Re: [squid-users] Squid configuration sanity check

2018-05-15 Thread Alex K
Hi again, With this config I get: ERROR: No forward-proxy ports configured. I am wondering if I could just add a dummy entry: http_port 3130 to suppress this error. But not sure how this is useful when reading: https://wiki.squid-cache.org/KnowledgeBase/NoForwardProxyPorts Alex On Tue, May

Re: [squid-users] TCP FIN,ACK after ServerHelloDone with pcmag.com

2018-05-15 Thread Ahmad, Sarfaraz
I see a message similar to Marcus' in cache.log. 2018/05/16 00:20:10 kid1| ERROR: negotiating TLS on FD 77: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (1/-1/0) And I am running squid-4.0.24. Sarfaraz -Original Message- From: squid-users On Behalf

Re: [squid-users] TCP FIN,ACK after ServerHelloDone with pcmag.com

2018-05-15 Thread Marcus Kool
The proxies that I used for the test have Squid 4.0.22 and Squid 4.0.23. Marcus On 15/05/18 15:40, Amos Jeffries wrote: On 16/05/18 01:32, Marcus Kool wrote: pcmag.com also does not load here, although my config parameters are slightly different. The certificate is indeed huge... Do you have

Re: [squid-users] TCP FIN,ACK after ServerHelloDone with pcmag.com

2018-05-15 Thread Amos Jeffries
On 16/05/18 01:32, Marcus Kool wrote: > pcmag.com also does not load here, although my config parameters are > slightly different. > The certificate is indeed huge... > Do you have >    ERROR: negotiating TLS on FD NNN: error:14090086:SSL > routines:ssl3_get_server_certificate:certificate verify fa

Re: [squid-users] SOLVED - SECURITY ALERT: Host header forgery detected

2018-05-15 Thread Amos Jeffries
On 16/05/18 02:02, Eliezer Croitoru wrote: > Hey Martin, > > Technically there should be a way to inform Squid-Cache about multiple > addresses for the same destination. > If Squid doesn't know that it's a real IP of the domains a partial solution > is to use the same DNS service but it can also

Re: [squid-users] Collecting squid logs to DB

2018-05-15 Thread Eliezer Croitoru
I updated the repo: http://gogs.ngtech.co.il/elicro/squid-sql-logger The additions are: - GoLang mysql logging service source code. - Static pre-compiled binaries for(linux, windows, all bsd, Darwin, linux_arm.. , linux_mips...). - Installation instructions for th

Re: [squid-users] Sibling cache with ssl peek/splice/bump?

2018-05-15 Thread Alex Rousskov
On 05/15/2018 08:27 AM, Alex Crow wrote: > Is it currently possible in v4 with bumping to have a cache_peer setup > so that https:// resources can be fetched from a peer if they are > available there? If I am interpreting the "if available" part of your question correctly, then what you want is

[squid-users] Sibling cache with ssl peek/splice/bump?

2018-05-15 Thread Alex Crow
Hi list, Is it currently possible in v4 with bumping to have a cache_peer setup so that https:// resources can be fetched from a peer if they are available there? Many thanks Alex -- This message is intended only for the addressee and may contain confidential information. Unless you are tha

Re: [squid-users] SOLVED - SECURITY ALERT: Host header forgery detected

2018-05-15 Thread Eliezer Croitoru
Hey Martin, Technically there should be a way to inform Squid-Cache about multiple addresses for the same destination. If Squid doesn't know that it's a real IP of the domains a partial solution is to use the same DNS service but it can also be something else. For example there should be a way\o

Re: [squid-users] TCP FIN,ACK after ServerHelloDone with pcmag.com

2018-05-15 Thread Marcus Kool
pcmag.com also does not load here, although my config parameters are slightly different. The certificate is indeed huge... Do you have ERROR: negotiating TLS on FD NNN: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (1/-1/0) or other errors in cache.log ? M

[squid-users] TCP FIN,ACK after ServerHelloDone with pcmag.com

2018-05-15 Thread Ahmad, Sarfaraz
Hi Folks, I am using Squid as a HTTPS interception proxy. When I try to access https://www.pcmag.com , (which is supposed to be bumped in my environment ), I get "unable to forward request at this time" even though the website is perfectly accessible outside of the proxy. A packet capture sugg

[squid-users] TCP_TUNNEL_ABORTED/200 with spliced windowsupdates

2018-05-15 Thread Ahmad, Sarfaraz
Thanks Amos. Turns out it had nothing to do with the proxy but different MTU on the networks. I now have a little better understanding of this amazing piece of software. Sarfaraz ___ squid-users mailing list squid-users@lists.squid-cache.org http://lis

Re: [squid-users] TCP_TUNNEL_ABORTED/200 with spliced windows updates

2018-05-15 Thread Amos Jeffries
On 14/05/18 20:59, Ahmad, Sarfaraz wrote: > Hi Folks, > > I am using WCCP and redirecting traffic to Squid for both HTTP/HTTPS > interception. > > In this setup, I have spliced most of the Windows updates's services > using SNI in squid's acls. Yet even with TCP tunnel, I am getting > failures wi

Re: [squid-users] About functional testing

2018-05-15 Thread Amos Jeffries
On 15/05/18 00:29, 郦旺 wrote: > To whom it may concern, > > > I am a student who is interested in software reliability. After read the > Squid administrator's guide and FAQ, I only found the tests > like */“/*/*./test-builds.sh**”*/ to test the build before installation. > > > For the reason tha