Re: [squid-users] squid + dansguardian + havp https

From: troxlinux <xserverlinux_at_gmail.com>
Date: Fri, 13 May 2011 08:37:36 -0600

2011/5/12 Amos Jeffries <squid3_at_treenet.co.nz>:
> Versions would be helpful.

Hi amos my version is

squid-2.6.STABLE21-6.el5

>
> Your log show a success (status 200) reply using HTTP protocol.
>  The only thing strange is that "http://www.hotmail.com" always replies with
> a 302 redirect for me, never 200.
>
> This 200 response is coming out of HavP (127.0.0.1). Whether it is casued
> there or at the origin we can't tell yet.
>
>
> HTTPS uses CONNECT requests. CONNECT only send the domain:port or IP:port
> for the URL, and will always have unknown (infinite) body size for both
> request and reply. So be extra careful about what filters you try an make
> them pass in DG and HavP.
>
>  Squid will attempt to open a direct TCP connection (bypassing havp) and
> pass the SSL encrypted data down it unless you configure
> "nonhierarchichal_direct off".
>

I put this option , but not load the pages , the stranger is that now
I see the 302, but does not work

see the log:

 TCP_MISS/302 1113 GET http://mail.google.com/mail/ -
DIRECT/74.125.229.117 text/html
1305296398.800 3906 127.0.0.1 TCP_MISS/302 1814 GET
http://www.hotmail.com/ - DIRECT/64.4.56.87 text/html1305296448.8

regards

-- 
rickygm
http://gnuforever.homelinux.com
Received on Fri May 13 2011 - 14:38:03 MDT

This archive was generated by hypermail 2.2.0 : Sat May 14 2011 - 12:00:01 MDT