Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-08 Thread Alex Rousskov
On 2024-07-05 20:55, Jonathan Lee wrote: FIXED I think it wanted a new certificate generated mine became to weak I needed one that ECDSA with prime256v sha256 and not RSA anymore that solved my errors Glad you found a solution! And if these errors resurface, you now have a blueprint for the

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
FIXED I think it wanted a new certificate generated mine became to weak I needed one that ECDSA with prime256v sha256 and not RSA anymore that solved my errors The error is gone when this cert is used :) > On Jul 5, 2024, at 14:33, Jonathan Lee wrote: > > However even with it marked as no

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
However even with it marked as no 05.07.2024 14:30:46 ERROR: failure while accepting a TLS connection on conn4633 local=192.168.1.1:3128 remote=192.168.1.5:49721 FD 30 flags=1: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000417+TLS_IO_ERR=1 continues I am going to take a break please if anyone kn

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
a certificate from was the non iMac >>>> >>>> The iMac keeps sending change cipher requests and wants TLS1.3 over and >>>> over as soon as a TLS1.2 pops up it works >>>> >>>> That one has the certificate however that system the Toshiba do

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
s with this error. I highly suspect that I need to enable TLS1.3 >>> would you agree? >>> >>> -Original Message- >>> From: Alex Rousskov >>> Sent: Friday, July 5, 2024 11:02 AM >>> To: squid-users >>> Cc: Jonathan Lee >&

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
as the certificate however that system the Toshiba does not have >> any issues with this error. I highly suspect that I need to enable TLS1.3 >> would you agree? >> >> -Original Message- >> From: Alex Rousskov >> Sent: Friday, July 5, 2024 11:02 AM >>

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
> -Original Message- > From: Alex Rousskov > Sent: Friday, July 5, 2024 11:02 AM > To: squid-users > Cc: Jonathan Lee > Subject: Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6 > > On 2024-07-05 12:02, Jonathan Lee wrote: > >>>

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread jonathanlee571
I need to enable TLS1.3 would you agree? -Original Message- From: Alex Rousskov Sent: Friday, July 5, 2024 11:02 AM To: squid-users Cc: Jonathan Lee Subject: Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6 On 2024-07-05 12:02, Jonathan Lee wrote: > > Alex: I rec

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Alex Rousskov
On 2024-07-05 12:02, Jonathan Lee wrote: > Alex: I recommend determining what that CA is in these cases (e.g., by capturing raw TLS packets and matching them with connection information from A000417 error messages in cache.log or %err_detail in access.log). I have Wireshark running do I ju

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
Side note: I have just found while analyzing Wireshark packets that this A000417 error only occurs with use of the iMac and the Safari browser, this does not occur on Windows 10 with the Edge browser. > On Jul 5, 2024, at 09:02, Jonathan Lee wrote: > > per > > As the next step in triage, I

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
per As the next step in triage, I recommend determining what that CA is in these cases (e.g., by capturing raw TLS packets and matching them with connection information from A000417 error messages in cache.log or %err_detail in access.log). I have Wireshark running do I just look for informa

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Jonathan Lee
Thanks for the email and support with this. I will get wireshark running on the client and get the info required. Yes the information prior is from the firewall side outside of the proxy testing from the demilitarized zone area. I wanted to test this first to rule that out as it’s coming in from

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Alex Rousskov
On 2024-07-04 19:12, Jonathan Lee wrote: You also stated .. " my current working theory suggests that we are looking at a (default) signUntrusted use case.” I noticed for Squid documents that default is now set to off .. The http_port option you are looking at now is not the directive I was

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Alex Rousskov
On 2024-07-04 19:02, Jonathan Lee wrote: I do not recommend changing your configuration at this time. I recommend rereading my earlier recommendation and following that instead: "As the next step in triage, I recommend determining what that CA is in these cases (e.g., by capturing raw TLS packe

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-05 Thread Alex Rousskov
On 2024-07-04 18:12, Jonathan Lee wrote: I know before I could use tls_outgoing_options cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:HIGH:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
It does not recognize this directive 2024/07/04 16:16:46| Processing: url_rewrite_children 32 startup=8 idle=4 concurrency=0 2024/07/04 16:16:46| Processing: tls-default-ca on 2024/07/04 16:16:46| /usr/local/etc/squid/squid.conf(235): unrecognized: 'tls-default-ca’ Or with use of = > On Jul 4

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
You also stated .. " my current working theory suggests that we are looking at a (default) signUntrusted use case.” I noticed for Squid documents that default is now set to off .. http://www.squid-cache.org/Versions/v5/cfgman/http_port.html http://www.squid-cache.org/Versions/v6/cfgman/http_po

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
>>> I do not recommend changing your configuration at this time. I recommend >>> rereading my earlier recommendation and following that instead: "As the >>> next step in triage, I recommend determining what that CA is in these cases >>> (e.g., by capturing raw TLS packets and matching them with

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
Sorry tls_outgoing_options cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS tls_outgoing_options options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE Would I add this here? > On Jul 4, 2024, at 15:12, Jonathan Lee wrote: > > I know before I could use > > tls_outgoing_opt

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
I know before I could use tls_outgoing_options cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:HIGH:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS However with the update I am seeing ER

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Alex Rousskov
On 2024-07-04 15:37, Jonathan Lee wrote: in Squid.conf I have nothing with that detective. Sounds good; sslproxy_cert_sign default should work OK in most cases. I mentioned signUntrusted algorithm so that you can discover (from the corresponding sslproxy_cert_sign documentation) which CA/cer

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
Maybe adding it like this … sslproxy_cert_sign signTrusted bump_only_mac https_login splice_only_mac NoBumpDNS NoSSLIntercept ssl_bump peek step1 miss_access deny no_miss active_use ssl_bump splice https_login active_use ssl_bump splice splice_only_mac splice_only active_use ssl_bump splice NoBum

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Jonathan Lee
I found it # TAG: sslproxy_cert_sign # #sslproxy_cert_sign acl ... # #The following certificate signing algorithms are supported: # # signTrusted # Sign using the configured CA certificate which is usually # placed in and trusted by end-user

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Alex Rousskov
On 2024-07-04 12:11, Jonathan Lee wrote: failure while accepting a TLS connection on conn5887 local=192.168.1.1:3128 SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000417 A000417 is an "unknown CA" alert sent by client to Squid while the client is trying to establish a TLS connection to/through Squid. The

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-04 Thread Alex Rousskov
On 2024-07-03 13:56, Jonathan Lee wrote: Hello fellow Squid users does anyone know how to fix this issue? I counted about eight different "issues" in your cache.log sample. Most of them are probably independent. I recommend that you explicitly pick _one_, search mailing list archives for prev

Re: [squid-users] Squid Cache Issues migration from 5.8 to 6.6

2024-07-03 Thread Jonathan Lee
I forgot to mention my certificates I use on squid was generated from this method openssl req -x509 -new -nodes -key myProxykey.key -sha256 -days 365 -out myProxyca.pem Sent from my iPhone > On Jul 3, 2024, at 10:56, Jonathan Lee wrote: > > Hello fellow Squid users does anyone know how to

Re: [squid-users] Squid Cache 6.9 on Ubuntu 22.04.3 LTS. Not caching large files to disk.

2024-04-12 Thread Jonathan Lee
making progress, I just need to understand where I am going wrong with > SSL Bump for https connections. Why it is still tunnelling? If I fix that I > think it will cache/pull from cache the https downloads too. #fingerscrossed > > Any suggestions or decent web blogs/etc on how to con

Re: [squid-users] Squid Cache 6.9 on Ubuntu 22.04.3 LTS. Not caching large files to disk.

2024-04-12 Thread PinPin Poola
uggestions or decent web blogs/etc on how to configure it? Have a great weekend, Many Thanks Pin From: Jonathan Lee Sent: 12 April 2024 15:10 To: PinPin Poola Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache 6.9 on Ubuntu 22.04.3 LT

Re: [squid-users] Squid cache questions

2024-04-06 Thread Jonathan Lee
Thanks for the reply I am using the built in StoreID program however it requires the database file so I have it only set to the items in the dynamic cache settings custom refresh areas. The rewrite program should redirect to pull from the cache right? Only for bumped connections and or cab fil

Re: [squid-users] Squid cache questions

2024-04-06 Thread Amos Jeffries
On 6/04/24 11:34, Jonathan Lee wrote: if (empty($settings['sslproxy_compatibility_mode']) || ($settings['sslproxy_compatibility_mode'] == 'modern')) { // Modern cipher suites $sslproxy_cipher = "EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+

Re: [squid-users] Squid cache questions

2024-04-06 Thread Amos Jeffries
On 5/04/24 17:25, Jonathan Lee wrote: ssl_bump splice https_login ssl_bump splice splice_only ssl_bump splice NoSSLIntercept ssl_bump bump bump_only markBumped ssl_bump stare all acl markedBumped note bumped true url_rewrite_access deny markedBumped for good hits should the url_rewirte_access d

Re: [squid-users] Squid cache questions

2024-04-05 Thread Jonathan Lee
if (empty($settings['sslproxy_compatibility_mode']) || ($settings['sslproxy_compatibility_mode'] == 'modern')) { // Modern cipher suites $sslproxy_cipher = "EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECD

Re: [squid-users] Squid cache questions

2024-04-04 Thread Amos Jeffries
On 4/04/24 17:48, Jonathan Lee wrote: Is there any particular order to squid configuration?? Yes. Does this look correct? Best way to find out is to run "squid -k parse", which should be done after upgrades as well to identify and

Re: [squid-users] Squid-cache authentication is not working

2023-09-09 Thread Jason Long
Hello, Thanks again. You right, I must move the following lines after the authentication lines: http_access allow localnet http_access allow localhost http_access deny all It worked. On Sunday, September 10, 2023 at 01:57:32 AM GMT+3:30, Alex Rousskov wrote: On 2023-09-09 15:09, Jason Lo

Re: [squid-users] Squid-cache authentication is not working

2023-09-09 Thread Alex Rousskov
On 2023-09-09 18:27, Alex Rousskov wrote: On 2023-09-09 15:09, Jason Long wrote: My Squid-cache server IP is "192.168.1.2". I use Mozilla Firefox and set the proxy to "192.168.1.2:3128". What information do you need to tell you? Do you see Firefox requests/transactions reflected in Squid acce

Re: [squid-users] Squid-cache authentication is not working

2023-09-09 Thread Alex Rousskov
On 2023-09-09 15:09, Jason Long wrote: My Squid-cache server IP is "192.168.1.2". I use Mozilla Firefox and set the proxy to "192.168.1.2:3128". What information do you need to tell you? Do you see Firefox requests/transactions reflected in Squid access.log? Anything in Squid cache.log? Sorr

Re: [squid-users] Squid-cache authentication is not working

2023-09-09 Thread Jason Long
Hi Alex,Thank you so much for your reply.My Squid-cache server IP is "192.168.1.2".I use Mozilla Firefox and set the proxy to "192.168.1.2:3128".What information do you need to tell you? Sent from Yahoo Mail on Android On Sat, Sep 9, 2023 at 5:56 PM, Alex Rousskov wrote: On 2023-09-09 09

Re: [squid-users] Squid-cache authentication is not working

2023-09-09 Thread Alex Rousskov
On 2023-09-09 09:09, Jason Long wrote: Hello, I installed the Squid-cache on Debian 12, then I installed the Apache utils: $ sudo apt install apache2-utils After it, I did the following steps: $ sudo touch /etc/squid/passwd $ sudo chown proxy /etc/squid/passwd Then: $ sudo htpasswd /etc/squi

Re: [squid-users] Squid-Cache VS PHP, put some things in perspective

2022-04-24 Thread Eliezer Croitoru
n any helpers crashes. Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-users On Behalf Of Amos Jeffries Sent: Thursday, April 14, 2022 07:18 To: squid-users@lists.squid-cache.org Subject: Re: [squid-users]

Re: [squid-users] Squid-Cache VS PHP, put some things in perspective

2022-04-17 Thread Eliezer Croitoru
hanks, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-users On Behalf Of Amos Jeffries Sent: Thursday, April 14, 2022 07:18 To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid-Cache V

Re: [squid-users] Squid-Cache VS PHP, put some things in perspective

2022-04-13 Thread Amos Jeffries
On 13/04/22 10:30, Eliezer Croitoru wrote: I am looking for adventurous Squid Users which wants to help me test if PHP 7.4+ still possess the same old 5.x STDIN bugs. Hi Eliezer, Thanks for taking on a re-investingation. FTR, the old problem was not stdin itself. The issue was that PHP w

Re: [squid-users] squid cache

2021-03-01 Thread Majed Zouhairy
Thanks for, at least, the explanation On 3/1/21 6:12 PM, Alex Rousskov wrote: On 3/1/21 2:07 AM, Majed Zouhairy wrote: i tried this, but neither the https download bandwidth restriction nor caching seems to be working as expected Squid cannot cache HTTP responses without bumping HTTPS traffic

Re: [squid-users] squid cache

2021-03-01 Thread Alex Rousskov
On 3/1/21 2:07 AM, Majed Zouhairy wrote: > i tried this, but neither the https download bandwidth restriction nor > caching seems to be working as expected Squid cannot cache HTTP responses without bumping HTTPS traffic. This is a protocol-level limitation, not a bug. There are known delay pools

Re: [squid-users] squid cache

2021-02-28 Thread Majed Zouhairy
i tried this, but neither the https download bandwidth restriction nor caching seems to be working as expected acl slower src 10.46.10.78 acl localnet src 10.46.10.0/24 acl SSL_ports port 443 acl Safe_ports port 80 # http acl Safe_ports port 8080# http acl Safe_ports port 21

Re: [squid-users] Squid cache with SSL

2020-05-27 Thread Eliezer Croitoru
-28704261Email: ngtech1...@gmail.com From: Amos JeffriesSent: Monday, May 25, 2020 1:02 PMTo: squid-users@lists.squid-cache.orgSubject: Re: [squid-users] Squid cache with SSL On 25/05/20 8:09 pm, Andrey Etush-Koukharenko wrote:> Hello, I'm trying to set up a cache for GCP signed URLs using squid 4.

Re: [squid-users] Squid cache with SSL

2020-05-25 Thread Amos Jeffries
On 25/05/20 8:09 pm, Andrey Etush-Koukharenko wrote: > Hello, I'm trying to set up a cache for GCP signed URLs using squid 4.10 > I've set ssl_bump: > *http_port 3128 ssl-bump cert=/etc/ssl/squid_ca.pem > generate-host-certificates=on dynamic_cert_mem_cache_size=4MB > > sslcrtd_program /usr/lib/sq

Re: [squid-users] squid-cache proxy which does it all

2020-01-09 Thread robert k Wild
thanks for this Amos, really appreciate it :) On Thu, 9 Jan 2020 at 19:00, Amos Jeffries wrote: > On 9/01/20 8:34 pm, robert k Wild wrote: > > hi all, > > > > I have made a script for squid that installs the following – > > > > Squid – http proxy server > > Squid ssl-bump – https interception fo

Re: [squid-users] squid-cache proxy which does it all

2020-01-09 Thread Amos Jeffries
On 9/01/20 8:34 pm, robert k Wild wrote: > hi all, > > I have made a script for squid that installs the following – > > Squid – http proxy server > Squid ssl-bump – https interception for squid > C-ICAP – icap server > clamAV – AV engine to detect trojan viruses malware etc > squidclamav – to mak

Re: [squid-users] Squid Cache Problem

2019-07-25 Thread Devilindisguise
Great, thank you. We'll take a look at the DNS cache and see what we find. -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-ca

Re: [squid-users] Squid Cache Problem

2019-07-24 Thread Matus UHLAR - fantomas
On 25.07.19 00:41, Devilindisguise wrote: We have what is probably an easy one. Some Windows servers use a locally installed Squid proxy instance for all outbound traffic. These servers also make use of some F5 GTM (DNS) servers to provide a resilient inter-DC DNS topology. Essentially what shou

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Antony Stone
On Saturday 20 October 2018 at 16:53:12, Mujtaba Hassan Madani wrote: > Hi, > > now it works through URL > > http://196.202.134.253:3128/squid-internal-mgr/info instead of > http://proxy.com:3128/squid-internal-mgr/info Yes, that is because proxy,com does not belong to you - it points to someon

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Mujtaba Hassan Madani
-cache.org Subject: Re: [squid-users] Squid Cache Server On Saturday 20 October 2018 at 15:59:36, Mujtaba Hassan Madani wrote: > Hi Antony, > > this is the first IP Connection to 34.194.132.99 failed. That is the address which "proxy,com" resolves to on my machine too. >

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Antony Stone
On Saturday 20 October 2018 at 15:59:36, Mujtaba Hassan Madani wrote: > Hi Antony, > > this is the first IP Connection to 34.194.132.99 failed. That is the address which "proxy,com" resolves to on my machine too. > the IP of my server is 196.202.134.253 So, does this give you any clues as to

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Mujtaba Hassan Madani
.org Subject: Re: [squid-users] Squid Cache Server On Saturday 20 October 2018 at 14:56:33, Mujtaba Hassan Madani wrote: > Hi Amos, > >I get attached message when trying to access cache manger through web > interface below is my full URL > > http://proxy.com:3128/squid-interna

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Antony Stone
On Saturday 20 October 2018 at 14:56:33, Mujtaba Hassan Madani wrote: > Hi Amos, > >I get attached message when trying to access cache manger through web > interface below is my full URL > > http://proxy.com:3128/squid-internal-mgr/info 1. What IP address does "proxy.com" resolve to on your

Re: [squid-users] Squid Cache Server

2018-10-20 Thread Mujtaba Hassan Madani
ries Sent: Saturday, October 13, 2018 7:58:34 AM To: Mujtaba Hassan Madani; squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server On 12/10/18 7:55 AM, Mujtaba Hassan Madani wrote: > Hi Amos, > > I have change my domain name to proxy instead of that long o

Re: [squid-users] Squid Cache Server

2018-10-13 Thread Amos Jeffries
On 12/10/18 7:55 AM, Mujtaba Hassan Madani wrote: > Hi Amos, > >     I have change my domain name to proxy instead of that long one per > your advice i was wondering where to get information about my current > caching files and it's size ? i login to > http://proxy:3128/squid-internal-mgr/info f

Re: [squid-users] Squid Cache Server

2018-10-06 Thread Mujtaba Hassan Madani
? From: squid-users on behalf of Amos Jeffries Sent: Saturday, October 6, 2018 4:41:23 AM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server On 6/10/18 6:22 AM, Mujtaba Hassan Madani wrote: > Hi, > > I also get the attached error w

Re: [squid-users] Squid Cache Server

2018-10-05 Thread Amos Jeffries
On 6/10/18 6:22 AM, Mujtaba Hassan Madani wrote: > Hi, > >   I also get the attached error while been trying to access through web > interface for private IP address. I managed to add the IP on the bypass > proxy server for the local address but, i cant do for all since I have > many private IP

Re: [squid-users] Squid Cache Server

2018-10-05 Thread Mujtaba Hassan Madani
behalf of Mujtaba Hassan Madani Sent: Wednesday, September 19, 2018 1:46:44 PM To: Amos Jeffries; squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server Hi Amos, thanks for your concern, as I informed you Iam looking to install Squid on Ubuntu Linux server for Caching

Re: [squid-users] Squid Cache Server

2018-09-19 Thread Mujtaba Hassan Madani
: Sunday, September 16, 2018 4:58:37 PM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server On 15/09/18 12:13 PM, Mujtaba Hassan Madani wrote: > Hi Amos, > >you did not get back to me about my below concern > I responded to your concern about copyrigh

Re: [squid-users] Squid Cache Server

2018-09-16 Thread Amos Jeffries
On 15/09/18 12:13 PM, Mujtaba Hassan Madani wrote: > Hi Amos, > >    you did not get back to me about my below concern  > I responded to your concern about copyright. I do not see anything else in your messages as expressing a concern to be responded to. Amos >

Re: [squid-users] Squid Cache Server

2018-09-14 Thread Mujtaba Hassan Madani
Hi Amos, you did not get back to me about my below concern Regards Mujtaba H, From: Mujtaba Hassan Madani Sent: Thursday, September 13, 2018 5:36:48 PM To: Amos Jeffries; squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server

Re: [squid-users] Squid Cache Server

2018-09-13 Thread Mujtaba Hassan Madani
aba H, From: squid-users on behalf of Amos Jeffries Sent: Wednesday, September 12, 2018 2:54:37 PM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server On 13/09/18 2:16 AM, Mujtaba Hassan Madani wrote: > Dear Squid Team, > > how does co

Re: [squid-users] Squid Cache Server

2018-09-12 Thread Amos Jeffries
On 13/09/18 2:16 AM, Mujtaba Hassan Madani wrote: > Dear Squid Team, > >      how does content provider prevent it from been cached while passing > through squid proxy it's by a copy right law No. Contents which can be transferred through a proxy are implicitly licensed for re-distribution. Le

Re: [squid-users] Squid Cache Server

2018-09-12 Thread Mujtaba Hassan Madani
jtaba H, From: squid-users on behalf of Antony Stone Sent: Tuesday, September 11, 2018 8:54:05 AM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server On Tuesday 11 September 2018 at 10:43:13, Mujtaba Hassan Madani wrote: >

Re: [squid-users] Squid Cache Server

2018-09-11 Thread Antony Stone
On Tuesday 11 September 2018 at 10:43:13, Mujtaba Hassan Madani wrote: > Hi Squid team, > > I just want to no if squid can cache software for example windows > update, Java,etc. Squid doesn't care what a file is for - whether it's "software", web pages, images, music, video... Squid wi

Re: [squid-users] squid cache takes a break

2017-09-13 Thread Vieri
Thanks for the suggestion. I'm sure ufdbguard works great even though it's not maintained/updated on my distro (Gentoo). I use ready-made helpers/redirectors like squidGuard on other systems. However, on this system I wanted to avoid depending on extra software. I also wanted to make my own help

Re: [squid-users] squid cache takes a break

2017-09-12 Thread Eliezer Croitoru
squid-users@lists.squid-cache.org Subject: Re: [squid-users] squid cache takes a break It is just enough not to reinvent the wheel. What needs op - already exists and is called ufdbguard. And it's works perfectly with shallalist :) 13.09.2017 2:51, Eliezer Croitoru пишет: > I just must ad

Re: [squid-users] squid cache takes a break

2017-09-12 Thread Yuri
oun...@lists.squid-cache.org] On > Behalf Of Amos Jeffries > Sent: Tuesday, September 12, 2017 16:08 > To: squid-users@lists.squid-cache.org > Subject: Re: [squid-users] squid cache takes a break > > On 12/09/17 22:59, Vieri wrote: >> >&g

Re: [squid-users] squid cache takes a break

2017-09-12 Thread Eliezer Croitoru
...@lists.squid-cache.org] On Behalf Of Amos Jeffries Sent: Tuesday, September 12, 2017 16:08 To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] squid cache takes a break On 12/09/17 22:59, Vieri wrote: > > > From: Amos Jeffries >> >>

Re: [squid-users] squid cache takes a break

2017-09-12 Thread Amos Jeffries
On 12/09/17 22:59, Vieri wrote: From: Amos Jeffries That is all it needs to do to begin with; parse off the numeric value from the input line and send it back as prefix on the output line. The helper does not need threading or anything particularly special

Re: [squid-users] squid cache takes a break

2017-09-12 Thread Vieri
From: Amos Jeffries > > That is all it needs to do to begin with; parse off the numeric value > from the input line and send it back as prefix on the output line. The > helper does not need threading or anything particularly special for the > > minimal support

Re: [squid-users] squid cache takes a break

2017-09-11 Thread Amos Jeffries
On 11/09/17 20:49, Vieri wrote: From: Amos Jeffries a) start fewer helpers at a time. b) reduce cache_mem. c) add concurrency support to the helpers. So I decreased the startup, idle, cache_mem values: # egrep 'startup=|idle=' squid.conf external_acl_type

Re: [squid-users] squid cache takes a break

2017-09-11 Thread Vieri
From: Amos Jeffries > > a) start fewer helpers at a time. > > b) reduce cache_mem. > > c) add concurrency support to the helpers. So I decreased the startup, idle, cache_mem values: # egrep 'startup=|idle=' squid.conf external_acl_type bllookup ttl=86400 nega

Re: [squid-users] squid cache takes a break

2017-09-09 Thread Amos Jeffries
On 09/09/17 05:39, Vieri wrote: Hi, Sorry for the title, but I really don't know how to describe what just happened today. It's really odd. I previously posted a few similar issues which were all fixed if I increased certain parameters (ulimits, children-{max,startup,idle}, TTL, etc.). This

Re: [squid-users] squid cache peer not rotating over round robin !

2017-09-05 Thread Amos Jeffries
On 05/09/17 07:17, --Ahmad-- wrote: hello folks I’m trying to rotate squid request over several peers my config are below but they are only stuck with 1 peer . acl custNet dstdomain .trustly.com .ing.nl .adyen.com .rabobank.nl .abn.nl .iplocation.net .abnamro.com .abnamro.nl .abnamro.nl cac

Re: [squid-users] Squid Cache to Users at Full Bandwidth

2017-05-06 Thread joseph
you have to mark packet on mangle the DSCP(tos) = 12 first did you and in squid add qos_flows tos local-hit=0x30 miss=0xFF and in queues pic the marked packet name so it will serve the cached HIT to your clients if you can not do it i help u out -- View this message in context: http:

Re: [squid-users] Squid Cache to Users at Full Bandwidth

2017-05-06 Thread christian brendan
tachment was scrubbed... > URL: <http://lists.squid-cache.org/pipermail/squid-users/ > attachments/20170505/f49ed72e/attachment-0001.html> > > -- > > Message: 2 > Date: Fri, 5 May 2017 23:46:29 +0600 > From: Yuri Voinov > To: squid-users@li

Re: [squid-users] Squid Cache to Users at Full Bandwidth

2017-05-05 Thread Antony Stone
On Friday 05 May 2017 at 16:18:33, christian brendan wrote: > Squid Version 3.5.20 > Cento 7 > Mikrotik RouterBoard v 6.39.1 > Users IP: 192.168.1.0/24 > Squid ip: 192.168.2.1 > > Traffic to squid is routed > > i would like users to have full LAN bandwidth access to squid server, i > have tried

Re: [squid-users] Squid Cache to Users at Full Bandwidth

2017-05-05 Thread Yuri Voinov
http://wiki.squid-cache.org/ 05.05.2017 21:18, christian brendan пишет: > Squid Version 3.5.20 > Cento 7 > Mikrotik RouterBoard v 6.39.1 > Users IP: 192.168.1.0/24 > Squid ip: 192.168.2.1 > > Traffic to squid is routed > > i would like users to have full LAN bandwidth acce

Re: [squid-users] squid cache analysis

2017-04-06 Thread Antony Stone
On Thursday 06 April 2017 at 12:27:54, Punyasloka Arya wrote: > squid version:3.3 > OS:centos Which version of CentOS? How was Squid installed? Precisely which version of 3.3 are you using? > The squid cache is not functioning properly You'll have to be more specific than that - what *is* wor

Re: [squid-users] Squid Cache: Version 3.5.16 and ext_ldap_group_acl

2016-04-12 Thread Thomas Elsäßer
Am 12-04-2016 10:58, schrieb Amos Jeffries: On 12/04/2016 8:36 p.m., Thomas Elsäßer wrote: Dear all, I call from Shell: /usr/local/squid/libexec/ext_ldap_group_acl -d -R -b "OU=UMW,DC=a,DC=b,DC=de" -D "...@a.b.de" -w "XXX" \ -f "(&(objectClass=person)(sAMAccountName=%v)(MemberOf=CN=%g

Re: [squid-users] Squid Cache: Version 3.5.16 and ext_ldap_group_acl

2016-04-12 Thread Amos Jeffries
On 12/04/2016 8:36 p.m., Thomas Elsäßer wrote: > Dear all, > > I call from Shell: > > /usr/local/squid/libexec/ext_ldap_group_acl -d -R -b > "OU=UMW,DC=a,DC=b,DC=de" -D "...@a.b.de" -w "XXX" \ > -f > "(&(objectClass=person)(sAMAccountName=%v)(MemberOf=CN=%g,OU=DomLokaleGruppen,OU=Gruppen

Re: [squid-users] squid cache

2016-02-09 Thread Amos Jeffries
On 10/02/2016 6:16 a.m., turgut kalfaoğlu wrote: > Hi again.. I have a squid setup with two servers; one acting as "parent" > and only getting requests from the child, > and the other one actually serves people as a transparent accelerator > for the slow internet. What do you mean exactly? "transp

Re: [squid-users] squid cache peer issues

2015-12-21 Thread Alex Samad
Hi seems like .12 is now available for me. I will apply and retest. is there anything you would like me to do if I see it again ? A On 21 December 2015 at 21:26, Amos Jeffries wrote: > On 21/12/2015 2:00 p.m., Alex Samad wrote: >> Hi >> >> running on centos 6.7 >> >> 3.5.12 still not available

Re: [squid-users] squid cache peer issues

2015-12-21 Thread Amos Jeffries
On 21/12/2015 2:00 p.m., Alex Samad wrote: > Hi > > running on centos 6.7 > > 3.5.12 still not available on centos 6. > > rpm -qa | grep squid > squid-helpers-3.5.11-1.el6.x86_64 > squid-3.5.11-1.el6.x86_64 > > This is the 2 cache_peer statements I use > > # on alcdmz1 > cache_peer gsdmz1.yiel

Re: [squid-users] squid cache

2015-09-30 Thread Amos Jeffries
On 1/10/2015 8:47 a.m., Antony Stone wrote: > On Wednesday 30 September 2015 at 21:35:32, Magic Link wrote: > >> Hi,i configure squid to use cache. It seems to work because when i did a >> try with a software's download, the second download is TCP_HIT in the >> access.log. > > Congratulations. >

Re: [squid-users] squid cache

2015-09-30 Thread Amos Jeffries
On 1/10/2015 8:41 a.m., Leonardo Rodrigues wrote: > Em 30/09/15 16:35, Magic Link escreveu: >> Hi, >> >> i configure squid to use cache. It seems to work because when i did a >> try with a software's download, the second download is TCP_HIT in the >> access.log. >> The question i have is : why the

Re: [squid-users] squid cache

2015-09-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Don't do it. Never. You make most sites broken for your clients. Dynamic content not ended up by cgi-bin. Caching dynamic content is not so simple and trivial task. 01.10.15 1:35, Magic Link пишет: > Hi,i configure squid to use cache. It seems t

Re: [squid-users] squid cache

2015-09-30 Thread Antony Stone
On Wednesday 30 September 2015 at 21:35:32, Magic Link wrote: > Hi,i configure squid to use cache. It seems to work because when i did a > try with a software's download, the second download is TCP_HIT in the > access.log. Congratulations. > The question i have is : why the majority of requests

Re: [squid-users] squid cache

2015-09-30 Thread Leonardo Rodrigues
Em 30/09/15 16:35, Magic Link escreveu: Hi, i configure squid to use cache. It seems to work because when i did a try with a software's download, the second download is TCP_HIT in the access.log. The question i have is : why the majority of requests can't be cached (i have a lot of tcp_miss/2

Re: [squid-users] Squid cache youtube and other websites

2015-05-25 Thread Reet Vyas
Hi Yuri, Thanks for nice info. As I mentioned I have only tplink TL-R470T router and machine with configuration of Cent OS 6 HDD 1 TB RAM 32 GB So Is this possible with above router or do I have to change my router for same. I can do this using IPtables only On Mon, May 25, 2015 at 4:57 PM, Yu

Re: [squid-users] Squid cache youtube and other websites

2015-05-25 Thread Yuri Voinov
Look, Ma. ;) I'm a LumberJack :)) http://i.imgur.com/NGn6Ao4.png http://i.imgur.com/Uz0zXut.png Note, that Youtube now uses QUIC protocol (especially in Chrome), which cannot be processed by Squid ever. To cache Youtube, you must solve two tasks: 1. Completely force clients use HTTP/HTTPS

Re: [squid-users] Squid cache youtube and other websites

2015-05-25 Thread Reet Vyas
Hi Thanks Dan for info. I searched google about LUSCA and scripts available but I don't think it is working now. On Mon, May 25, 2015 at 12:21 PM, wrote: > Firstly, I think the biggest roadblocks you’re going to hit with caching > YouTube are: > > 1) It’s all encrypted now (thanks Google). Sq

Re: [squid-users] Squid cache youtube and other websites

2015-05-24 Thread dan
Firstly, I think the biggest roadblocks you’re going to hit with caching YouTube are: 1) It’s all encrypted now (thanks Google). Squid can’t cache what it can’t see inside an SSL tunnel. 2) They have a pretty intense CDN which you’ll need a StoreID helper to deal with. There are peop

Re: [squid-users] Squid cache Monitoring

2015-04-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 cachemrg.cgi SARG squidanalyzer sqtop Munin+Squid plugins 27.04.15 19:05, Hierony Manurung пишет: > Dear Fellow, > > Is there another tools / GUI tools to see Squid caching performance? > I know that when we want to see whether the request is HIT/

Re: [squid-users] Squid cache Monitoring

2015-04-27 Thread HackXBack
you can use monitorix -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-cache-Monitoring-tp4670937p4670938.html Sent from the Squid - Users mailing list archive at Nabble.com. ___ squid-users mailing list squid-

Re: [squid-users] squid cache peer with many sessions round robin to the same destination , is that possible ?

2015-01-27 Thread Amos Jeffries
On 28/01/2015 7:04 p.m., Ahmad wrote: > Hi mates , > > > > I have a proxy provider that give me may sessions , and each session is per > username and pwd. > > As an example , I have the provider 1.1.1.1 with 5 usernames > > Each username will give me different ip. > > > > I need to do on

Re: [squid-users] squid cache Large rock with aufs optimization for bandwidth saving

2014-11-16 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 17/11/2014 1:26 p.m., Ahmed Allzaeem wrote: > Hi Amos , thanks for reply. > > But I think using large rock will let the memory cache size be >32 > ??? am I correct ? > Maybe no, maybe yes. Shared memory is a separate feature to large rock. They

  1   2   >