Re: [squid-users] Squid 4.12 Arch Linux Google Chrome fails - OpenSSL 1.1.1g

2020-07-09 Thread Amos Jeffries
On 1/07/20 5:46 pm, Amish wrote: > > I know how to use git. My question was that in that PR, I saw commits > modifying files like Hasdshake.h, bio.cc. > > But in final PR only modification was done to Handshake.cc > > So I got confused. But I guess, the final PR is only what matters for my > pro

Re: [squid-users] Squid 4.11 Howto create SSL Bump certificates with only 3-12 months date of expiry

2020-07-09 Thread Amos Jeffries
On 30/06/20 3:13 am, info wrote: > > Hi Squid Community, > > how can I configure Squid to create SSL Bump Certifications with only > 3-12 months date of expiry? > As you know Squid uses a helper to generate the certificates. You can write a helper of your own to generate certificates with any c

Re: [squid-users] Explicitly use direct client IP in acl

2020-07-09 Thread Amos Jeffries
On 10/07/20 2:10 pm, Orion Poplawski wrote: > On 7/9/20 6:50 PM, Amos Jeffries wrote: >> On 10/07/20 9:54 am, Orion Poplawski wrote: >>> Hello - >>> >>>    We're using a setup like this: >>> >>> client -> e2guardian -> squid -> internet >>> >>> e2guardian is providing filtering and SSL inspection. 

Re: [squid-users] Explicitly use direct client IP in acl

2020-07-09 Thread Orion Poplawski
On 7/9/20 6:50 PM, Amos Jeffries wrote: On 10/07/20 9:54 am, Orion Poplawski wrote: Hello -   We're using a setup like this: client -> e2guardian -> squid -> internet e2guardian is providing filtering and SSL inspection.  Currently we only allow access to e2guardian from our internal network

Re: [squid-users] Explicitly use direct client IP in acl

2020-07-09 Thread Amos Jeffries
On 10/07/20 9:54 am, Orion Poplawski wrote: > Hello - > >   We're using a setup like this: > > client -> e2guardian -> squid -> internet > > e2guardian is providing filtering and SSL inspection.  Currently we only > allow access to e2guardian from our internal network.  Currently we > enforce ac

Re: [squid-users] Double method of authentication, possible?

2020-07-09 Thread Amos Jeffries
On 9/07/20 9:44 pm, Antonino Gianfranco Sanacori wrote: > Hi. > > I normally use a ldap authentication for my user but i would use the > basic authentication for some user. > > How can i configure squid to support both methods? They are not two methods. So no. But yes it is possible. -> Basic

Re: [squid-users] Forcing squid to fail when the whitelist doesn't exist

2020-07-09 Thread Matthew Macdonald-Wallace
Awesome, thanks! On Thu, 9 Jul 2020, 19:25 Alex Rousskov, wrote: > On 7/9/20 11:51 AM, Matthew Macdonald-Wallace wrote: > > > Turns out we're running 3.5.x > > > > I have not tested this, but if my quick reading of the latest v3.5 code > > is correct, then the missing parameters() file is treate

[squid-users] Explicitly use direct client IP in acl

2020-07-09 Thread Orion Poplawski
Hello - We're using a setup like this: client -> e2guardian -> squid -> internet e2guardian is providing filtering and SSL inspection. Currently we only allow access to e2guardian from our internal network. Currently we enforce access to squid come from localhost, except for some specific

Re: [squid-users] Forcing squid to fail when the whitelist doesn't exist

2020-07-09 Thread Matthew Macdonald-Wallace
On Thu, 9 Jul 2020 at 16:30, Alex Rousskov wrote: > On 7/9/20 2:25 AM, Matthew Macdonald-Wallace wrote: > > > > > I'll check the version that we're running and see if I can do > this. I > > > suspect that due to "enterprise requirements" our version won't be > the > > > latest, but h

Re: [squid-users] Forcing squid to fail when the whitelist doesn't exist

2020-07-09 Thread Alex Rousskov
On 7/9/20 11:51 AM, Matthew Macdonald-Wallace wrote: > > Turns out we're running 3.5.x > > I have not tested this, but if my quick reading of the latest v3.5 code > is correct, then the missing parameters() file is treated as a FATAL > configuration error (in ConfigParser::NextToken). FWIW, Squi

Re: [squid-users] Forcing squid to fail when the whitelist doesn't exist

2020-07-09 Thread Alex Rousskov
On 7/9/20 2:25 AM, Matthew Macdonald-Wallace wrote: > > > I'll check the version that we're running and see if I can do this.  I > > suspect that due to "enterprise requirements" our version won't be the > > latest, but hopefully it will support this. > > AFAICT, all supported Squ

Re: [squid-users] Forcing squid to fail when the whitelist doesn't exist

2020-07-09 Thread Matthew Macdonald-Wallace
> > I'll check the version that we're running and see if I can do this. I > > suspect that due to "enterprise requirements" our version won't be the > > latest, but hopefully it will support this. > > AFAICT, all supported Squid versions have parameters(). You will need to > enable configuration_i

[squid-users] Double method of authentication, possible?

2020-07-09 Thread Antonino Gianfranco Sanacori
Hi. I normally use a ldap authentication for my user but i would use the basic authentication for some user. How can i configure squid to support both methods? Thank you. Antonino -- Informativa sulla Privacy: http://www.unibs.it/node/8155 _