Re: [squid-users] Vary object loop returns

2016-06-07 Thread Yuri Voinov
about money. Traffic is money. Therefore, the more we will be able to properly and efficiently to cache - the better. 07.06.2016 17:00, Amos Jeffries пишет: > On 7/06/2016 9:12 p.m., Yuri Voinov wrote: >> >> >> >> 07.06.2016 5:13, Amos Jeffries пишет: >>> On 7/

Re: [squid-users] Vary object loop returns

2016-06-07 Thread Yuri Voinov
pays terabytes non-peering traffic? The same tricks I've seen with a user-agent. With Vary. 07.06.2016 16:36, Amos Jeffries пишет: > On 7/06/2016 8:48 p.m., Yuri Voinov wrote: >> >> 07.06.2016 4:57, Amos Jeffries пишет: >>> On 7/06/2016 5:55 a.m., Yuri Voinov wrote: >

Re: [squid-users] Vary object loop returns

2016-06-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 # Clean up Vary to increase caching reply_header_access Vary deny all reply_header_replace Vary Accept-Encoding Hmmm? ;) 08.06.2016 22:02, Heiler Bemerguy пишет: > > > Hum.. Amos, that store_miss would just make the object with that Vary header

Re: [squid-users] Vary object loop returns

2016-06-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Ok, Amos. How to correctly normalize headers? I.e., to strip User-Agent, for example? 08.06.2016 23:02, Amos Jeffries пишет: > On 9/06/2016 4:03 a.m., Yuri Voinov wrote: >> >> # Clean up Vary to increase caching >> rep

Re: [squid-users] Vary object loop returns

2016-06-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Alternate-Protocol - agreed. With both directions, for request and replies. Alt-Svc -can be discussed. X-Firefox-Spdy - can be discussed. 08.06.2016 22:47, joe пишет: > deny those will help > > Strict-Transport-Security > Alternate-Protocol > a

Re: [squid-users] Somewhat OT: Content Filter with https

2016-06-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 AFAIK ufdbguard has no alternative. 09.06.2016 2:05, Sergio Belkin пишет: > Hi, > > I've been using a few years ago squid+dansguardian. But nowadays, DG is not maintained anymore. I know that exists squidGuard, ufdbGuard, and e2guardian. > > Feat

Re: [squid-users] Somewhat OT: Content Filter with https

2016-06-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I confirm. I've replaced squidGuard with ufdbguard significantly long time ago and uses it in production. With SSL Bump. It's very fast, has not unlimited memory consumption. And - this is important - has client-server model. 09.06.2016 2:37, M

Re: [squid-users] Redirect after sslbump teminate

2016-06-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yes no problem. Signs the certificate of the local web server with root certificate the proxy, which is already in user's browser - and voila. 13.06.2016 15:01, Antony Stone пишет: > On Monday 13 June 2016 at 10:51:35, Eng Hooda wrote: > >> Thank

Re: [squid-users] Regex optimization

2016-06-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I propose to nominate for the second place of the contest "The most inefficient use of computing resources - 2016." :-!:-D Because first place already occuped. :-D 30 millions pornsites in one squid's ACL and 7 minutes for squid -k refresh. 8-)

Re: [squid-users] Regex optimization

2016-06-17 Thread Yuri Voinov
considering its price. So. 17.06.2016 3:11, Benjamin E. Nichols пишет: > > > > On 6/16/2016 3:28 PM, Yuri Voinov wrote: > I propose to nominate for the second place of the contest "The most > inefficient use of computing resources - 2016." :-!:-D > > Because f

Re: [squid-users] Regex optimization

2016-06-17 Thread Yuri Voinov
: > > > > On 6/16/2016 3:28 PM, Yuri Voinov wrote: > I propose to nominate for the second place of the contest "The most > inefficient use of computing resources - 2016." :-!:-D > > Because first place already occuped. :-D 30 millions pornsites in one > squid's

[squid-users] ECDSA and SSL bump

2016-06-18 Thread Yuri Voinov
secure connection. With CIPHER/PROTOCOL negotiation error in browser. Yea, latest Chrome. Does this mean that Squid is not support ECDSA? WBR, Yuri -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXZUHLAAoJENNXIZxhPexGIuYIAI/9zSbTSdAcR1aUGV1paYyt

Re: [squid-users] ECDSA and SSL bump

2016-06-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 19.06.2016 17:40, Amos Jeffries пишет: > On 19/06/2016 10:17 p.m., Yuri wrote: >> Must be: >> >> openssl ecparam -name secp384r1 -genkey -param_enc named_curve -out >> rootCA.key >> >> :) >> >

Re: [squid-users] ECDSA and SSL bump

2016-06-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Cert generator is ok. Bug 4497 still not gone. So, it is irrelevant ECDSA. Sad. 19.06.2016 15:18, Amos Jeffries пишет: > On 19/06/2016 12:42 a.m., Yuri Voinov wrote: >> >> Good weekend to all. >> >> Gentlemen,

Re: [squid-users] ECDSA and SSL bump

2016-06-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ECDSA works with any combination with RSA in CA-subordinate CA's. Will check compatibility issues, if any. 19.06.2016 17:40, Amos Jeffries пишет: > On 19/06/2016 10:17 p.m., Yuri wrote: >> Must be: >> >> openssl ecpar

Re: [squid-users] ECDSA and SSL bump

2016-06-20 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 akamaihd.net has compatibility issues with ECDSA squid's certs. fb.com behind it, etc. 20.06.2016 0:10, Yuri Voinov пишет: > > ECDSA works with any combination with RSA in CA-subordinate CA's. > > Will check compat

Re: [squid-users] ECDSA and SSL bump

2016-06-20 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Windows Updates is also incompatible with ECDSA due to akamai behind. :) 20.06.2016 17:19, Yuri Voinov пишет: > > akamaihd.net has compatibility issues with ECDSA squid's certs. fb.com behind it, etc. > > 20.06.2016 0:10,

Re: [squid-users] Configuring squid to work as an HTTPS proxy

2016-06-20 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You using wrong and extremal unspecific manual. Feel free to use our good manuals: http://wiki.squid-cache.org/ConfigExamples 20.06.2016 20:02, Jobin George пишет: > > Hi, > > > > I am trying to setup squid3 as an HTTPS proxy using the tutoria

Re: [squid-users] Unknown Cipher Suite

2016-06-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL still not support ChaCha-Poly this days. And unknown when be supported. This time only exists unsupported patch from CloudFlare. And, as alternative, LibreSSL. Which is not available for all platforms. 22.06.2016 22:48, Amos Jeffries пише

Re: [squid-users] WTF ? SSL Certficate error: certificate issuer (CA) not known

2016-06-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Unknown intermediate certificate, that's all. Dig to the direction sslproxy_foreign_intermediate_certs parameter. 23.06.2016 1:07, sebastien.boulia...@cpu.ca пишет: > > Hu ? > > > > My CA is known… Where is the issue ? :( > > The sy

Re: [squid-users] Latest ssl and Squid stable compile issue

2016-06-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I suggest this will not solve your unknown cipher issue. :) 23.06.2016 3:12, James Lay пишет: > Had zero issues when compiling against libressl-2.4.1. I now have ChaCha > Poly cipher support...happy days! > > James > > On 2016-06-22 13:29, Jame

Re: [squid-users] flickr.com redirect error

2016-06-24 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hm. My opinion is the same - this is redirection loop. Just need to localize it. 24.06.2016 20:23, Ozgur Batur пишет: > Hi Yuri, > > Thank you. I put the #301 loop directives and restarted squid unfortunately result is the same. He

Re: [squid-users] flickr.com redirect error

2016-06-24 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Be careful, guys. Via is reauired to HTTP by RFC. 24.06.2016 21:40, Ozgur Batur пишет: > Hi Rafael, Yuri, > > Thank you very much, "via off" did the trick. It is probably a server specific issue as you said. > > Best Re

Re: [squid-users] Skype Issues

2016-06-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Amos, you are a wrong. No Squid-4. It's unstable and not ready for production. Whenever it's features. Some time ago I have the same issue and know what happens exactly. Skype initial connection site uses RC4 cipher. Which is disabled in most sq

Re: [squid-users] Problem with certificates and SSLBump

2016-06-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Use search. Some days agi I've played around with ECDSA certs and drop it due to extremal incompatibility with clients. Here was this thread. 25.06.2016 22:10, C. L. Martinez пишет: > Hi all, > > I have some problems with my squid config when I

Re: [squid-users] Skype Issues

2016-06-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 25.06.2016 23:09, Amos Jeffries пишет: > On 26/06/2016 4:32 a.m., Yuri Voinov wrote: >> >> Amos, you are a wrong. >> >> No Squid-4. It's unstable and not ready for production. Whenever it's >> f

Re: [squid-users] Problem with certificates and SSLBump

2016-06-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 25.06.2016 23:22, Amos Jeffries пишет: > On 26/06/2016 4:46 a.m., C. L. Martinez wrote: >> On Sat 25.Jun'16 at 22:33:56 +0600, Yuri Voinov wrote: >>> >>> -BEGIN PGP SIGNED MESSAGE- >>> Hash: SHA2

Re: [squid-users] Problem with certificates and SSLBump

2016-06-25 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 25.06.2016 23:47, C. L. Martinez пишет: > On Sun 26.Jun'16 at 5:22:31 +1200, Amos Jeffries wrote: >> On 26/06/2016 4:46 a.m., C. L. Martinez wrote: >>> On Sat 25.Jun'16 at 22:33:56 +0600, Yuri Voinov wrote: >

Re: [squid-users] Skype Issues

2016-06-29 Thread Yuri Voinov
issues. > Thanks for your help. > > > Renato Jop > > On Mon, Jun 27, 2016 at 9:36 AM, Renato Jop mailto:ren...@gmail.com>> wrote: > > Is there a way to verify that the SSL library doesn't support SSLv3? > > Renato Jop > >

Re: [squid-users] url_rewrite_program is ignored by squid

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Squidguard abandoned for years. Drop it out. 29.06.2016 23:12, Moataz Elmasry пишет: > Hi all, > > I'm trying to use squid with squidguard, but it seems that squid3 is somehow ignoring the url_rewrite_program completely. While starting squid I'm

Re: [squid-users] Cache economy calculation

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hhh... billing system? 30.06.2016 0:29, Eduardo Carneiro пишет: > Hello everyone. > > I am using Squid 3.5.19 with dynamic and static caching feature activated. > It's working very well. All entries of the access.log are in a post

Re: [squid-users] Cache economy calculation

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Eh, if you have access.log in SQL database, you cah simple write SQL query - viola! select (TCP_HIT/TCP_MISS)*100 from access_log; // Cache hit select (field_with_bytes_from_access_log_table * TCP_HIT_count/field_with_bytes_from_access_log_table

Re: [squid-users] Cache economy calculation

2016-06-29 Thread Yuri Voinov
:))) 30.06.2016 1:16, Yuri Voinov пишет: > > Eh, if you have access.log in SQL database, you cah simple write SQL > query - viola! > > select (TCP_HIT/TCP_MISS)*100 from access_log; // Cache hit > > select (field_with_bytes_from_access_log_table * > TCP_HIT_count/field_with_byt

Re: [squid-users] Cache economy calculation

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You can extend your SQL query as you required, of course. This was only an direction, idea. Or, possible to write several different queries, like existing script-based reporting tool. 30.06.2016 0:45, Eduardo Carneiro пишет: > Thank you Y

Re: [squid-users] Cache economy calculation

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yep. Sure. 30.06.2016 0:57, Eduardo Carneiro пишет: > Thank you again. In this case, I think that I'll exclude the "DENIED" of my > query. Theoretically this access don't go to the internet. That's correct? > > > > -- > View this message in conte

Re: [squid-users] url_rewrite_program is ignored by squid

2016-06-29 Thread Yuri Voinov
; > What are seeing in the squid access.log file at the same time you are using the proxy? > > It should show something when you load a simple HTTP page such as: > > http://www.squid-cache.org/ > > > > And Yuri, > > As was mentioned here in another thread. > > Indeed

Re: [squid-users] url_rewrite_program is ignored by squid

2016-06-29 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 30.06.2016 3:30, Yuri Voinov пишет: > > > > 30.06.2016 2:34, Eliezer Croitoru пишет: > > > > Hey Moataz,( is this the first name?) > > > > > > > > > I would be able to t

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Consider TCP/UDP/53 Cisco interception + Unbound + dnscrypt. And 127.0.0.1:53 as your squid's DNS resolver finally. 01.07.2016 1:07, Chris Horry пишет: > > > On 06/30/2016 14:55, Alex Crow wrote: >> >> >> On 30/06/16 19:40, brendan kearney wrote:

Re: [squid-users] NOTICE: Authentication not applicable on intercepted requests.

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 01.07.2016 1:19, Eugene M. Zheganin пишет: > Hi. > > On 30.06.2016 17:04, Amos Jeffries wrote: >> On 30/06/2016 9:21 p.m., Eugene M. Zheganin wrote: >>> Hi, >>> >>> Could this message be moved on loglevel 2 instead of 1 ? >>> I think that this me

Re: [squid-users] NOTICE: Authentication not applicable on intercepted requests.

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 01.07.2016 1:19, Eugene M. Zheganin пишет: Interceprion proxy don't support auth. By default. End of discussion. -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXdXErAAoJENNXIZxhPexGHuwIAIlMz0C0PIyIQ1iL3eS71M0d 85SHy+iET55da6R

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
> could use the mangle netfilter table to change your DNS queries and so deceive your ISP, but I'm almost sure that the root servers will not recognize. It was just an idea. > > 2016-06-30 16:16 GMT-03:00 Yuri Voinov mailto:yvoi...@gmail.com>>: > > > Consider TC

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
change your DNS queries and so deceive your ISP, but I'm almost sure that the root servers will not recognize. It was just an idea. > > 2016-06-30 16:16 GMT-03:00 Yuri Voinov mailto:yvoi...@gmail.com>>: > > > Consider TCP/UDP/53 Cisco interception + Unbound + dnscrypt. And

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
dress transparent_dns set ip next-hop ip.of.your.server route-map redirect_dns permit 20 interface fax/x ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx ip policy route-map redirect_dns 01.07.2016 1:29, Yuri Voinov пишет: > > Just no forward queries to roots, what's the problem with Unbound? >

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 DNScrypt is not required any crypto. it encrypted itself. Just Google-fu it. :) 01.07.2016 1:33, Chris Horry пишет: > > > On 06/30/2016 15:30, Yuri Voinov wrote: >> >> I've google-fu for you: >> >> ! >

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 PS. Initial level Cisco router cost at eBay is less than 40$. It's a garbage. 01.07.2016 1:33, Chris Horry пишет: > > > On 06/30/2016 15:30, Yuri Voinov wrote: >> >> I've google-fu for you: >> >> !

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I'm wrong. 11,50$ http://www.ebay.com/itm/Cisco-1800-Series-1841-Router-With-64MB-Flash-Card-w-Power-Cord-/142035497145 01.07.2016 1:35, Yuri Voinov пишет: > > PS. Initial level Cisco router cost at eBay is less than 40$. It&

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 IDK when user is only one :) There is no Cisco required :) 01.07.2016 2:05, reinerotto пишет: > There is no need for cisco stuff. > dnscrypt-proxy+dnsmasq, for example, to be used + one of the many open > dnscrypt servers form this list: > https:

Re: [squid-users] Force DNS queries over TCP?

2016-06-30 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Just fantasy required :) :) :) And Google-fu :) 01.07.2016 2:52, Yuri Voinov пишет: > > IDK when user is only one :) There is no Cisco required :) > > > 01.07.2016 2:05, reinerotto пишет: > > There is no need for cisco stuf

Re: [squid-users] Force DNS queries over TCP?

2016-07-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Dont forget about legal issues. Using anti-ISP filtration/censorship crypto solutions can be completely out-of-law in some countries. 01.07.2016 20:27, reinerotto пишет: > Please, don't be so cryptic in your comments. The long quotations of the

Re: [squid-users] Force DNS queries over TCP?

2016-07-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 01.07.2016 20:27, reinerotto пишет: > Please, don't be so cryptic in your comments. The long quotations of the org DNScrypt is offtopic here. -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXdot8AAoJENNXIZxhPexG1RMH/21m/r+SjV+MrE

Re: [squid-users] Force DNS queries over TCP?

2016-07-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 :) I'm moron too :) 01.07.2016 21:30, Antony Stone пишет: > On Friday 01 July 2016 at 17:25:49, Yuri Voinov wrote: > >> DNScrypt is offtopic here. > > ... says the man who has posted 11 of the 22 (now 23) emails in this

Re: [squid-users] Force DNS queries over TCP?

2016-07-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 cisco is just one of them. Let me explain to you why the conversation turned for Cisco. Squid (as by as another proxies) is used most frequently as a server for the user group. Each of them can set their own DNS settings. That may be completely d

Re: [squid-users] how to fix proxy squid on virtualmin (ubuntu 16, 04)?

2016-07-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Antonio, the gods punished you :) You're too many try to help :) Even so, it :) 03.07.2016 21:36, james82 пишет: > So now what? I don't have any file on hdd1, ssd1 ,... So how to edit it? you > not give me correct answer. > > cache_dir rock /hd

Re: [squid-users] how to fix proxy squid on virtualmin (ubuntu 16, 04)?

2016-07-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Antonio, are you kidding :) Some people need answers in the form of comic books or videos on YouTube. Magic Button "Make excellent" and how her push :) PS. But comic books is preferable. : 04.07.2016 1:21, Antony Stone пишет: > On Sunday

Re: [squid-users] host_verify_strict and wildcard SNI

2016-07-06 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sounds familiar. Do you experience occasional problems with CloudFlare sites? 06.07.2016 20:36, Steve Hill пишет: > > I'm using a transparent proxy and SSL-peek and have hit a problem with an iOS app which seems to be doing broken things with th

Re: [squid-users] host_verify_strict and wildcard SNI

2016-07-06 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I know. Just asked. Since I am familiar with the standards. 07.07.2016 1:54, Eliezer Croitoru пишет: > Hey Yuri, > > These two subjects are not related directly to each other but they might have something in common. > Squid exp

Re: [squid-users] host_verify_strict and wildcard SNI

2016-07-06 Thread Yuri Voinov
still do not see any reason why any solutions to these problems. Moreover, the splice does not solve these problems. Just skip the whole networks in the proxy bypass. What is totally unacceptable. Traffic is money. And a lot of money. 07.07.2016 2:38, Eliezer Croitoru пишет: > Hey Yuri, >

Re: [squid-users] host_verify_strict and wildcard SNI

2016-07-07 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 07.07.2016 19:59, Marcus Kool пишет: > > > On 07/07/2016 10:49 AM, Yuri wrote: > >>>>>>>> A similar question can be asked about SNI names containing unusual >>>>>>>> charact

Re: [squid-users] adaptation_access not working with squid acl's

2016-07-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 http://wiki.squid-cache.org/ConfigExamples/ContentAdaptation/C-ICAP 14.07.2016 21:06, Stephen Stark пишет: > Hello, > > I been having trouble getting this to work in 3.5 > > I have an acl like the one below. I am having a problem when I use this

Re: [squid-users] Authenticacion with Active Directory fails

2016-07-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Man, did your RTFM? Kerberos security has perfect manual. 14.07.2016 22:07, Sergio Belkin пишет: > Hi, > > Using squid squid-3.5.19-1.el7.centos.x86_64, > > I obtain a kerberos ticket but I get the following when trying to use the proxy: > > 20

Re: [squid-users] Authenticacion with Active Directory fails

2016-07-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 http://wiki.squid-cache.org/ConfigExamples/Authenticate/Kerberos#Configuring_a_Squid_Server_to_authenticate_from_Kerberos 14.07.2016 23:59, Yuri Voinov пишет: > > Man, > > did your RTFM? > > Kerberos security has perfect manual

Re: [squid-users] adaptation_access not working with squid acl's

2016-07-14 Thread Yuri Voinov
access service_avi_resp deny all > > but that does not seem to work. > > So i would think it would test1 acl to would get scaned but it does not. > > Any help would be great! > > > On Jul 14, 2016 1:52 PM, "Yuri Voinov" mailto:yvoi...@gmail.com>&g

Re: [squid-users] adaptation_access not working with squid acl's

2016-07-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Feel free to read our wiki. Here can be answers on most of your questions, is it? 15.07.2016 0:35, Yuri Voinov пишет: > > > http://wiki.squid-cache.org/action/show/HelpOnAccessControlLists?action=show&redirect=HelpOnAcl > &

Re: [squid-users] adaptation_access not working with squid acl's

2016-07-15 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 15.07.2016 15:41, Amos Jeffries пишет: > On 15/07/2016 6:35 a.m., Yuri Voinov wrote: >> >> >> http://wiki.squid-cache.org/action/show/HelpOnAccessControlLists?action=show&redirect=HelpOnAcl >> > > Yrui; note

Re: [squid-users] Squid Transparent WEB Captatif : Cisco ASA WCCP

2016-07-15 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 15.07.2016 21:52, Maxime Lambert пишет: > Hi everyone !! > > My issue is that i didn't received any data in access.log. I work on Ubuntu Server 16.04 with Squid 5.3.20 compiled with : > ./configure --prefix=/usr --localstatedir=/var --libexecdir=

Re: [squid-users] This is first time I use squid, i don't know how to edit file squid.conf for start using squid

2016-07-18 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I suggest be better you start from here: https://en.wikipedia.org/wiki/Text_editor https://en.wikipedia.org/wiki/List_of_text_editors There is no step-by-step instruction how to edit text file. This is very basic IT experience you must to have b

Re: [squid-users] protect squid.conf file

2016-07-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The simplest way I see is: - - Write you own custom squid's startup script (with bash/any shell you want). - - This script will decrypt squid.conf before any startup/shutdown/reconfigure operation then encrypt config again. - - Therefore squid.c

Re: [squid-users] protect squid.conf file

2016-07-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 23.07.2016 2:04, Antony Stone пишет: > On Friday 22 July 2016 at 21:53:31, Yuri Voinov wrote: > >> The simplest way I see is: >> >> - Write you own custom squid's startup script (with bash/any shell you >> want

Re: [squid-users] protect squid.conf file

2016-07-22 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 23.07.2016 2:22, Antony Stone пишет: > On Friday 22 July 2016 at 22:14:36, Yuri Voinov wrote: > >> 23.07.2016 2:04, Antony Stone пишет: >>> >>> How does this help? >> >> Yes, this is idiotic idea :) &g

[squid-users] http://www.squid-cache.org/Versions/v4/

2016-07-27 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 See here for days on end is a bit fed up: https://i1.someimage.com/6OTXUOr.png What is going on? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXmRQqAAoJENNXIZxhPexGk8sH/2OaD/0VVXnvANgonp/CKf8z IFhXIwaltIJ+SOZ/zdhMNwfaT43cjXwLz

Re: [squid-users] how to add default directive to squid

2016-07-28 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 AFAIK, you want just start squid without any config file or with empty config? 28.07.2016 14:27, --Ahmad-- пишет: > Hi Developers . > > i want to add like default directive to squid > > as we know the default cache_mem is 256 M > i want to add s

Re: [squid-users] Fwd: All website getting Blocked

2016-08-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You haven't permissive rule for localnet. 03.08.2016 22:53, Harsha S Aryan пишет: > > -- Forwarded message -- > From: *Harsha S Aryan* mailto:harsha.s.ar...@gmail.com>> > Date: Wed, Aug 3, 2016 at 10:22 PM > Subject: All website g

Re: [squid-users] Range header is a hit ratio killer

2016-08-07 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 So, the overall answer is "NO". You can use Store-ID + collapsed forwarding functionality to achieve something your want. May be together, may be separate. Hard luck :) But this is your own problem. No one will solve the problem without the infu

Re: [squid-users] squid 3.3.8 https

2016-08-08 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 3.3.8 is antique at 2016. Upgrade at least to 3.5.20. 09.08.2016 2:39, Erdosain9 пишет: > > I want to limit the bandwidth for youtube, so I want to intercept https connections. I followed several tutorials and can not. Could someone give me a ha

Re: [squid-users] X-Squid-Error

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I'm regulary got the same error. By my observations, it's produces by GTalk. 12.08.2016 15:05, joe пишет: > it was on debug all 2 if you want i re install it and do dump on all 9 > i did not try the relise r14785 > r14782 was good > > 2016/0

Re: [squid-users] How can I complete this tutorial?

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Man, if you do not know what to add - we do the more we can not know. You asked - what do you want to do? Formulate the problem, it makes it clear that it is necessary to add. If you do not know yourself, you have to do - we can know where it came

Re: [squid-users] How can I complete this tutorial?

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It is not sesessary to make screenshots every time, man. Just enough copy-n-paste relevant cache.log entries. You are freaking annoying. Can you clearly explain what you want to achieve and clearly formulate the problem? Do we have to guess your

Re: [squid-users] Helppppp

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Wait a minute, man. Can you describe in more detail what's wrong with you? 12.08.2016 19:29, Michel пишет: > Hello everyone. I have the following problem. The squid server has the > system time correctly however messages > squid out with 5 hours

Re: [squid-users] Helppppp

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Also - most obvious question: which TZ is setted up on your box globally, and per-user ? Seems you squid's user TZ is different than global. 12.08.2016 20:04, Yuri Voinov пишет: > > Wait a minute, man. Can you describe in more detail w

Re: [squid-users] X-Squid-Error

2016-08-12 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Something like self-made bullshit proto, something like bittorrent-over-http or something. Heh. Webmasters still respect us! 12.08.2016 22:00, Amos Jeffries пишет: > On 13/08/2016 3:17 a.m., joe wrote: >> 2016/08/12 18:14:51.855 kid1| 74,9| Req

Re: [squid-users] How can I complete this tutorial?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 # NETWORK OPTIONS # - # TAG: http_port #Usage:port [mode] [options] #hostname:port [mode] [options] #1.2.3.4:port [mode] [options] # #The sock

Re: [squid-users] How can I complete this tutorial?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 For forwarding HTTP-proxy it is enough http_port 3128 13.08.2016 19:36, james82 пишет: > Is I edit this right: > # Squid normally listens to port 3128 > http_port 3128 80 443 > > # TAG: https_port > # Note: This option is only available if Squid

Re: [squid-users] How can I complete this tutorial?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 #You may specify multiple socket addresses on multiple lines, #each with their own SSL certificate and/or options. Man, really, read squid.conf.documented! All you questions are answered there! 13.08.2016 20:29, james82 пишет: > what abo

Re: [squid-users] How can I complete this tutorial?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 This not helps you. Once more. Again and again. 1. Specify you task. What do you want to achieve with squid. Exactly. Do your understand this phrase? You task. 2. Read fine squid manuals. Including squid.conf.documented. Did you understand, whic

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 https://torproject.org Not by squid. 13.08.2016 22:54, james82 пишет: > I want change my public ip-address to access some website by use squid proxy. > Is I actually can do that? How to do that? > > > > -- > View this message in context: http://

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 2008? This is antique tutorial. 8 years in IT is eternity. 14.08.2016 3:11, Vito A. Smaldino пишет: > Here > https://itechnology.wordpress.com/2008/05/26/setup-squid-proxy-server-to-use-multiple-outgoing-ip-addresses/ > you can find a good exa

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I suggests you lost of op point. He is talking about anonimity, not about rotating outgoing IP's. 14.08.2016 3:24, Yuri Voinov пишет: > > 2008? > > This is antique tutorial. 8 years in IT is eternity. > > > 14.08.2016 3:

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
functions. In fact, I just did not hear the problem statement, which could be required for this functionality. 14.08.2016 3:40, Vito A. Smaldino пишет: > > > 2016-08-13 23:24 GMT+02:00 Yuri Voinov mailto:yvoi...@gmail.com>>: > > > 2008? > > This is antique tutor

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.08.2016 3:59, Vito A. Smaldino пишет: > > > 2016-08-13 23:31 GMT+02:00 Yuri Voinov mailto:yvoi...@gmail.com>>: > > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > I suggests you lost

Re: [squid-users] Is I can change my public ip-address by use squid proxy?

2016-08-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.08.2016 3:59, Vito A. Smaldino пишет: > > > 2016-08-13 23:31 GMT+02:00 Yuri Voinov mailto:yvoi...@gmail.com>>: > > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > I suggests you lost

Re: [squid-users] Squid cpu usage 100% from few days ago !!

2016-08-14 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 14.08.2016 18:35, Antony Stone пишет: > On Sunday 14 August 2016 at 14:25:38, Omid Kosari wrote: > >> Still could not find the app or url but the 2 server ip addresses are >> 149.202.92.139 and 173.236.187.17 . > > The first does not respond on p

[squid-users] 2016/08/15 18:20:53 kid1| WARNING: HTTP: Invalid Response: No object data received for

2016-08-15 Thread Yuri Voinov
al/ws/be91a9c2b5ce789cb72eb0262551eff0fbbcc00f2c44ad01c1e89e3671d20369 AKA lp-push-server-164.lastpass.com/ws/be91a9c2b5ce789cb72eb0262551eff0fbbcc00f2c44ad01c1e89e3671d20369 Most often for sites with AKA names. As you can see in entrie above, this is store-ID rewrited URL. What does it mean and how to suppress this warnings? WBR, Yuri -BEGI

[squid-users] kid1| WARNING: HTTP: Invalid Response: No object data received for

2016-08-15 Thread Yuri Voinov
al/ws/be91a9c2b5ce789cb72eb0262551eff0fbbcc00f2c44ad01c1e89e3671d20369 AKA lp-push-server-164.lastpass.com/ws/be91a9c2b5ce789cb72eb0262551eff0fbbcc00f2c44ad01c1e89e3671d20369 Most often for sites with AKA names. As you can see in entrie above, this is store-ID rewrited URL. What does it mean and how to suppress this warnings? WBR, Yuri -BEGI

Re: [squid-users] kid1| WARNING: HTTP: Invalid Response: No object data received for

2016-08-15 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Maybe I'm not very well put. As I understand it, the AKA is the original name, which does not work out quite correctly Store ID. Anyway, what caused this warning? 15.08.2016 18:27, Yuri Voinov пишет: > > Hi gents. > > Someti

Re: [squid-users] kid1| WARNING: HTTP: Invalid Response: No object data received for

2016-08-15 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 15.08.2016 18:46, Amos Jeffries пишет: > On 16/08/2016 12:31 a.m., Yuri Voinov wrote: >> >> Maybe I'm not very well put. As I understand it, the AKA is the original >> name, which does not work out quite correctly St

Re: [squid-users] kid1| WARNING: HTTP: Invalid Response: No object data received for

2016-08-16 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 16.08.2016 22:57, Alex Rousskov пишет: > On 08/15/2016 06:46 AM, Amos Jeffries wrote: >> On 16/08/2016 12:31 a.m., Yuri Voinov wrote: >>> >>> Maybe I'm not very well put. As I understand it, the AKA is the origin

Re: [squid-users] Yet another store_id question HIT MISS

2016-08-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 17.08.2016 20:28, Amos Jeffries пишет: > On 18/08/2016 1:43 a.m., Omid Kosari wrote: >> Why following link is HIT >> >> X-Cache:"HIT from cache1" >> X-Cache-Lookup:"HIT from cache1:3128" >> >> >> http://igcdn-photos-c-a.akamaihd.net/hphotos-ak-xa

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-17 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Vips do not want enter username and password? :) 18.08.2016 2:58, erdosain9 пишет: > Hi > Squid configured to authenticate with AD with LDAP. this is the relevant > configuration. > > > # Active Directory > auth_param basic program /usr/lib64/squ

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 https://www.google.com/search?q=Kerberos+%28Heimdal%29+configuring 19.08.2016 21:20, erdosain9 пишет: > Kerberos (Heimdal) -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXtykTAAoJENNXIZxhPexG3yUH/3wOl8nd6OAtfWVcCKYvDqFS A2aAiVL

Re: [squid-users] AD Ldap (automatically take the user that is logging on PC)

2016-08-19 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sorry, this is not to me. My setups works without any authentication, just transparent interception. :) 20.08.2016 0:16, erdosain9 пишет: > :-) > lol > > This is the krb5.conf in the AD. > [libdefaults] > default_realm = EPRUEBA.LAN >

<    3   4   5   6   7   8   9   10   11   12   >