Re: [squid-users] Squid memory consumption problem

2020-06-20 Thread Eliezer Croitoru
e at my working hoursso we would be able to resolve this issue on-line without so much delay between email to email.My usual working hours are usually from 10:00 AM till 05:00 PM IST. Eliezer Eliezer CroitoruTech SupportMobile: +972-5-28704261Email: ngtech1...@gmail.com From: DIXIT AnkitSent: F

[squid-users] Error: (71) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2020-06-21 Thread Eliezer Croitoru
I have tested 4.12 and with default settings I am getting an error on some local common web pages. (71) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)Handshake with SSL server failed: error:141A318A:SSL routines:tls_process_ske_dhe:dh key too small In my search for users who had a similar issue

Re: [squid-users] Squid is using ipv4 for non-ssl connections

2020-06-23 Thread Eliezer Croitoru
Just to clear out the doubts about the subject. The decision on what IP version to use for outgoing connections is based on:DNS A and recordsReachability:  Ping? Icmp? Happy Eyeballs? I am not sure what was the situation but,some tests were done to run an IPv6 only network with IPv6 to IPv4 Ga

Re: [squid-users] Squid memory consumption problem

2020-06-28 Thread Eliezer Croitoru
-5-28704261Email: ngtech1...@gmail.com From: DIXIT AnkitSent: Thursday, June 25, 2020 5:08 PMTo: Eliezer Croitoru; Alex Rousskov; squid-users@lists.squid-cache.orgCc: UPADHYAY Neeraj; SETHI Konica; DWIVEDI Gaurav KumarSubject: RE: [squid-users] Squid memory consumption problem Eliezer, I have some

Re: [squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Eliezer Croitoru
Hey Vieri, This connections is being bumped and it’s based on a CONNECT connection to the proxy.I believe what you are looking for is at:https://wiki.squid-cache.org/ConfigExamples/Chat/Whatsapp Hope It Helps,Eliezer  Eliezer CroitoruTech SupportMobile: +972-5-28704261Email: ngtech1...@gmail.co

Re: [squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Eliezer Croitoru
] Squid 4 and on_unsupported_protocol   On Monday, June 29, 2020, 6:41:41 PM GMT+2, Eliezer Croitoru wrote: > > > I believe what you are looking for is at:> https://wiki.squid-cache.org/ConfigExamples/Chat/Whatsapp Thanks, but the article doesn't work for me.I still see Firefox com

Re: [squid-users] Squid memory consumption problem

2020-06-30 Thread Eliezer Croitoru
The first thing to do is look at:https://wiki.squid-cache.org/KnowledgeBase/HostHeaderForgery It should clear couple doubts for you. Eliezer Eliezer CroitoruTech SupportMobile: +972-5-28704261Email: ngtech1...@gmail.com From: DIXIT AnkitSent: Tuesday, June 30, 2020 10:46 AMTo: Eliezer Croitoru

[squid-users] Host header forgery detected on domain: mobile.pipe.aria.microsoft.com

2021-01-06 Thread Eliezer Croitoru
ay to look at these short TTLs as something to decide by an ACL? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Host header forgery detected on domain: mobile.pipe.aria.microsoft.com

2021-01-06 Thread Eliezer Croitoru
to happen so we can disable the logs since the service continue to work with this low ttl. The only and main issue is the extensive logging which is wrong. Should we continue this on Squid-dev? Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Com

Re: [squid-users] Squid 4 Migration - balance_on_multiple_ip

2021-01-07 Thread Eliezer Croitoru
-outgoing-addresses How many IP addresses are we talking about ? Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Conner Bean Sent: Wednesday, January 6, 2021 10:24 PM To: squid

Re: [squid-users] Host header forgery detected on domain: mobile.pipe.aria.microsoft.com

2021-01-07 Thread Eliezer Croitoru
arios which are far more important then basic caching while not lowering the caching as important as the service itself. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Thursday

Re: [squid-users] How do I rotate access.log?

2021-01-10 Thread Eliezer Croitoru
Have you tried to use the OS logrotate? Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: squid-users On Behalf Of roee klinger Sent: Sunday, January 10, 2021 5:25 PM To: squid

Re: [squid-users] cache_peer selection based on username

2021-01-10 Thread Eliezer Croitoru
You should use a note acl for that. When you return the whitelisted client you should add a note which can be 1-100 or any other static string. It works just out of the box. Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> n

Re: [squid-users] cache_peer selection based on username

2021-01-11 Thread Eliezer Croitoru
to-ip.conf It’s better to run the lab and see the content of the conf files to understand it. You will need VirtualBox and Vagrant to power up this lab. Later I might be able to record a video of this but not sure yet about this. Eliezer ---- Eliezer Croitoru Tech Support Mobi

Re: [squid-users] What is the state of V5 branch? Can I try to publish some RPMS?

2021-01-11 Thread Eliezer Croitoru
We are now less one bug then before, just 3 to go: <https://bugs.squid-cache.org/show_bug.cgi?id=4806> <https://bugs.squid-cache.org/show_bug.cgi?id=4832> <http://bugs.squid-cache.org/show_bug.cgi?id=5055> Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704

[squid-users] no src IP in access log for locally generated requests

2021-01-11 Thread Eliezer Croitoru
I have in my logs: 1610372657.529 0 - TCP_DENIED/403 3638 GET http://crl.kaspersky.com/aia/KSNGlobalRootCAECC.crt - HIER_NONE/- text/html - And it means probably that squid is generating these requests. What ACL can I use to allow this? Eliezer Eliezer Croitoru Tech

Re: [squid-users] distinguish between IPv4 and IPv6

2021-01-11 Thread Eliezer Croitoru
een all of the above happen in production services in the last year. I can write a helper for this if required. Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon From: squid-use

Re: [squid-users] cache_peer selection based on username

2021-01-12 Thread Eliezer Croitoru
to use 0-1. Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Amos Jeffries Sent: Tuesday, January 12, 2021 3:46 AM To: squid-users@lists.squid-cache.org Subject: Re: [s

[squid-users] Microsoft store issues with ssl-bump

2021-01-12 Thread Eliezer Croitoru
issue without the dns+fw level bypass. Any hints might help to find and resolve this issue Thanks, Eliezer * Squid 5.0.4 on Fedora 33. * I can generate a "support file" which contains all squid conf for reproduction of the issue by the dev team. ---- Elieze

Re: [squid-users] Microsoft store issues with ssl-bump

2021-01-12 Thread Eliezer Croitoru
;t. I will try to test it with another proxy which only looks at the SNI. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Lorenzo Marcantonio Sent: Tuesday, January 12, 20

Re: [squid-users] Microsoft store issues with ssl-bump

2021-01-12 Thread Eliezer Croitoru
:54 conn 192.168.189.X:64669 - 104.79.221.20:443 connected [storeedgefd.dsx.mp.microsoft.com:443] So the regex: storeedgefd\.dsx\.mp\.microsoft\.com should work. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original

Re: [squid-users] Microsoft store issues with ssl-bump

2021-01-12 Thread Eliezer Croitoru
ess explicitly connected to with > TLS/1.2 immediately. IIRC latest Squid force the client to TLS/1.2 when > preparing to bump, but may not for spliceand stare. So YMMV. OK Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soo

Re: [squid-users] Microsoft store issues with ssl-bump

2021-01-12 Thread Eliezer Croitoru
27;s not OK for Squid and any other SNI based certificate validator. Thanks Helped and Helps, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Alex Rousskov Sent: Tues

Re: [squid-users] distinguish between IPv4 and IPv6

2021-01-12 Thread Eliezer Croitoru
Can you share this solution of yours? These days it’s good to know about any piece of IPv4 vs/with IPv6 stack solutions. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From:

Re: [squid-users] WARNING: no_suid: setuid(0): (1) Operation not permitted

2021-01-13 Thread Eliezer Croitoru
create the basic Debian machine but not the whole Kerberos setup in a sec. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon From: squid-users On Behalf Of David Touzeau Sent: Wed

Re: [squid-users] generate-host-certificates=on fails to generate certificates for _some_ hosts

2021-01-14 Thread Eliezer Croitoru
arstechnica.com:443 /dev/null | openssl x509 -noout -text Let me know if something specific is seen in your environment. It shouldn't matter too much but, what OS are you running squid ontop and what is "squid -v" output? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile:

Re: [squid-users] Mutual TLS for the upstream example

2021-01-14 Thread Eliezer Croitoru
I don’t know about Squid but I assume varnish has this feature: https://docs.varnish-software.com/varnish-cache-plus/features/backend-ssl/ If you just need a GW without caching it should work as expected. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email

Re: [squid-users] Mutual TLS for the upstream example

2021-01-14 Thread Eliezer Croitoru
Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: Sergey Maslyakov Sent: Friday, January 15, 2021 1:38 AM To: Eliezer Croitoru Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] Mutual TLS f

Re: [squid-users] Adding headers in ICAP server with no preview

2021-01-18 Thread Eliezer Croitoru
Any modification of the headers is a bit complicated. I can try to check/test it but it will take time. >From what I see 5.0.4 is pretty stable however there are specific issues >related to TLS 1.3. Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Em

Re: [squid-users] sslcrtvalidator_program

2021-01-18 Thread Eliezer Croitoru
n -e 'test\x01' to emulate it but I still don't get it right. Hope for a hint about the subject. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Mond

[squid-users] Trying to verify couple tls issues

2021-01-18 Thread Eliezer Croitoru
ags=33 happens. However I am not sure. Are there any config that might affect this negotiation in squid? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon ___ squid-users mailing l

[squid-users] What is this access.log line?

2021-01-18 Thread Eliezer Croitoru
means? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon ___ squid-users mailing list squid-users@lists.squid-cache.or

Re: [squid-users] chromium based browsers don't play a video, when sslbump is enabled

2021-01-20 Thread Eliezer Croitoru
It's not clear if only Chromium or also a simple Chrome. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Dieter Bloms Sent: Wednesday, January 20, 2021 1:

Re: [squid-users] chromium based browsers don't play a video, when sslbump is enabled

2021-01-20 Thread Eliezer Croitoru
=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,--as-needed -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld ' 'CXX=g++' 'CXXFLAGS=-O2 -fexceptions -g

Re: [squid-users] Squid doesn't notice AD group changes

2021-01-20 Thread Eliezer Croitoru
with AD but when I have implemented it with LDAP it worked as expected. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon From: squid-users On Behalf Of heimarbeit123...@web.d

Re: [squid-users] Squid doesn't notice AD group changes

2021-01-21 Thread Eliezer Croitoru
ss.txt -f "(&(sAMAccountName=%u)(memberOf=CN=%g,OU=Groups,DC=ng,DC=tech))" -h ngtech-dc.ng.tech Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon From: squid-users On Beha

Re: [squid-users] effective acl for tcp_outgoing_address

2021-01-24 Thread Eliezer Croitoru
Hey, I can try to test/check this but I am missing the basic Kerberos auth with AD setup. I have a working setup but the transparent authentication is not working for me. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.

[squid-users] acl aclname server_cert_fingerprint

2021-01-25 Thread Eliezer Croitoru
ump-server-fingerprint.list" To be explicit despite that only sha1 is a valid checksum. Squid doesn't accept the above line but this one yes: acl NoBump_certificate_fingerprint server_cert_fingerprint "/etc/squid/no-ssl-bump-server-fingerprint.list" Is there a reason for that? Thanks, E

Re: [squid-users] acl aclname server_cert_fingerprint

2021-01-25 Thread Eliezer Croitoru
com be decrypted instead of spliced? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Tuesday, January 26, 2021 6:22 AM To: Eliezer Croitoru ; squid-users@lists.squid-

Re: [squid-users] acl aclname server_cert_fingerprint

2021-01-27 Thread Eliezer Croitoru
king fine except this fingerprint part which is not always the best way to splice. However it seems like it should be pretty straight forward. I can dump the whole config into a tar file to try and understand better the setup if required. Thanks, Eliezer Eliezer Croitoru Tech Support Mobi

Re: [squid-users] acl aclname server_cert_fingerprint

2021-01-27 Thread Eliezer Croitoru
ant since there aren't any errors. ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Wednesday, January 27, 2021 8:43 PM To: squid-users@lists.squid-cache.org Cc: Eliezer Croitoru

Re: [squid-users] acl aclname server_cert_fingerprint

2021-01-28 Thread Eliezer Croitoru
iezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Wednesday, January 27, 2021 10:07 PM To: squid-users@lists.squid-cache.org Cc: Eliezer Croitoru Subject: Re: [squid-users] acl ac

[squid-users] CentOS Changes, anyone noticed?

2021-01-28 Thread Eliezer Croitoru
Since I am providing the CentOS RPM's I noticed that there was a change on the OS. Has anyone noticed the latest changes with CentOS 8 and Stream? Thanks, Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1..

Re: [squid-users] re-directing through squid using MAC

2021-01-30 Thread Eliezer Croitoru
categorizing then I can provide with Squid and a subscription. (…No hard feelings with the Squid project) All The Bests, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From:

Re: [squid-users] re-directing through squid using MAC

2021-01-30 Thread Eliezer Croitoru
about Mobile phones, the difference between WIFI and Mobile 4G is only the .. Power of amplification. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: squid-users On Beh

[squid-users] ngtech repository goes TLS.

2021-01-30 Thread Eliezer Croitoru
will update almost automatically. Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon ___ squid-users mailing list squid-users@lists.squid-cac

[squid-users] Many google services IP addresses returns invalid2.invalid CN and Error negotiating SSL connection on FD

2021-01-31 Thread Eliezer Croitoru
n some way. I have seen this issue a lot in couple setups which … google services are being accessed from mobile devices or Google Chrome. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon _

Re: [squid-users] Fixing Squid configuration for caching proxy?

2021-02-01 Thread Eliezer Croitoru
/s3-gsg.pdf What version of squid are you using? squid -v output should give something. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: mailto:ngtech1...@gmail.com Zoom: Coming soon From: squid-users On Behalf Of Milos Dodic Sent: Friday, January 29, 2021 7:57 PM To

Re: [squid-users] Wildcard for url domain

2021-02-02 Thread Eliezer Croitoru
I would use: \.autodiscover\.[a-z0-9\-]+\.onmicrosoft\.com$ Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: squid-users On Behalf Of Bruno de Paula Larini Sent: T

[squid-users] Started testing squid-6.0.0-20210204-r5f37a71ac

2021-02-07 Thread Eliezer Croitoru
TLS connection on conn2195 local=216.58.198.67:443 remote=192.168.189.94:41724 FD 104 flags=33: 0x55cf6a6debe0*1 current master transaction: master78 which is a google host related issue. Alex and Amos, Can the project do something about this? Thanks, Eliezer Eliezer

[squid-users] Port or switch level authorization

2021-02-08 Thread Eliezer Croitoru
be logged. Thanks, Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Originserver load balancing and health checks in Squid reverse proxy mode

2021-02-08 Thread Eliezer Croitoru
y specific known use cases then use it. For general purpose these days it might not work as you might expect. Take into account that browsers cache lots of things, even these who shouldn't so the gain/profit should be tested first. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5

Re: [squid-users] Port or switch level authorization

2021-02-09 Thread Eliezer Croitoru
Thanks Amos, OK this seems to answer my question. A session helper with ttl=3 should be enough if it will return the username associated by the helper. The next thing is to block traffic if there is no username. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1

Re: [squid-users] Originserver load balancing and health checks in Squid reverse proxy mode

2021-02-09 Thread Eliezer Croitoru
A and advice here and there. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Chris Sent: Tuesday, February 9, 2021 6:36 PM To: squid-users@lists.squid-cache.org Subject: Re: [

Re: [squid-users] Started testing squid-6.0.0-20210204-r5f37a71ac

2021-02-11 Thread Eliezer Croitoru
55cf6a6debe0*1 > > current master transaction: master78 > > which is a google host related issue. The access to google hosts seems to be the main issue here. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming so

Re: [squid-users] Started testing squid-6.0.0-20210204-r5f37a71ac

2021-02-15 Thread Eliezer Croitoru
Hey Alex, Where exactly do you see Host Header Forgery in my last email? Eliezer * I wrote my own proxy for now. Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Thursday, February

Re: [squid-users] Started testing squid-6.0.0-20210204-r5f37a71ac

2021-02-15 Thread Eliezer Croitoru
re is an issue with ssl bump and this specific host is a re-producible issue/case/problem. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: Alex Rousskov Sent: Monday, February 15, 2021 9:03 PM To

Re: [squid-users] websocket with sslbump

2021-03-11 Thread Eliezer Croitoru
need this binaries, I can put them at: https://ngtech.co.il/repo/bin/debian/10.4/amd64/ Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: squid-users On Behalf Of Niels H

Re: [squid-users] a specific host generates a 503 ...

2021-03-11 Thread Eliezer Croitoru
iezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Walter H. Sent: Wednesday, March 10, 2021 7:55 AM To: Squid Users Subject: [squid-users] a specific host generates

Re: [squid-users] Squid 5 does not send ICAP request

2021-03-15 Thread Eliezer Croitoru
;t resolve for at-least 3 minutes. Thanks, Eliezer ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Alex Rousskov Sent: Friday, March 12, 2021 8:43 PM To: 橋本紘希 ; squid-users@l

Re: [squid-users] Protecting squid

2021-03-15 Thread Eliezer Croitoru
Hey Ben, Since you probably doesn’t have 100k users and there for passwords it wouldn't do a thing. Nobody will feel you dropping the TTL. The content of the credentials file will be in RAM so you should give it a try first and ask later. All The Bests, Eliezer Eliezer Croitoru

Re: [squid-users] How to automatically Restart Squid on Ubuntu?

2021-03-22 Thread Eliezer Croitoru
why is it crashing the proxy. Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon From: squid-users On Behalf Of Francesco Chemolli Sent: Monday, March 22, 2021 5:20 PM To: squid

Re: [squid-users] squid won't return cached even with refresh_pattern extra options override-lastmod override-expire ignore-reload ignore-no-store ignore-private store-stale

2021-03-27 Thread Eliezer Croitoru
et me know if you need more help, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com Zoom: Coming soon -Original Message- From: squid-users On Behalf Of Alex Rousskov Sent: Friday, March 26, 2021 10:36 PM To: squid-users@lists.squid-cach

[squid-users] Looking for subscription plan plain text Blacklists for a spin

2021-03-27 Thread Eliezer Croitoru
are many vendors for blacklists I would be happy to get any recommendations. Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Comin

Re: [squid-users] compile squid with tumbleweed

2021-04-01 Thread Eliezer Croitoru
ys to create the rootca. One with the CA.pl script and the other one is with the openssl tool. As long as you don't need the CA.pl specifically I would recommend using openssl. It's plain simple to just create a rootCA certificate. All The Bests, Eliezer Eliezer Croitoru Tech

Re: [squid-users] Can't get squid with whitelist text file to work TCP_DENIED/403

2021-04-14 Thread Eliezer Croitoru
Did you got it working eventually? Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com Zoom: Coming soon From: squid-users On Behalf Of Elliott Blake, Lisa Marie Sent: Thursday, April 8, 2021 10:11

Re: [squid-users] Cache Peers and traffic handling

2021-04-15 Thread Eliezer Croitoru
I don’t know your use case that well but maybe another proxy can do that for you. I wrote a haproxy routing config by username sometime ago: https://gist.github.com/elico/405f0608e60910fc9ea119e22e1ffd07 It's very simple and worth a shot. Let me know if it might be good for you. All The Bests, E

Re: [squid-users] All Adaptation ICAPs go down at the same time

2021-04-19 Thread Eliezer Croitoru
Hey Roie, >From the output I assume it’s a dns resolution issue. In the past I remember that Docker was updating the hosts file with the relevant names but it’s not working the same way now. Currently Docker is using a local network dns service which is being accessed via 127.0.0.53. >Fro

Re: [squid-users] Is there a way to bind squid's outbound traffice to a specific network interface

2021-04-19 Thread Eliezer Croitoru
It might be possible to use the tcp_outgoing_address for this purpose but it’s not clear What your setup technically look like and what is preventing the browser to do as you please. Eliezer From: squid-users On Behalf Of Cary Lewis Sent: Monday, April 12, 2021 12:58 AM To: squid-users@l

Re: [squid-users] allow request to cloudfront after 302 redirection.

2021-05-24 Thread Eliezer Croitoru
bin/location-openner.rb acl location_openner external openlocation http_access deny gitlab_package redirect location_openner http_access allow location_openner Thanks, ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-users

Re: [squid-users] allow request to cloudfront after 302 redirection.

2021-05-27 Thread Eliezer Croitoru
302 redirection. On 5/24/21 5:52 AM, Eliezer Croitoru wrote: > Following up this thread I was wondering about an example how to do > that with an external_acl helper. With ICAP I can do that easily to > some degree. With an external_acl helper I am not sure what values to > send. A

Re: [squid-users] Ubuntu 20.04 "apt update" issues behind a VPN and Squid proxy

2021-07-07 Thread Eliezer Croitoru
Hey David, Just wondering if you have seen the apt related docs at: https://help.ubuntu.com/community/AptGet/Howto/#Setting_up_apt-get_to_use_a_http-proxy Eliezer From: squid-users On Behalf Of David Mills Sent: Wednesday, July 7, 2021 2:26 AM To: squid-users@lists.squid-cache.org Subject: [sq

Re: [squid-users] TPROXY Error

2021-07-07 Thread Eliezer Croitoru
Hey Ben, I want to try and reset this issue because I am missing some technical details. 1. What Linux Distro and what version are you using? 2. the output of 'ip address' 3. the output of 'ip rule' 4. the output of 'ip route show' 5. the output of 'ip route show table 100' 6. the output of 'ip

Re: [squid-users] TPROXY Error

2021-07-07 Thread Eliezer Croitoru
Sent: Wednesday, July 7, 2021 3:36 PM To: Eliezer Croitoru ; squid-users@lists.squid-cache.org Subject: Re: [squid-users] TPROXY Error By the help of God. Hi Eliezer, Thanks for your help. Please let me know if you need more information. Regards, Ben On 07/07/2021 14:01, Eliezer Croitor

Re: [squid-users] Ubuntu 20.04 "apt update" issues behind a VPN and Squid proxy

2021-07-08 Thread Eliezer Croitoru
Hey David, I have just verified that the next guide works as expected: https://www.serverlab.ca/tutorials/linux/administration-linux/how-to-set-the-proxy-for-apt-for-ubuntu-18-04/ on Ubuntu 20.04 you can create the file: /etc/apt/apt.conf And then add to it the next lines: (replace th

Re: [squid-users] TPROXY Error

2021-07-13 Thread Eliezer Croitoru
Hey Ben, Still waiting for the relevant output. Once I will have the relevant details I will probably be able to verify how and what is the issue. Eliezer -Original Message- From: Eliezer Croitoru Sent: Thursday, July 8, 2021 12:04 AM To: 'squid-users@lists.squid-cache.org'

Re: [squid-users] [squid-announce] Squid 4.16 is available

2021-08-17 Thread Eliezer Croitoru
Hey Amos, I started testing the latest squid versions. It will probably will take more time then usual and I hope the RPMs will be ready tomorrow. Eliezer -Original Message- From: squid-announce On Behalf Of Amos Jeffries Sent: Thursday, July 22, 2021 7:24 AM To: squid-annou...@lists.s

Re: [squid-users] Squid performance issues

2021-09-05 Thread Eliezer Croitoru
From: https://serverfault.com/a/717273/227456 2 The number of file descriptors is set in the systemd unit file. By default this is 16384, as you can see in /usr/lib/systemd/system/squid.service. To override this, create a locally overriding /etc/systemd/system/squid.service which changes t

Re: [squid-users] [squid-announce] Squid 4.16 is available

2021-09-15 Thread Eliezer Croitoru
Hey Amos and Alex, I have tested the 4.16 version and it seems to work steady on basic loads. Eliezer -Original Message- From: squid-announce On Behalf Of Amos Jeffries Sent: Thursday, July 22, 2021 7:24 AM To: squid-annou...@lists.squid-cache.org Subject: [squid-announce] Squid 4.16 is

Re: [squid-users] About Squid 4, AD, Kerberos and AD group auth.

2021-09-25 Thread Eliezer Croitoru
Hey, Have you tried these instructions: https://support.kaspersky.com/KWTS/6.1/en-US/166336.htm Eliezer From: squid-users On Behalf Of Hernan Saltiel Sent: Monday, September 20, 2021 16:17 To: Amos Jeffries Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] About Squid

Re: [squid-users] About Squid 4, AD, Kerberos and AD group auth.

2021-09-27 Thread Eliezer Croitoru
Thanks, I am looking for an English guide. I am not to familiar with the language of the guide in the link. Eliezer From: Hernan Saltiel Sent: Sunday, September 26, 2021 15:16 To: Eliezer Croitoru Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] About Squid 4, AD

Re: [squid-users] Error 503 accessing Instagram/facebook via IPv6

2021-11-02 Thread Eliezer Croitoru
Hey, Is this a tproxy or intercept setup? Eliezer -Original Message- From: squid-users On Behalf Of marcelorodr...@graminsta.com.br Sent: Saturday, October 30, 2021 09:10 To: squid-users@lists.squid-cache.org Subject: [squid-users] Error 503 accessing Instagram/facebook via IPv6 Hi, I

Re: [squid-users] RES: Squid 4.13 does not access Facebook

2022-01-08 Thread Eliezer Croitoru
Use Ansible to do it… Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: <mailto:ngtech1...@gmail.com> ngtech1...@gmail.com From: squid-users On Behalf Of Graminsta Sent: Friday, January 7, 2022 23:40 To: 'Bruno de Paula Larini' ; squid-users@lists

[squid-users] 4.17 and 5.3 SSL BUMP issue: SSL_ERROR_RX_RECORD_TOO_LONG

2022-01-23 Thread Eliezer Croitoru
olution and I was wrong). If any details are missing let me know. I am pretty sure that there is an open bug for this issue and I am more then welcome to get a redirection towards it with a link. Thanks, Eliezer Croitoru Tech Support Mobile: +9

Re: [squid-users] 4.17 and 5.3 SSL BUMP issue: SSL_ERROR_RX_RECORD_TOO_LONG

2022-01-24 Thread Eliezer Croitoru
work in my specific scenario which I really don't care about caching when I'm in a DOS situation. ---- Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-users On Behalf Of Alex Rousskov Sent: Monday, January 24, 202

[squid-users] The status of AIA ie: TLS code: X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY ?

2022-01-25 Thread Eliezer Croitoru
about writing a daemon that will do the trick automatically for 4.17. Any ideas about the subject? Thanks, Eliezer Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com ___ squid-users mailing list squid-users@lists.

Re: [squid-users] Tune Squid proxy to handle 90k connection

2022-01-31 Thread Eliezer Croitoru
the real world usage will affect the service. I believe that 5 workers is enough and also take into account that the external helpers would also require CPU so don’t rush into changing the workers amount just yet. All The Bests, Eliezer Eliezer Croitoru NgTech, Tech Support

Re: [squid-users] squid url_rewrite_program how to return a kind of TCP reset

2022-01-31 Thread Eliezer Croitoru
/sb_icap.go Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> From: squid-users On Behalf Of David Touzeau Sent: Monday, January 31, 2022 10:54 To: squid-users@lists.squid-cache.org Subject: Re:

Re: [squid-users] external helper development

2022-02-02 Thread Eliezer Croitoru
optimize the system to take very high load. I hope the above will help you. Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-users On Behalf Of André Bolinhas Sent: Wednesday, February 2, 2022 00:

Re: [squid-users] How to fix the error error:transaction-end-before-headers in access log

2022-02-02 Thread Eliezer Croitoru
l-mgr/menu HTTP/1.1\r\nHost:\ proxy-host-or-ip\r\n Which will require couple manager ACLs to make sure only the LB will have access to the internal mgr pages. Hope This Helps, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Me

Re: [squid-users] external helper development

2022-02-03 Thread Eliezer Croitoru
have seen that it out-performs any other service I have tried until now. Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> From: squid-users On Behalf Of David Touzeau Sent: Thursday, Febr

Re: [squid-users] [ext] Re: Absolute upper limit for filedescriptors in squid-6?

2022-02-03 Thread Eliezer Croitoru
What OS are you using exactly? Thanks, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: Ralf Hildebrandt Sent: Thursday, February 3, 2022 09:42 To: NgTech LTD Cc: Squid Users Subject: Re: [squid-users

Re: [squid-users] external helper development

2022-02-06 Thread Eliezer Croitoru
and I will try to give an example via this: * HTTP * DNS * Others With the above example you would just need more helpers and add concurrency support to the squid external_acl helper configuration. With enough helpers the stdin buffers will be enough to compensate the missing threads impleme

Re: [squid-users] external helper development

2022-02-06 Thread Eliezer Croitoru
hread) stdin_thread = threading.Thread(target=handle_stdin, args=(2,)) stdin_thread.start() threads.append(stdin_thread) while(RUNNING): time.sleep(3) print("Not RUNNING") for thread in threads: thread.join() print("All threads stopped.") ## END

Re: [squid-users] [ext] Re: Absolute upper limit for filedescriptors in squid-6?

2022-02-06 Thread Eliezer Croitoru
It has Systemd, Use it. Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: Ralf Hildebrandt Sent: Friday, February 4, 2022 10:12 To: Eliezer Croitoru Cc: 'Squid Users' Subject: Re: [squid-u

Re: [squid-users] external helper development

2022-02-07 Thread Eliezer Croitoru
as not meant to be running as a STDIN/OUT daemon/helper software. All The Bests, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> From: David Touzeau Sent: Monday, February 7, 2022 02:42

Re: [squid-users] [squid-announce] Squid 5.4 is available

2022-02-09 Thread Eliezer Croitoru
, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com -Original Message- From: squid-announce On Behalf Of Amos Jeffries Sent: Wednesday, February 9, 2022 10:53 To: squid-annou...@lists.squid-cache.org Subject: [squid-announce] Squid 5.4 is

Re: [squid-users] [squid-announce] Squid 5.4 is available

2022-02-10 Thread Eliezer Croitoru
” Thanks, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> From: FredB Sent: Wednesday, February 9, 2022 18:41 To: squid-users@lists.squid-cache.org; Eliezer Croitoru Subject: Re: [squid-users]

Re: [squid-users] Vulnerabilities with squid 4.15

2022-02-10 Thread Eliezer Croitoru
on your setup so I might be able to clone such a setup it will help a lot. Thanks, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> From: robert k Wild Sent: Thursday, February 10, 2022 21

Re: [squid-users] Squid plugin sponsor

2022-02-10 Thread Eliezer Croitoru
7/8 I would be happy to try and re-create the lab here and to make sure that there will be a well documented configuration guide. If there is a good tutorial or guide I would be happy to try and verify if it works in my lab. Thanks, Eliezer Eliezer Croitoru NgTech, Tech Support Mobile: +972

  1   2   3   4   5   6   7   8   9   10   >