few info that I'm allowed to share is

Re: [squid-users] How to replace (squid/3.x.x) info at http reponse header via and warning

2016-04-16 Thread johnzeng
Hello Amos : Thanks again . John > Hello Dear Sir > > How to replace (squid/3.x.x) info at http reponse header via and warning , > > Whether i will updated HttpHeader.cc ? > > {"Via", HDR_VIA, ftStr}, /* for now */ > {"Warning", HDR_WARNING, ftStr}, /* for now */ > > > Best Regards > > > John __

Re: [squid-users] Squid 4: Cloudflare SSL connection problem

2016-04-16 Thread Yuri Voinov
mozilla.org now has the same issue on Squid 4 like CloudFlare: https://i1.someimage.com/P03GmSY.png All ok but handshake does not complete: root @ cthulhu / # /usr/local/bin/openssl s_client -connect mozilla.org:443 -CApath /etc/ope/csw/ssl/certs CONNECTED(0003) depth=2 C = US, O = DigiCe