Re: [squid-users] Is your kerberos ticket expired?

2017-10-08 Thread Dijxie
W dniu 05.10.2017 o 16:16, erdosain9 pisze: Hi. All is working fine, but im having this error in the mail of root -- From r...@squid.domain.lan Tue Oct 3 04:00:02 2017 Return-Path

Re: [squid-users] Kerberos access denied and reauthentication

2017-07-28 Thread Dijxie
W dniu 28.07.2017 o 10:46, Grey pisze: Shoul I wait for the error to appear and post the section relevant to the time when it occurs? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Kerberos-access-denied-and-reauthentication-tp4683224p4683232.html Sent fro

Re: [squid-users] ntml winbindd_privileged permission issue

2017-07-27 Thread Dijxie
On 2017-07-27 18:15, Max Ashton wrote: Hi guys, I have just configured our squid proxy to use ntlm authentication. I am failing to find correct file permission for the /var/lib/samba/winbindd_privileged folder. Squid failed to authenticate using winbind when the following file permissions are

Re: [squid-users] Kerberos access denied and reauthentication

2017-07-27 Thread Dijxie
On 2017-07-27 10:27, Grey wrote: Hi, I'm trying to setup a proxy server using Squid 3.5.23 on Debian 9; I've successfully setup Kerberos authentication generating the keytab file with ktutil and manually setting the required SPN on my Windows domain controller. The problem I'm encountering is tha

Re: [squid-users] Dstdomain "there are more than 100 regular expressions"

2017-07-06 Thread Dijxie
W dniu 06.07.2017 o 15:22, erdosain9 pisze: Hi. I have this in my cache.log ad_block, is a list for block publicity. there is a best way to do that?? 2017/07/06 10:35:49| /etc/squid/squid.conf line 55: acl ads dstdom_regex "/etc/squid/listas/ad_block.lst" 2017/07/06 10:35:49| WARNING: there ar

Re: [squid-users] The best way to start | stop | reload | status

2017-07-06 Thread Dijxie
W dniu 06.07.2017 o 15:08, erdosain9 pisze: Hi. mmm... im having a doubt. I usually use Systemctl for start, stop, reload, and status; but sometimes i heard that it was not the best way to do these actions. Way? I heard something wrong? And if not the best way, what would it be? 1) squid -z 2) s

Re: [squid-users] Has anyone seen v3.5.x.x authenication work in an all windows environment?

2017-07-03 Thread Dijxie
W dniu 03.07.2017 o 09:43, Todd Pearson pisze: I have spent the past few days working to get the latest version working in an all windows environment. I am unable to get kerberos authentication to work. I am struggling with getting the keytab file correct. Wondering if there is anyone who h

Re: [squid-users] Tagged ACLs?

2017-05-20 Thread Dijxie
W dniu 20.05.2017 o 18:07, Ralf Hildebrandt pisze: Currently we're using a few blacklists (from abuse.ch) as ACLs on our squid installation. This is working well, but we want to create statistics on how many clients were "caught" trying to access blocked sites. Currently, we're grepping the log

Re: [squid-users] Change are not taking

2017-05-19 Thread Dijxie
W dniu 19.05.2017 o 19:13, Patrick Flaherty pisze: Hi, I am making changes to my squid.conf, yet they don’t seem to take. Is there something I’m missing? Any help appreciated # Squid Proxy Configuration # Network(s) where proxy traffic is originating # acl localnet src 10.0.0.0/8

Re: [squid-users] How to redirect all squid's error pages to one?

2017-05-19 Thread Dijxie
W dniu 19.05.2017 o 17:16, Amos Jeffries pisze: On 20/05/17 02:55, Dijxie wrote: W dniu 19.05.2017 o 15:13, Amos Jeffries pisze: On 20/05/17 00:44, Dijxie wrote: Hi list, 1. I'd like to redirect **all** squid error pages to one, universal, preferably internal squid error page. For s

Re: [squid-users] How to redirect all squid's error pages to one?

2017-05-19 Thread Dijxie
W dniu 19.05.2017 o 15:13, Amos Jeffries pisze: On 20/05/17 00:44, Dijxie wrote: Hi list, 1. I'd like to redirect **all** squid error pages to one, universal, preferably internal squid error page. For sure I can symlink every error page to one, but is there a clener way? I'm not

[squid-users] How to redirect all squid's error pages to one?

2017-05-19 Thread Dijxie
Hi list, 1. I'd like to redirect **all** squid error pages to one, universal, preferably internal squid error page. For sure I can symlink every error page to one, but is there a clener way? I'm not sure if I get it: http://www.squid-cache.org/Doc/config/deny_info/ 2. And then, using %e code

Re: [squid-users] Documentation for squidclient?

2017-05-18 Thread Dijxie
W dniu 18.05.2017 o 15:07, erdosain9 pisze: And for example, if i have this Negotiate Authenticator Statistics: program: /lib64/squid/negotiate_kerberos_auth number active: 20 of 20 (0 shutting down) requests sent: 23980 replies received: 23980 queue length: 0 avg service time: 8 msec ID #

Re: [squid-users] Documentation for squidclient?

2017-05-18 Thread Dijxie
W dniu 18.05.2017 o 14:48, erdosain9 pisze: Hi. Where i can find documentation for the opcion on squidclient, many of them are self-explanatory but for example this: [root@squid ~]# squidclient mgr:external_acl HTTP/1.1 200 OK Server: squid/3.5.20 Mime-Version: 1.0 Date: Thu, 18 May 2017 12:40:5

Re: [squid-users] Slow server ¿?

2017-05-17 Thread Dijxie
On 2017-05-17 19:43, erdosain9 wrote: Hi. The server is serving web pages very slow. Not related to bandwith of delay pools... Thanks -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Slow-server-tp4682400p4682440.html Sent from the Squid - Users mailing

Re: [squid-users] Squid custom error page

2017-05-17 Thread Dijxie
W dniu 17.05.2017 o 13:32, chcs pisze: Firefox 53.0.2 , Chrome 58.3029 y Opera 44 display "Proxy Server Refused Connection" page, instead of Squid custom error page, when connect to HTTPS site which blocked by proxy server. For example we try to connect to https://www.something.com via Squid prox

Re: [squid-users] WARNING: All 20/20 negotiateauthenticator processes are busy.

2017-05-15 Thread Dijxie
On 2017-05-15 20:53, erdosain9 wrote: http_port 192.168.1.215:3128 Hi, My guess is since you've declared it this way (I never did), you should try consequently: squidclient -h 192.168.1.215 -p 3128 mgr:negotiateauthenticator -h stands for host; running squidclient without this parameter make

Re: [squid-users] WARNING: All 20/20 negotiateauthenticator processes are busy.

2017-05-12 Thread Dijxie
W dniu 12.05.2017 o 17:30, erdosain9 pisze: Hi. Thanks! We have 100 users... What would you think is a good "auth_param negotiate children"?? The one that does not gives you a warning. One of my squids has 12 users who can kill 18 helpers and generate 1.2GB log within one day; it all

Re: [squid-users] WARNING: All 20/20 negotiateauthenticator processes are busy.

2017-05-11 Thread Dijxie
W dniu 11.05.2017 o 17:27, erdosain9 pisze: Hi. Im having this problem. may 11 11:26:23 squid..lan squid[32138]: WARNING: All 30/30 negotiateauthenticator processes are busy. may 11 11:26:23 squid..lan squid[32138]: WARNING: 30 pending requests queued may 11 11:26:23 squid..lan squid

Re: [squid-users] Squid - using NTLM for SSO

2017-05-09 Thread Dijxie
Hello list, I need your help with a Squid-Proxy (3.5) NTLM Auth, the aim is to use SSO for my windows clients. My Windows-Clients are using Active-Directory running on a Samba4-PDC. I set up ldap basic auth in a developer environment, now I want to achieve SSO. (using NTLM?) The Documen

Re: [squid-users] Squid proxy without name resolution for internet adresses behind parent proxy

2017-04-28 Thread Dijxie
W dniu 28.04.2017 o 11:00, mbaltruschat pisze: Hello everybody, i am trying to migrate my old squid 2.7 to 3.5 and are getting stuck, the new proxy is very slow, requests need very long until they open, i guess ist a name resolution problem, because the proxy cant resolve internet domain names b

Re: [squid-users] Unliked SSL cipher

2017-04-19 Thread dijxie
Do you recieve the same error while connecting to https://www.wikipedia.org? If you connect to https://91.198.174.192/* directly, your browser schould warn you about ssl issue; that is because of: CN = *.wikipedia.org SAN= *.wikipedia.org wikipedia.org *.m.wikipedia.org *.zero.wikipedia.org