Re: [squid-users] Squid crashes with 3.5.1

2015-05-08 Thread Prashanth Prabhu
Hi Amos, > IIRC. I patched in the bug fix -- I assume the patch file listed in the bug report is the most current? -- but it didn't help. I saw the same crash in a couple of patched systems. The stack trace is pasted below. As I pointed out in m

Re: [squid-users] Squid crashes with 3.5.1

2015-05-08 Thread Dmitry Melekhov
08.05.2015 11:29, Prashanth Prabhu пишет: As I pointed out in my earlier email, the crash occurs with c-icap connections I guess this is why my 3.5.4 crashes too, although had no chance to debug yet, I found info in log that there are no enough redirectors, which never happend with 3.4.

Re: [squid-users] Squid crashes with 3.5.1

2015-05-08 Thread Dmitry Melekhov
08.05.2015 13:35, Dmitry Melekhov пишет: 08.05.2015 11:29, Prashanth Prabhu пишет: As I pointed out in my earlier email, the crash occurs with c-icap connections I guess this is why my 3.5.4 crashes too, although had no chance to debug yet, I found info in log that there are no enough redirect

[squid-users] Reverse Proxy and SSL client side renegotiation

2015-05-08 Thread Jakob Curdes
Hello all, I have configured squid 3.3.8 (CentOS 7 rpm) as an SSL reverse proxy which works fine. However, I would like to make it as secure as possible. The SSLLabs test showed "Secure Client-Initiated Renegotiation *Supported* *DoS DANGER* (more info

Re: [squid-users] Reverse Proxy and SSL client side renegotiation

2015-05-08 Thread Amos Jeffries
On 8/05/2015 10:46 p.m., Jakob Curdes wrote: > Hello all, I have configured squid 3.3.8 (CentOS 7 rpm) as an SSL > reverse proxy which works fine. However, I would like to make it as > secure as possible. The SSLLabs test showed > "Secure Client-Initiated Renegotiation *Supported* *DoS DANGER* (mor

Re: [squid-users] Client IP spoofing via squid proxy

2015-05-08 Thread Ambadas Hibare
Hi Amos, It's happening as you said: the packets doing this: client -> Squid -SYN-> server client <-ACK-- server client -RST-> Squid There's a firewall in between squid & web server which is directly sending SYN-ACK to client instead of squid. But in my requirement, the cli

Re: [squid-users] Client IP spoofing via squid proxy

2015-05-08 Thread Amos Jeffries
On 9/05/2015 1:56 a.m., Ambadas Hibare wrote: > Hi Amos, > > It's happening as you said: > > the packets doing this: > client -> Squid -SYN-> server > client <-ACK-- server > client -RST-> Squid > > There's a firewall in between squid & web server which is directly sending >

Re: [squid-users] CHROOT Problems Part II

2015-05-08 Thread Casey Daniels
I managed to get most of the errors cleaned up, in a LONG and TEDIOUS process, however when I assumed fixing one error would fix another error was wrong. I'm still getting the following error. logfileHandleWrite: daemon:/usr/local/squid/var/logs/access.log: error writing ((32) Broken pipe)