Re: [squid-users] squid3/4 compilation error with Centos8/RH8

2022-05-02 Thread Francesco Chemolli
t; > > > > > *From: *squid-users on behalf > of Eliezer Croitoru > *Date: *Monday, May 2, 2022 at 11:59 AM > *To: *squid-users@lists.squid-cache.org > > *Subject: *Re: [squid-users] squid3/4 compilation error with Centos8/RH8 > > Try to use the next SRPM:

Re: [squid-users] squid3/4 compilation error with Centos8/RH8

2022-05-02 Thread Ahmad Alzaeem
@lists.squid-cache.org Subject: Re: [squid-users] squid3/4 compilation error with Centos8/RH8 Try to use the next SRPM: https://www.ngtech.co.il/repo/centos/8/SRPMS/squid-4.17-8.el8.src.rpm Good Luck, Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com

Re: [squid-users] squid3/4 compilation error with Centos8/RH8

2022-05-02 Thread Eliezer Croitoru
Try to use the next SRPM: https://www.ngtech.co.il/repo/centos/8/SRPMS/squid-4.17-8.el8.src.rpm Good Luck, Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com From: squid-users On Behalf Of Ahmad Alzaeem Sen

Re: [squid-users] squid3 : Really need to use external (slow) acl with peer_cache_access

2017-01-26 Thread Amos Jeffries
On 25/01/2017 10:29 p.m., ho...@free.fr wrote: > > Hi everybody, > > I really try to find a answer with google, and within > the archives of this mailing list but couldn't find anything > so... here I am... > > I need to select a squid parent based on the login of the > user (and others things).

Re: [squid-users] Squid3 configure to force access to the facebook by the proxy

2017-01-03 Thread Hardik Dangar
I am not sure why you would need that many ports. if you think each port is for each user or some other misconcept then let me tell you, you can route all your hosts and traffic from single port only. On Tue, Jan 3, 2017 at 4:06 PM, hitman13 wrote: > Hi guys, I'm new to linux > And I need to con

Re: [squid-users] SQUID3 FreeRADIUS

2016-08-30 Thread Craddock, Tommy
Hello, The name of the helper was changed some time ago: 2.5 Helper Name Changes To improve the understanding of what each helper does and where it should be used the helper binaries which are bundled with Squid have undergone a naming change in this release. Below is a list of the old helper

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-23 Thread Amos Jeffries
On 24/06/2016 1:19 a.m., Alejandro Cabrera Obed wrote: > OK Eliezer, thanks a lotI will disable IPv6 and compile Squid3 again > disabling ICMP (pinger) also because I don't need these features at all. > Maybe yes. Maybe no. pinger is a tricky one. It is used to record RTT for each server conn

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-23 Thread Alejandro Cabrera Obed
> Eliezer > > > > > > Eliezer Croitoru <http://ngtech.co.il/lmgtfy/> > Linux System Administrator > Mobile: +972-5-28704261 > Email: elie...@ngtech.co.il > > > > *From:* squid-users [mailto:squid-users-boun...@lists.squid-cache.org] *On > Behalf O

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-23 Thread Eliezer Croitoru
org Subject: Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger I notice that I've comnpiled squid3 with --enable-icmp but I don't need thsi option because I don't work eith parent caches. So I will

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-22 Thread Alejandro Cabrera Obed
I notice that I've comnpiled squid3 with --enable-icmp but I don't need thsi option because I don't work eith parent caches. So I will try to reconfigure squid3 withouth the ICMP option (no pinger at all), and I expect not to see any IPv6 warning. Regards, 2016-06-22 21:29 GMT-03:00 Alejandro Ca

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-22 Thread Alejandro Cabrera Obed
I can't see anything about IPv6: *cat /etc/default/networking:* # Configuration for networking init script being run during # the boot sequence # Set to 'no' to skip interfaces configuration on boot #CONFIGURE_INTERFACES=yes # Don't configure these interfaces. Shell wildcards supported/ #EXCLUD

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-22 Thread Antony Stone
On Thursday 23 June 2016 at 01:22:45, Alejandro Cabrera Obed wrote: > #ifconfig > > eth0 Link encap:Ethernet HWaddr 00:50:53:b2:6e:88 > inet addr:10.17.133.114 Bcast:10.17.135.255 Mask:255.255.252.0 > > loLink encap:Local Loopback > inet addr:127.0.0.1 Mask:2

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-22 Thread Alejandro Cabrera Obed
#ifconfig eth0 Link encap:Ethernet HWaddr 00:50:53:b2:6e:88 inet addr:10.17.133.114 Bcast:10.17.135.255 Mask:255.255.252.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:4488 errors:0 dropped:96 overruns:0 frame:0 TX packets:986 errors

Re: [squid-users] Squid3: icmp_sock: (97) Address family not supported by protocol / pinger: Unable to start ICMPv6 pinger

2016-06-22 Thread Antony Stone
On Thursday 23 June 2016 at 01:08:33, Alejandro Cabrera Obed wrote: > 2016/06/22 19:56:35| pinger: Unable to start ICMPv6 pinger. > > But after that the squid3 daemon runs OK. What's the output from "ifconfig" on that machine? Antony. -- It may not seem obvious, but (6 x 5 + 5) x 5 - 55 equal

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
OK Antony thank you!! 2016-06-22 18:28 GMT-03:00 Roberto Carna : > Amos, just a last comment: > > My squid.conf from Squid3 has this line: > > #Default: > # logfile_rotate 0 > > So the parameter you mentiones it's just setup. > > Any other thing relative to log problem? > > 2016-06-22 11:4

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Antony Stone
On Wednesday 22 June 2016 at 23:28:56, Roberto Carna wrote: > My squid.conf from Squid3 has this line: > > #Default: > # logfile_rotate 0 > > So the parameter you mentiones it's just setup. You do realise that # at the start of a line means it is a comment and has no effect, right? Antony.

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
Amos, just a last comment: My squid.conf from Squid3 has this line: #Default: # logfile_rotate 0 So the parameter you mentiones it's just setup. Any other thing relative to log problem? 2016-06-22 11:42 GMT-03:00 Amos Jeffries : > On 23/06/2016 1:44 a.m., Roberto Carna wrote: >> Dear Antony, t

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
OK, I'll do that. And what about the "nocreate" option in the logrotate file for squid3???Do I have to delete or change for waht option??? Thanks a lot again, this is my last question. 2016-06-22 14:02 GMT-03:00 Amos Jeffries : > On 23/06/2016 4:32 a.m., Roberto Carna wrote: >> Amos and Antony,

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Amos Jeffries
On 23/06/2016 4:32 a.m., Roberto Carna wrote: > Amos and Antony, thanks a lot for your help. > > At first, I'll enable IPv6 in my Debian box. > > And for the log problem, I couldn't understand what yoy said > Amos...please can you detail what I have to do in order to avoid log > rotation problems

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
Amos and Antony, thanks a lot for your help. At first, I'll enable IPv6 in my Debian box. And for the log problem, I couldn't understand what yoy said Amos...please can you detail what I have to do in order to avoid log rotation problems??? And at last, why do you think the log problem arrives w

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Amos Jeffries
On 23/06/2016 1:44 a.m., Roberto Carna wrote: > Dear Antony, thanks for your help..below is the > /etc/logrotate.d/squid3 filebut before I have to say I've seen in > the web that this problem is solved by enabling IPv6, and was reported > by a ticket (https://forum.opnsense.org/index.php?topic=

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Antony Stone
On Wednesday 22 June 2016 at 15:44:42, Roberto Carna wrote: > Dear Antony, thanks for your help..below is the > /etc/logrotate.d/squid3 filebut before I have to say I've seen in > the web that this problem is solved by enabling IPv6, and was reported > by a ticket (https://forum.opnsense.org/i

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Antony Stone
On Wednesday 22 June 2016 at 15:49:57, Roberto Carna wrote: > Also I see in cache.log: > > pinger: Initialising ICMP pinger ... > 2016/06/22 09:58:51| pinger: ICMP socket opened. > 2016/06/22 09:58:51| icmp_sock: (97) Address family not supported by > protocol 2016/06/22 09:58:51| pinger: Unabl

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
Also I see in cache.log: pinger: Initialising ICMP pinger ... 2016/06/22 09:58:51| pinger: ICMP socket opened. 2016/06/22 09:58:51| icmp_sock: (97) Address family not supported by protocol 2016/06/22 09:58:51| pinger: Unable to start ICMPv6 pinger. 2016/06/22 09:58:51| Pinger exiting. 2016-06-2

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Roberto Carna
Dear Antony, thanks for your help..below is the /etc/logrotate.d/squid3 filebut before I have to say I've seen in the web that this problem is solved by enabling IPv6, and was reported by a ticket (https://forum.opnsense.org/index.php?topic=879.0) ..can this be true??? /var/log/squid3/*.log {

Re: [squid-users] Squid3 error: CHILD: hello write test failed logrotate

2016-06-22 Thread Antony Stone
On Wednesday 22 June 2016 at 14:53:23, Roberto Carna wrote: > everything was OK until the /var/log/squid3/access.log rotate to > access.log.1. From this moment, the access.log file is not present, and the > squid3 daemon doesn't respond...I'm not sure the cause. Show us your log rotation script.

Re: [squid-users] squid3 / debian stable / please update to 3.4.14

2015-12-31 Thread Massimo . Sala
tch to a new thread for it. Two subjects in one Email, excuse me ! Many thanks, Sala Amos Jeffries 31/12/2015 10:43 To massimo.s...@asl.bergamo.it cc lu...@debian.org, Subject Re: [squid-users] squid3 / debian stable / please update to 3.4.14 On 2015-12-30 03:26, massimo.s...@asl.be

Re: [squid-users] squid3 / debian stable / please update to 3.4.14

2015-12-31 Thread L . P . H . van Belle
Greetz, Louis > -Oorspronkelijk bericht- > Van: squid-users [mailto:squid-users-boun...@lists.squid-cache.org] Namens > Amos Jeffries > Verzonden: donderdag 31 december 2015 10:43 > Aan: massimo.s...@asl.bergamo.it > CC: lu...@debian.org; squid-users@lists.squid-cache.org >

Re: [squid-users] squid3 / debian stable / please update to 3.4.14

2015-12-31 Thread Amos Jeffries
On 2015-12-30 03:26, massimo.s...@asl.bergamo.it wrote: ciao Luigi I ask to update the distro to squid 3.4.14, the last stable version, released in august. Rationale : 1) various bugs and memory leaks fixed; 2) security fix for CVE 2015 5400; 3) support for Alternate-Protocol HTTP header. I ne

Re: [squid-users] squid3 / debian stable / please update to 3.4.14

2015-12-30 Thread L . P . H . van Belle
Hai, You can very easy upgrade to 3.5.12 on Jessie. Add sid to your sources.list, or better in : /etc/apt/sources.list.d/debian-sid.list Only the deb-src line is needed. Now apt-get update # install dependecies. apt-get build-dep squid # get and build source. apt-get source squid -b if y

Re: [squid-users] Squid3.x have issue with some sites, squid2.x not.

2015-11-24 Thread Amos Jeffries
On 24/11/2015 8:53 p.m., Matus UHLAR - fantomas wrote: > On 24.11.15 15:27, Amos Jeffries wrote: >> 3.4 has about 12 years of code development difference to 2.7. >> It is no surprise when they act different (good or bad). > > how do you compare this? 2.7 versions were produces in 2008 to 2010, whe

Re: [squid-users] Squid3.x have issue with some sites, squid2.x not.

2015-11-23 Thread Matus UHLAR - fantomas
On 24.11.15 15:27, Amos Jeffries wrote: 3.4 has about 12 years of code development difference to 2.7. It is no surprise when they act different (good or bad). how do you compare this? 2.7 versions were produces in 2008 to 2010, where are those 12 years? -- Matus UHLAR - fantomas, uh...@fantoma

Re: [squid-users] Squid3.x have issue with some sites, squid2.x not.

2015-11-23 Thread Amos Jeffries
On 24/11/2015 1:56 p.m., Beto Moreno wrote: > Hi guys. > > I have face some issue with Squid Cache: Version 3.4.10. > > Example this site: > > www.salud.gob.mx > www.issemym.gob.mx > > I cannot access this site. > > Now, I have a other installation running squid 2.7.x, in that network > I can

Re: [squid-users] Squid3 Authentication Ldap AD

2015-11-06 Thread Rafael Maleta Fdez
The problem is that I want to authenticate the Windows domain users to authenticate to the squid, or reports that leave me with the ips users, so for that I need to authenticate my squid v3.4.8 on Windows Active Directory I'm doing queries to Active Directory and give me error root@debian:/ho

Re: [squid-users] Squid3 Authentication Ldap AD

2015-11-06 Thread Amos Jeffries
On 7/11/2015 5:40 a.m., Rafael Maleta Fdez wrote: > Above all good > squid3 version 3.4.8 in the authentication parameter change for > basic_ldap_auth and I'm having trouble making queries against Windows > Active Directory, please help with this. > Thank you very much for your attention. > More

Re: [squid-users] Squid3 Support for TLS 1.1 and TLS 1.2

2015-11-06 Thread Dieter Bloms
Hi, On Fri, Nov 06, Fullyrealized LLC wrote: > I have been trying to bolster my pfsense systems and found one > difficulty with squid3. I cant figure out how to allow for support of > tls 1.1 and 1.2. It supports tls 1 of course but the new reports from > qualys give a "C" for such. I am wonderin

Re: [squid-users] Squid3 Kerberos Auth works but does not update theusers group membership in the winbind cache of samba as forexamle ntlm_auth does

2015-09-13 Thread Markus Moeller
Hi Enrico, The Kerberos helper will authenticate only for now ( There is a now code to get the group information, but it is not further processed). It does not do anything to group membership like the winbind cache. Also keep in mind Kerberos cache for about 10 hours the ticket on the cl

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-25 Thread Marcus Kool
Kool" An: "Jens Offenbach" , squid-users@lists.squid-cache.org Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load during object caching On 07/24/2015 01:01 PM, Jens Offenbach wrote: @Marcus: I am not sure what exactly causes the problems, but could you please make a

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-25 Thread Jens Offenbach
, 24. Juli 2015 um 19:01 Uhr Von: "Marcus Kool" An: "Jens Offenbach" , squid-users@lists.squid-cache.org Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load during object caching On 07/24/2015 01:01 PM, Jens Offenbach wrote: > @Marcus: > I am not sure what exactl

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Marcus Kool
: Freitag, 24. Juli 2015 um 14:33 Uhr Von: "Marcus Kool" An: "Jens Offenbach" , squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching On 07/24/2015 03:25 AM, Jens Offenbach wrote: I have made a quick test of Squid 3.3.8 on Ub

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Jens Offenbach
: "Marcus Kool" An: "Jens Offenbach" , squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching On 07/24/2015 03:25 AM, Jens Offenbach wrote: > I have made a quick test of Squid 3.3.8 on Ubuntu 15.04 and I get the same > proble

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Marcus Kool
liezer Croitoru" , "Amos Jeffries" , squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching It is not easy for me, but I have tested Squid 3.3.8 from the Ubuntu packaging on a "real" physical infrastructure. I get the same

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Amos Jeffries
On 24/07/2015 7:49 p.m., Jens Offenbach wrote: > I have found something out... Hopefully, it helps to reproduce and solve the > issue. > > I got it working with a good download rate, but very high CPU usage on Squid > 3.3.8 and Squid 3.5.6. There seems to be problem with large files that get >

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Amos Jeffries
t; http://w1.wikisend.com/node-fs/download/6a004a416f65b4cdf7f8eff4ff961199/squid.strace >> >> I hope it can help you. >> *Gesendet:* Donnerstag, 23. Juli 2015 um 13:29 Uhr >> *Von:* "Marcus Kool" >> *An:* "Jens Offenbach" , "Eliezer Croitoru&qu

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-24 Thread Jens Offenbach
;Jens Offenbach" An: squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching I have made a quick test of Squid 3.3.8 on Ubuntu 15.04 and I get the same problem: 100 % CPU usage, 500 KB/sec download rate.   Gesendet: Freitag, 24. Juli 2015 um 07:

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Jens Offenbach
ot; , squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching It is not easy for me, but I have tested Squid 3.3.8 from the Ubuntu packaging on a "real" physical infrastructure. I get the same results on the physical machine (1x Intel(R)

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Jens Offenbach
Gesendet: Donnerstag, 23. Juli 2015 um 20:08 Uhr Von: "Marcus Kool" An: "Jens Offenbach" , "Amos Jeffries" , "Eliezer Croitoru" , squid-users@lists.squid-cache.org Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load during object caching The strace

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Marcus Kool
*Gesendet:* Donnerstag, 23. Juli 2015 um 13:29 Uhr *Von:* "Marcus Kool" *An:* "Jens Offenbach" , "Eliezer Croitoru" , "Amos Jeffries" , squid-users@lists.squid-cache.org *Betreff:* Re: [squid-users] Squid3: 100 % CPU load during object caching I am not sure i

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Jens Offenbach
Ok. I am sorry, Please, try this one: http://wikisend.com/download/413650/squid.strace Regards, Jens   Gesendet: Donnerstag, 23. Juli 2015 um 16:25 Uhr Von: "Marcus Kool" An: "Jens Offenbach" Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load during object cachin

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Amos Jeffries
On 23/07/2015 11:29 p.m., Marcus Kool wrote: > I am not sure if it is relevant, maybe it is: > > I am developing an ICAP daemon and after the ICAP server sends a "100 > continue" > Squid sends the object to the ICAP server in small chunks of varying sizes: > 4095, 5813, 1448, 4344, 1448, 1448, 289

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Jens Offenbach
uid.strace   I hope it can help you.   Gesendet: Donnerstag, 23. Juli 2015 um 13:29 Uhr Von: "Marcus Kool" An: "Jens Offenbach" , "Eliezer Croitoru" , "Amos Jeffries" , squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load duri

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Marcus Kool
; '--with-large-files' '--with-default-user=proxy' '--enable-linux-netfilter' 'build_alias=x86_64-linux-gnu' 'CFLAGS=-g -O2 -fPIE -fstack-protector --param=ssp-buffer-size=4 -Wformat -Werror=format-security -Wall' 'LDFLAGS=-Wl,-Bsymbolic-functi

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-23 Thread Jens Offenbach
x27; '--with-pidfile=/var/run/squid3.pid' '--with-filedescriptors=65536' '--with-large-files' '--with-default-user=proxy' '--enable-linux-netfilter' 'build_alias=x86_64-linux-gnu' 'CFLAGS=-g -O2 -fPIE -fstack-protector --param=ssp-bu

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Jens Offenbach
ries" Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching On 22/07/2015 21:59, Eliezer Croitoru wrote: > Hey Jens, > > I have tested the issue with LARGE ROCK and not AUFS or UFS. > Using squid or not my connection to the server is about 2.5 MBps (20Mbps). >

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Eliezer Croitoru
On 22/07/2015 21:59, Eliezer Croitoru wrote: Hey Jens, I have tested the issue with LARGE ROCK and not AUFS or UFS. Using squid or not my connection to the server is about 2.5 MBps (20Mbps). Squid is sitting on an intel atom with SSD drive and on a HIT case the download speed is more then double

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Eliezer Croitoru
Von: "Eliezer Croitoru" An: squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching Can you share the relevant squid.conf settings? Just to reproduce.. I have a dedicated testing server here which I can test the issue on. 8GB archive whic

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Jens Offenbach
18:28 Uhr Von: "Eliezer Croitoru" An: squid-users@lists.squid-cache.org Betreff: Re: [squid-users] Squid3: 100 % CPU load during object caching Can you share the relevant squid.conf settings? Just to reproduce.. I have a dedicated testing server here which I can test the issue on. 8GB

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Eliezer Croitoru
3.327152 3428139 7 total Can I do anything that helps to get ride of this problem? Gesendet: Dienstag, 21. Juli 2015 um 17:37 Uhr Von: "Amos Jeffries" An: "Jens Offenbach" , "squid-users@lists.squid-cache.org" Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-22 Thread Jens Offenbach
3428139 7 total Can I do anything that helps to get ride of this problem?   Gesendet: Dienstag, 21. Juli 2015 um 17:37 Uhr Von: "Amos Jeffries" An: "Jens Offenbach" , "squid-users@lists.squid-cache.org" Betreff: Re: Aw: Re: [squid-users] Squid3: 100 % CPU load durin

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-21 Thread Amos Jeffries
On 22/07/2015 12:31 a.m., Jens Offenbach wrote: > Thank you very much for your detailed explainations. We want to use Squid in > order to accelerate our automated software setup processes via Puppet. > Actually > Squid will host only a very short amount of large objects (10-20). Its > purpose

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-21 Thread Eliezer Croitoru
On 21/07/2015 10:59, Jens Offenbach wrote: Is there someting wrong with my config? I have already used Squid 3.3.14. I get the same result. Unfortunately, I was not able to build Squid 3.5.5 and 3.5.6. What was the issue? I am using 3.5.6 on 14.04.2 64 bit. Eliezer __

Re: [squid-users] Squid3: 100 % CPU load during object caching

2015-07-21 Thread Amos Jeffries
On 21/07/2015 7:59 p.m., Jens Offenbach wrote: > I am running Squid3 3.3.8 on Ubuntu 14.04. Squid3 has been installed from the > Ubuntu package repository. In my scenario, Squid has to cache big files >= 1 > GB. At the moment, I am getting very bad transfer rates lower that 1 MB/sec. > I have ch

Re: [squid-users] Squid3 authentification proxy and method CONNECT SSL

2015-07-01 Thread Alexandre Magnat
Hi Amos; Thanks you for this complete response. You're true, I have to upgrade my Debian :) soon ! For the conf, I have put this value in my squid.conf auth_param ntlm keep_alive off auth_param negotiate keep_alive off but it seems it's not working (one user have call me) to be sure, i'

Re: [squid-users] Squid3 authentification proxy and method CONNECT SSL

2015-07-01 Thread Amos Jeffries
On 1/07/2015 8:55 p.m., Alexandre Magnat wrote: > Hello, > > I use Squid3 (3.1.20) Please upgrade. > with Squidguard filtering linked with an user 's > authentication on a OpenLDAP. > But, recurrently, Firefox, Thunderbird, Chrome (certainly IE) ask again > frequently the login and password in

Re: [squid-users] squid3 doesn't work well

2015-04-27 Thread Helmut Hullen
Hallo, Dennis, Du meintest am 27.04.15: > Our squid3 server refused to work smoothly. I am not sure if I can > post and get help here. Some details may be helpful. Viele Gruesse! Helmut ___ squid-users mailing list squid-users@lists.squid-cache.org h

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-04 Thread Anton Radkevich
Guys, I just need an HTTPS proxy that can handle both http and https connections for authorised clients only. I tried to configure something like it's described here http://www.mail-archive.com/squid-users@squid-cache.org/msg93592.html Forward HTTPs proxy with digest_pw_auth for example. But I am

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Amos Jeffries
On 4/02/2015 9:20 a.m., Anton Radkevich wrote: > Yuri, > > I'd like to allow or deny access for a client before establishing of > encrypted channel to proxy server using an authentication method of squid > proxy. I think you and Yuri are talking past each other on this. This page has what you w

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 04.02.2015 3:30, Anton Radkevich пишет: > Guys, > > I just need an HTTPS proxy that can handle both http and https connections for authorised clients only. I tried to configure something like it's described here http://www.mail-archive.com/squid-use

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Anton Radkevich
Guys, I just need an HTTPS proxy that can handle both http and https connections for authorised clients only. I tried to configure something like it's described here http://www.mail-archive.com/squid-users@squid-cache.org/msg93592.html Forward HTTPs proxy with digest_pw_auth for example. But I am

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Sure. :) This way: http://yvoinov.blogspot.com/2014/08/squid-tor-privoxy-transparent-dns.html http://yvoinov.blogspot.com/2014/08/squid-tor-privoxy-transparent-dns_19.html :) 04.02.2015 2:44, Anton Radkevich пишет: > > Yuri, > > Can you please sh

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Eliezer Croitoru
Hey Anton, If you use https_port with ssl certificate it will be for one of two options: - interception of ssl traffic - reverse proxy with ssl For both cases the connection between the server and the client in the end will be encrypted while non of them is in a forward proxy mode and there

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Anton Radkevich
Yuri, Can you please share any configuration examples? ;) 03 февр. 2015 г. 23:27 пользователь "Yuri Voinov" написал: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Eliezer, > > Squid can be cascaded with Privoxy+Tor. :) > > And then - we can route users into it using ACL's ;) > > Ye

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 No. It will be encrypted to both directions. 04.02.2015 2:41, Anton Radkevich пишет: > > Hey Eliezer, > > Thank you for your explanation, just want to clarify. > > Does it mean that if I configure squid to listen https_port on port 3129 with ssl cer

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Anton Radkevich
Hey Eliezer, Thank you for your explanation, just want to clarify. Does it mean that if I configure squid to listen https_port on port 3129 with ssl certificate, connection from a client to squid server by port 3129 will be NOT encrypted? Anton 03 февр. 2015 г. 23:23 пользователь "Eliezer Croito

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Eliezer, Squid can be cascaded with Privoxy+Tor. :) And then - we can route users into it using ACL's ;) Yep, not Squid itself. But with external services. ;) 04.02.2015 2:23, Eliezer Croitoru пишет: > On 03/02/2015 17:14, Anton Radke

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Eliezer Croitoru
On 03/02/2015 17:14, Anton Radkevich wrote: so just to be clear the connection flow will look like: browser Server Destination where is probably some form of HTTPS connection for support with the browser PAC Hey Anton, Squid do not support socks connection or any other form of encryption.

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Anton Radkevich
Yuri, I'd like to allow or deny access for a client before establishing of encrypted channel to proxy server using an authentication method of squid proxy. Can I setup any authentication method for https forward proxy? If yes, is it possible to use more secure hash algorithms than old md5? Thanks

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://wiki.squid-cache.org/Features/Authentication http://wiki.squid-cache.org/ConfigExamples#Authentication This one? 04.02.2015 2:06, Anton Radkevich пишет: > > Thanks for quick reply, > We don't need ssl bumping, or isn't it possible to configu

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 As forward HTTPS proxy you can use no tricks. Just preroute HTTPS traffic to Squid and permit method CONNECT with 443 port - Squid forward HTTPS connections by design. I do not understand, what does authentication here. This is another problem that

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Anton Radkevich
Thanks for quick reply, We don't need ssl bumping, or isn't it possible to configure by another way, without using ssl bumping? What's about authentication using modern hash algorithms sha256/512? Anton 03 февр. 2015 г. 22:58 пользователь "Yuri Voinov" написал: > > -BEGIN PGP SIGNED MESSAGE

Re: [squid-users] SQUID3 HTTPs forward proxy and sha256/512 authentication

2015-02-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit 04.02.2015 1:03, Anton Radkevich пишет: > > Hi everyone, > > Could you please help me with configuration Squid3 as forward HTTPs proxy? > > Is it possible to configure it in such w

Re: [squid-users] squid3

2015-01-30 Thread Bobby
0, 2015 3:28 AM Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] squid3 > It is not true. > Squid3 in debian is newer then 3.1 as far as I remember and if it's > not in the main repos then use the backports for it. No, 3.1.20 is the latest in stable release (wheezy)

Re: [squid-users] squid3

2015-01-30 Thread FredB
> It is not true. > Squid3 in debian is newer then 3.1 as far as I remember and if it's > not > in the main repos then use the backports for it. No, 3.1.20 is the latest in stable release (wheezy) > > It is but it’s the latest version available through apt-get on > > Debian 7 without adding backp

Re: [squid-users] squid3

2015-01-30 Thread Eliezer Croitoru
Hey Bobby, It is not true. Squid3 in debian is newer then 3.1 as far as I remember and if it's not in the main repos then use the backports for it. It is recommended that you will use a newer version of squid. If for your environment 3.1 works fine then I guess you can say that it works and th

Re: [squid-users] squid3

2015-01-29 Thread FredB
> > It is but it’s the latest version available through apt-get on Debian > 7 without adding backports which I may end up doing anyway. However > I don’t think that is my problem, I think I may have missed > something in my config and was wondering if anyone had seen this > before with the user

Re: [squid-users] squid3

2015-01-27 Thread Bobby
seeming to be passed to dansguardian. Bobby From: squid-users [mailto:squid-users-boun...@lists.squid-cache.org] On Behalf Of Yuri Voinov Sent: Tuesday, January 27, 2015 2:52 PM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] squid3 -BEGIN PGP SIGNED MESSAGE- Hash

Re: [squid-users] squid3

2015-01-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hmm.. Why so ancient Squid version? 3.1.x is legacy. Now Amos says: "Upgrade to last version". ;) Which is 3.5.1 (wow! :)) 28.01.2015 3:48, Bobby пишет: > > Sorry if you’re seeing this twice… I think I sent it to the wrong address the fir

Re: [squid-users] Squid3 config on Ubuntu remains even after uninstall and ignore the new config

2014-11-11 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/11/2014 1:37 a.m., Efe wrote: > I tried on different browser but it's the same. Clearing browser > cache and stopping the service made no difference either. I don't > know if Squid does change Ubuntu network settings. Any particular > place/file

Re: [squid-users] Squid3 config on Ubuntu remains even after uninstall and ignore the new config

2014-11-10 Thread Antony Stone
On Monday 10 November 2014 at 17:12:23 (EU time), Efe wrote: > acl myrule dstdom_regex "/etc/squid3/domainblock.txt" > http_access deny myrule > > where domainblock.txt is > > someaddress.com > blockthis.net As Amos said, use dstdomain instead of dstdom_regex. > Now whenever i

Re: [squid-users] Squid3 config on Ubuntu remains even after uninstall and ignore the new config

2014-11-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/11/2014 2:58 a.m., Efe wrote: > Thank you for your reply. I've managed to retrieve uncommented > config lines: > > $ grep -P '^\s*\w' /etc/squid3/squid.conf > > acl localnet src 192.168.0.101 # RFC1918 possible internal > network acl SSL_ports

Re: [squid-users] Squid3 config on Ubuntu remains even after uninstall and ignore the new config

2014-11-10 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/11/2014 12:22 a.m., Efe wrote: > OS: Ubuntu 14.04 LTS > > After i installed the squid3 package for the 1st time, i've add a > list of domains to be blocked in squid.conf: > > acl myrule dstdom_regex "/etc/squid3/domainblock.txt" http_access > d