Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Matus UHLAR - fantomas
On 17.05.16 18:10, zodyo wrote: I have same problem here, client cant login to a server with auth like LDAP via transparent/static squid. i have try with lusca and the newer squid 3.5.17 how can this be the same problem? It's very different problem. when talking about "transparent" proxy, you

[squid-users] ext_kerberos_ldap_group_acl and Kerberos cache

2016-05-17 Thread Eugene M. Zheganin
Hi. I've just checked that squid 3.5.19 sources, and discovered the following fact that is really disturbing: (first some explanation) Markus Moeller, the author of the external kerberos group helper, has implemented the Kerberos credentials cache in the ext_kerberos_ldap_group_acl helper back in

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Amos Jeffries
On 18/05/2016 10:05 a.m., Yuri Voinov wrote: > > . and a bit below in squid.conf.documented we can see. > > # SSL OPTIONS > # > - > > # TAG: sslproxy_client_certificate > #Client SSL Certificate to use when

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread zodyo
Dear all, I have same problem here, client cant login to a server with auth like LDAP via transparent/static squid. i have try with lusca and the newer squid 3.5.17 -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/explicit-forward-proxy-to-server-requring-cli

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 PS. I read the manual out loud. With an expression. Expensive. :-!:-D 18.05.16 3:11, Robert W Weaver пишет: > Greetings, squid users and devs, > > I think this is usual, but I can't find examples, and I can't make it work. :-) > > The issue is I

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 . and a bit below in squid.conf.documented we can see. # SSL OPTIONS # - # TAG: sslproxy_client_certificate #Client SSL Certificate to use when proxying http

Re: [squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 18.05.16 3:11, Robert W Weaver пишет: > Greetings, squid users and devs, > > I think this is usual, but I can't find examples, and I can't make it work. :-) > > The issue is I need to connect to a site that requires client authentication. Don't

[squid-users] explicit forward proxy to server requring client authentication

2016-05-17 Thread Robert W Weaver
Greetings, squid users and devs, I think this is usual, but I can't find examples, and I can't make it work. :-) The issue is I need to connect to a site that requires client authentication. Don't want to put the key and cert on each individual user, so instead want the key and cert on the pr

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Heh, qos need to be configured with squid.conf to be something different from 0x0 :) 18.05.16 2:40, J Green пишет: > That could work, I would just need to know at some point, if this event was > triggered. > > Been playing with %st , %>qos , & %

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread J Green
That could work, I would just need to know at some point, if this event was triggered. Been playing with %st , %>qos , & % wrote: > On 17/05/2016 6:37 a.m., J Green wrote: > > Re logging, does this eventually get logged by Squid, somewhere? > > > > I assume by "this" you mean the TOS values? > >

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 We need more information. Enable debug wccp gre and the router. See what happens. You may need to redirect the router debugging to the syslogd. This may be as a bug in the router and in Linux - yes, and there are spots in the Sun. Usually wccp wo

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 We need more information. Enable debug wccp gre and the router. See what happens. You may need to redirect the router debugging to the syslogd. This may be as a bug in the router and in Linux - yes, and there are spots in the Sun. Usually wccp wo

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Maile Halatuituia
Yuri/Amos I have a situation. I suspect it is my gre tunnel idle time or something but not sure. Every time like after 6 hrs, 4hrs it's not constant but after sometime i have to tear down the tunnel and re established it again in order for packet to be redirected from the router , at the same ti

Re: [squid-users] Can Traffic Management Settings be configured for other TCP protocols?

2016-05-17 Thread Amos Jeffries
On 17/05/2016 6:37 a.m., J Green wrote: > Re logging, does this eventually get logged by Squid, somewhere? > I assume by "this" you mean the TOS values? There are the %>qos and %http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Squid unable to send full PNG file

2016-05-17 Thread Amos Jeffries
On 17/05/2016 8:23 a.m., Aashima Madaan wrote: > Hi, > > I have a PNG file uploaded on server. > As part of Download process, it passes through SQUID to another server for > scanning and then to Client . > > When I send request to Download , the response sends only 27kb of image > back from serve

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
I have installed squid as my router and below are my iptable rules 675 39972 DNAT tcp -- eth1 * 0.0.0.0/00.0.0.0/0 tcp dpt:80 to:192.168.0.200:3127 0 0 REDIRECT tcp -- eth0 * 0.0.0.0/0 0.0.0.0/0tcp dpt:80 redir ports 3127

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread admin
I have the same config, but in my logs domain names Reet Vyas писал 2016-05-17 15:48: > Here is my txt file, as of now its working but I am getting secure connection > failed, I want to know if we can customize error message like Access Denied . > > In logs I am not getting full URL PFA logs

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
Here is my txt file, as of now its working but I am getting secure connection failed, I want to know if we can customize error message like Access Denied . In logs I am not getting full URL PFA logs for same. What I have to change in peek and splice ssl bump to get full URL ? Logs: 3481340.02

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread admin
get your blocked_https.txt Reet Vyas писал 2016-05-17 14:47: > Hi > > Below is my squid configuration > > Squid : 3.5.13 > OS ubuntu 14.04 > > http_port 3128 > http_port 3127 intercept > https_port 3129 intercept ssl-bump generate-host-certificates=on > dynamic_cert_mem_cache_size=4MB

Re: [squid-users] Squid Peek and splice

2016-05-17 Thread Reet Vyas
Hi Below is my squid configuration Squid : 3.5.13 OS ubuntu 14.04 http_port 3128 http_port 3127 intercept https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_certs/squid.crt key=/etc/squid/ssl_certs/squid.key cipher=ECDHE-RSA-RC4-

[squid-users] Squid transfers much not requested data from uplink in specific cases

2016-05-17 Thread Garri Djavadyan
Hello Squid community, According to the bug report 4511 [1], Squid may transfer much useless, not requested data from uplink after specific sequence of actions. For example, slow client (access rate 128Kb/s) may begin transfer of big cacheable object (4GB). After some time, another client (access