• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Squid 6.5 !! Nov 6th

Cache/Proxy
squid update bug fixes upstream fix
12
82
17.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kiokoman LAYER 8 @lg1980
    last edited by Dec 28, 2023, 1:45 PM

    It would be interesting to see what netgate have to say about this now,
    it seems that alot of cve if not all have been patched in squid 6.4 and 6.5, IMHO it would be a shame to remove this package from the list now. any chance that netgate will retreat that statement and continue to support squid or is it the final decision? @stephenw10 ?

    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
    Please do not use chat/PM to ask for help
    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

    J 1 Reply Last reply Dec 29, 2023, 6:45 PM Reply Quote 2
    • J
      JonathanLee @kiokoman
      last edited by Dec 29, 2023, 6:45 PM

      @kiokoman I would too, if the update fixes all of the issues why not use it?

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • J JonathanLee referenced this topic on Jan 5, 2024, 10:11 PM
      • J
        JonathanLee @lg1980
        last edited by Jan 5, 2024, 10:13 PM

        @lg1980 What is the recommended donation for this update? Also I can start to test this Jan 8th or 9th when all the kids are back in school

        Make sure to upvote

        L 1 Reply Last reply Jan 8, 2024, 11:55 AM Reply Quote 1
        • L
          lg1980 @JonathanLee
          last edited by Jan 8, 2024, 11:55 AM

          @JonathanLee said in Squid 6.5 !! Nov 6th:

          What is the recommended donation for this update? Also I can start to test this Jan 8th or 9th when all the kids are back in school

          I have no economic interest in these updates and support from Squid, whatever I personally feel in relation to covering my hours/dedication to work financially.

          J 1 Reply Last reply Jan 12, 2024, 4:27 PM Reply Quote 0
          • J
            JonathanLee
            last edited by Jan 9, 2024, 1:17 AM

            @stephenw10

            Did you check this out Squid with all the updates !!!

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • J
              JonathanLee @lg1980
              last edited by Jan 10, 2024, 10:12 PM

              @lg1980 result for use with arm processor

              🔒 Log in to view

              Make sure to upvote

              L 1 Reply Last reply Jan 12, 2024, 8:24 PM Reply Quote 0
              • J
                JonathanLee @lg1980
                last edited by Jan 12, 2024, 4:27 PM

                @lg1980 how can I test the package?

                Make sure to upvote

                1 Reply Last reply Reply Quote 0
                • J
                  jc1976
                  last edited by Jan 12, 2024, 8:08 PM

                  all these updates are great but what happens when it's finally done?

                  Netgate said squid will no longer be available in the package manager with the next major release of pfsense, so it seems squids days are numbered, at least for pfsense, which really sucks..

                  there's haproxy, but that lacks av integration.. people might say "it doesn't matter b/c internet traffic is encrypted.. yes, but if you're behind a proxy, then it works well!

                  so what are we supposed to do?

                  J 1 Reply Last reply Jan 12, 2024, 8:09 PM Reply Quote 0
                  • J
                    JonathanLee @jc1976
                    last edited by Jan 12, 2024, 8:09 PM

                    @jc1976 You just manually install it if you use it like us. It will be back alot of users use this.

                    Make sure to upvote

                    J 1 Reply Last reply Jan 12, 2024, 8:16 PM Reply Quote 0
                    • J
                      jc1976 @JonathanLee
                      last edited by Jan 12, 2024, 8:16 PM

                      @JonathanLee

                      ok, but if netgate removes it from the package manager and we have to manually install it, does that mean the gui portion of it will be removed and all configuring will need to be done via cli?

                      J L 3 Replies Last reply Jan 12, 2024, 8:19 PM Reply Quote 0
                      • J
                        JonathanLee @jc1976
                        last edited by JonathanLee Jan 12, 2024, 8:19 PM Jan 12, 2024, 8:19 PM

                        @jc1976 You would have to do it in cmd line after, and use the old packages to install manually

                        Make sure to upvote

                        1 Reply Last reply Reply Quote 0
                        • J
                          JonathanLee @jc1976
                          last edited by Jan 12, 2024, 8:21 PM

                          @jc1976

                          https://forum.netgate.com/topic/185029/resolved-quest-for-older-package-wget

                          I would not use it but if you need it like me..

                          I did it with Snort to stop the core dumps

                          Just know that Netgate recommended it be removed.

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • L
                            lg1980 @JonathanLee
                            last edited by Jan 12, 2024, 8:24 PM

                            @JonathanLee said in Squid 6.5 !! Nov 6th:

                            result for use with arm processor

                            Oh man ! it still doesn't compile binaries for the ARM version, I don't have Netgate hardware here to test.

                            This is only to AMD64 version architeture.

                            1 Reply Last reply Reply Quote 0
                            • L
                              lg1980 @jc1976
                              last edited by Jan 12, 2024, 8:26 PM

                              @jc1976 said in Squid 6.5 !! Nov 6th:

                              ok, but if netgate removes it from the package manager and we have to manually install it, does that mean the gui portion of it will be removed and all configuring will need to be done via cli?

                              No, personally, and even to maintain pf2ad, I will maintain in a parallel repository (in this case it will be unofficial) Squid and all the tools, as well as the web interface (as it is), with the necessary updates for each package

                              1 Reply Last reply Reply Quote 1
                              • M
                                Michele Trotta
                                last edited by Jan 23, 2024, 3:45 PM

                                Hi Luiz,

                                I'm starting from a clean installation of pfsense 2.7.2 and running the command fetch -q -o - https://gitlab.labexposed.com/-/snippets/15/raw/main/repo-squid66.sh | sh

                                I installed the packages as shown in the image.

                                🔒 Log in to view

                                After configuring Squid and SquidGuard I have the following errors:

                                • in real time

                                🔒 Log in to view

                                -on the client

                                🔒 Log in to view

                                where the ip 172.17.78.81 is the proxy

                                Is there anything I can do ?

                                J 3 Replies Last reply Jan 24, 2024, 6:55 AM Reply Quote 0
                                • J
                                  JonathanLee @Michele Trotta
                                  last edited by Jan 24, 2024, 6:55 AM

                                  @Michele-Trotta interesting…. What does Squids official website say about that error?

                                  Make sure to upvote

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    Michele Trotta
                                    last edited by Jan 24, 2024, 7:19 AM

                                    Hi everyone, since version 2.7.1 pfsense Squid is deprecated and that's why all these strange errors occur.
                                    I was hoping for Luiz's patch. Before abandoning pfsense+squid I will do some more tests because it is an excellent solution.
                                    If you have other solutions to try let me know.
                                    Greetings
                                    Michele

                                    J 1 Reply Last reply Jan 24, 2024, 7:38 AM Reply Quote 0
                                    • J
                                      JonathanLee @Michele Trotta
                                      last edited by JonathanLee Jan 24, 2024, 7:43 AM Jan 24, 2024, 7:38 AM

                                      @Michele-Trotta hello everyone on this post is already aware. This post is for work arounds. Squid itself has many new security updates already available. I am sure you are aware. Thanks, this post is just the open source community coming together to help find ways to make it work. Solutions are needed and being tested in here with high hopes of bring the latest Squid version online for die hard users. Just some open source discussion at its finest. Seems it still has some bugs with that error you see above.

                                      Leading to Ecap over icap I wonder if that would improve security as it can work directly with DoH I am told.

                                      DoH is a big issue with dns based security….. it’s pure https based DNS you can’t force it and it’s reaction based when you block it, ever worse is QUIC. The latest Squid updates have QUIC protocol tools to detect and inspect. That’s https over udp, and it’s a big issue within dns based cyber security detection also. That’s why Squid can’t and won’t die. It’s because Squid has solutions for all the new protocols.

                                      We make solutions not problems.

                                      Make sure to upvote

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        JonathanLee @Michele Trotta
                                        last edited by Jan 24, 2024, 7:47 AM

                                        @Michele-Trotta Squid has custom options you can check them on there website, I wonder if something is automatically activated when the new version is installed…

                                        Make sure to upvote

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          JonathanLee @Michele Trotta
                                          last edited by Jan 24, 2024, 7:51 AM

                                          @Michele-Trotta check this out…

                                          🔒 Log in to view

                                          https://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit

                                          You might have a certificate issue

                                          Make sure to upvote

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.