Re: [squid-users] krb5.conf Example

2024-11-25 Thread Marko Cupać
th kinit? ``` someuser@somesquid:~ $ kinit domainuser domainu...@example.org's Password: someuser@somesquid:~ $ klist Credentials cache: FILE:/tmp/krb5cc_1001 Principal: domainu...@example.org IssuedExpires Principal Nov 25 17:25:47 2024 Nov

[squid-users] TCP_TUNNEL/500 internal server error bandwidth impact

2023-09-27 Thread Marko Cupać
draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org https://lists.squid-cache.org/listinfo/squid-users

[squid-users] Squid 4.5 crashes on FreeBSD

2019-01-17 Thread Marko Cupać
6 with status 0 Jan 16 11:12:26 squid2 squid[64423]: Squid Parent: (squid-1) process 86955 started Could this be a software bug, or can I avoid this with configuration change? Thank you in advance, -- Before enlightenment - chop wood, draw water. After enlightenment - chop wood, draw water.

[squid-users] Squid 3.5.28 can't be built on FreeBSD 12.0-RELEASE

2018-12-24 Thread Marko Cupać
er; ^ ../../src/ssl/gadgets.h:116:43: error: use of undeclared identifier 'CRYPTO_LOCK_SSL' typedef LockingPointer SSL_Pointer; ---log-excerpt-end--- Thank you in advance, -- Before enlightenment - chop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar

[squid-users] Squid crashes with "!Comm::MonitorsRead(serverConnection->fd)"

2018-11-07 Thread Marko Cupać
11_03_22.crt - HIER_NONE/- application/octet-stream Notice there's no client IP address in the line. How come? How can I find out which clients request this? Thank you in advance, -- Before enlightenment - chop wood, draw water. After enlightenment - chip wood, dr

Re: [squid-users] auth username logging

2018-09-29 Thread Marko Cupać
On Sat, 29 Sep 2018 11:17:49 +1200 Amos Jeffries wrote: > On 29/09/18 3:56 AM, Marko Cupać wrote: > > Hi, > > > > I am testing migration of my AD-authenticated (kerberos + ntlm) 3.5 > > setup to 4.1. I noticed there are no usernames in access.log, just > > &

[squid-users] auth username logging

2018-09-28 Thread Marko Cupać
hop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] ssl bump and chrome 58

2017-04-21 Thread Marko Cupać
es in chrome again? Thank you in advance, -- Before enlightenment - chop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.

Re: [squid-users] How can I complete this tutorial?

2016-08-11 Thread Marko Cupać
chop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] sslbump and skype question

2016-07-28 Thread Marko Cupać
ou in advance, -- Before enlightenment - chop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] auth, ssl bump and analyzing logs

2016-07-14 Thread Marko Cupać
On Thu, 14 Jul 2016 23:27:04 +1200 Amos Jeffries wrote: > On 14/07/2016 8:38 p.m., Marko Cupać wrote: > > On Thu, 14 Jul 2016 20:23:03 +1200 > > Amos Jeffries wrote: > > > >> On 14/07/2016 7:45 p.m., Marko Cupać wrote: > >>> Hi, > >>> &

Re: [squid-users] auth, ssl bump and analyzing logs

2016-07-14 Thread Marko Cupać
On Thu, 14 Jul 2016 20:23:03 +1200 Amos Jeffries wrote: > On 14/07/2016 7:45 p.m., Marko Cupać wrote: > > Hi, > > > > is there a way to parse squid access.log in a way that only traffic > > that was served to clients count? > > Unless you are using a custom log

[squid-users] auth, ssl bump and analyzing logs

2016-07-14 Thread Marko Cupać
nment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] FreeBSD and Kerberos: RC4 keytabs work, AES256 don't

2016-03-15 Thread Marko Cupać
wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] dynamic ssl cert and active directory

2015-10-29 Thread Marko Cupać
enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] debug skype ssl_bump numeric ips to be spliced

2015-10-14 Thread Marko Cupać
aw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] help with acl order and deny_info pages

2015-10-07 Thread Marko Cupać
On Thu, 24 Sep 2015 23:02:35 +1200 Amos Jeffries wrote: > On 24/09/2015 7:30 p.m., Marko Cupać wrote: > > On Sun, 20 Sep 2015 21:43:26 +1200 > > Amos Jeffries wrote: > > > >> On 17/09/2015 7:24 p.m., Marko Cupać wrote: > >>> On Thu, 17 Sep 2015

Re: [squid-users] help with acl order and deny_info pages

2015-09-24 Thread Marko Cupać
On Sun, 20 Sep 2015 21:43:26 +1200 Amos Jeffries wrote: > On 17/09/2015 7:24 p.m., Marko Cupać wrote: > > On Thu, 17 Sep 2015 03:00:56 +1200 > > Amos Jeffries wrote: > > > >> On 17/09/2015 12:37 a.m., Marko Cupać wrote: > >>> Hi, > >>

Re: [squid-users] help with acl order and deny_info pages

2015-09-17 Thread Marko Cupać
On Thu, 17 Sep 2015 03:00:56 +1200 Amos Jeffries wrote: > On 17/09/2015 12:37 a.m., Marko Cupać wrote: > > Hi, > > > > I'm trying to setup squid in a way that it authenticates users via > > kerberos and grants different levels of web access according to ldap >

[squid-users] help with acl order and deny_info pages

2015-09-16 Thread Marko Cupać
trigger reauthentication while triggering deny_info? Thank you in advance. -- Before enlightenment - chop wood, draw water. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squi

Re: [squid-users] completely transparent Squid

2015-08-29 Thread Marko Cupać
eb requests from your users' ip pool to squid. In PF syntax this is something like: users = "{ 172.16.0.11 - 172.16.0.253 }" squid = "{ 172.6.0.10 }" unifi_lan = "{ 172.6.0.254 }" pass in on $unifi_lan proto tcp from $users to any port { 80 443 } \ rdr

Re: [squid-users] completely transparent Squid

2015-08-28 Thread Marko Cupać
ning OpenBSD + PF + Squid. There's (quite old but still relevant) howto: http://www.kernel-panic.it/openbsd/proxy/index.html Regards, -- Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] peek and splice content inspection question

2015-08-17 Thread Marko Cupać
nt) mode for SSLBump. Thanks for information about E2Guardian, I was not aware of it. Dansguardian didn't support kerberos authentication, and didn't have plans to ever support it, that's why I decided to move away from it to 'pure squid' setup.

Re: [squid-users] peek and splice content inspection question

2015-08-13 Thread Marko Cupać
On Fri, 14 Aug 2015 03:38:47 +1200 Amos Jeffries wrote: > On 14/08/2015 12:47 a.m., Marko Cupać wrote: > > Hi, > > > > a few years ago I had a working setup of squid + dansguardian which > > was giving me ability to inspect traffic and filter it according to &

[squid-users] peek and splice content inspection question

2015-08-13 Thread Marko Cupać
urious and unethical admin be able to easily dump bumped data and find sensitive information there? Thank you in advance, -- Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/list

Re: [squid-users] please help me test ext_ldap_group_acl from command line

2015-07-29 Thread Marko Cupać
;squid_noaccess' which resides in 'Web Services OU'... mimar.rs -> RS -> BG -> Groups -> Web Services - squid_noaccess ...typing in: pacija squid_noaccess ...returns OK. Regards, -- Marko Cupać https://www.mimar.rs/ __

[squid-users] please help me test ext_ldap_group_acl from command line

2015-07-28 Thread Marko Cupać
nts for postfix, apache authentication etc. Thank you in advance, -- Marko Cupać https://www.mimar.rs/ ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Probléme Squid to Java application

2014-10-22 Thread Marko Cupać
_access allow auth All I have to do is put domains that have broken authentication through proxy to /var/squid/lists/noauth and restart squid. -- Marko Cupać https://www.mimar.rs ___ squid-users mailing list squid-users@lists.squid-cache.org http: