<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><br>
</p>
<br>
<div class="moz-cite-prefix">03.03.2017 10:24, Adrian Miller пишет:<br>
</div>
<blockquote
cite="mid:CAOLOQx1v5Fd2-9RF2pnKwcAsJYKoyS67EseTB1mcoNsL_nEpOA@mail.gmail.com"
type="cite">
<div dir="ltr">Are you creating the database as root or the squid
user.....try as the squid user<br>
</div>
</blockquote>
It will not work when created as root. Will be permission denied.
crtd runs as squid, not as root.<br>
<blockquote
cite="mid:CAOLOQx1v5Fd2-9RF2pnKwcAsJYKoyS67EseTB1mcoNsL_nEpOA@mail.gmail.com"
type="cite">
<div class="gmail_extra"><br>
<div class="gmail_quote">On 3 March 2017 at 08:46, <span
dir="ltr"><<a moz-do-not-send="true"
href="mailto:squid-users-request@lists.squid-cache.org"
target="_blank">squid-users-request@lists.squid-cache.org</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">Send
squid-users mailing list submissions to<br>
<a moz-do-not-send="true"
href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.<wbr>org</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a moz-do-not-send="true"
href="http://lists.squid-cache.org/listinfo/squid-users"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>listinfo/squid-users</a><br>
or, via email, send a message with subject or body 'help' to<br>
<a moz-do-not-send="true"
href="mailto:squid-users-request@lists.squid-cache.org">squid-users-request@lists.<wbr>squid-cache.org</a><br>
<br>
You can reach the person managing the list at<br>
<a moz-do-not-send="true"
href="mailto:squid-users-owner@lists.squid-cache.org">squid-users-owner@lists.squid-<wbr>cache.org</a><br>
<br>
When replying, please edit your Subject line so it is more
specific<br>
than "Re: Contents of squid-users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. Re: squid 3.5.2==> HTTPS FATAL: The ssl_crtd
helpers are<br>
crashing too rapidly, need help! (Yuri Voinov)<br>
<br>
<br>
------------------------------<wbr>------------------------------<wbr>----------<br>
<br>
Message: 1<br>
Date: Fri, 3 Mar 2017 03:46:10 +0600<br>
From: Yuri Voinov <<a moz-do-not-send="true"
href="mailto:yvoinov@gmail.com">yvoinov@gmail.com</a>><br>
To: <a moz-do-not-send="true"
href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.<wbr>org</a><br>
Subject: Re: [squid-users] squid 3.5.2==> HTTPS FATAL:
The ssl_crtd<br>
helpers are crashing too rapidly, need help!<br>
Message-ID: <<a moz-do-not-send="true"
href="mailto:714528e5-a6d5-e72a-2bc7-9950a8eecb73@gmail.com">714528e5-a6d5-e72a-2bc7-<wbr>9950a8eecb73@gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
This problem, in principle, is common to all versions of
ssl-bumped<br>
Squid from version 3.4 and 5.0, inclusive, and occurs when
the stored<br>
certificate is damaged for any reason. The only thing
vorkeraund that I<br>
could find - a monitor kesh.log and initialize the
certificate database<br>
again with squid restart automatically.<br>
<br>
In some installations, this problem does not occur over the
years. In<br>
other - almost daily. I have no desire to find out why this
is happening<br>
exactly. For me it was easier to make the watchdog, which
will follow up<br>
on this.<br>
<br>
03.03.2017 3:40, Yuri Voinov пишет:<br>
><br>
> One hint finally:<br>
><br>
> '([^ ]*) helper database ([^ ]*) failed: The SSL
certificate database<br>
> ([^ ]*) is corrupted. Please rebuild' - - - 0 exec<br>
> "/usr/local/bin/crtd_create.sh -r >/dev/null
2>&1"<br>
> 'FATAL: ([^ ]*) helpers are crashing too rapidly, need
help!' - - -<br>
> 0 exec "/usr/local/bin/crtd_create.sh -r
>/dev/null 2>&1"<br>
> 'Cannot add certificate to db.' - - - 0 exec<br>
> "/usr/local/bin/crtd_create.sh -r >/dev/null
2>&1"<br>
><br>
> PS. This is from logsurfer.conf.<br>
><br>
><br>
> 03.03.2017 3:34, Yuri Voinov пишет:<br>
>><br>
>> This error is usually preceded by another error in
cache.log<br>
>> associated with the certificates.<br>
>><br>
>> I will show you the direction. Then go himself.<br>
>><br>
>> This software will useful for you to solve:<br>
>><br>
>> <a moz-do-not-send="true"
href="http://www.crypt.gen.nz/logsurfer/" rel="noreferrer"
target="_blank">http://www.crypt.gen.nz/<wbr>logsurfer/</a><br>
>><br>
>> HTH, Yuri<br>
>><br>
>><br>
>> 03.03.2017 2:47, --Ahmad-- пишет:<br>
>>> hey folks .<br>
>>> i have a problem with squid it get crashed
after i enabled https !<br>
>>> cache log error => FATAL: The ssl_crtd
helpers are crashing too<br>
>>> rapidly, need help!<br>
>>><br>
>>> i googled many topics and relevant pages and
couldnt find a<br>
>>> clear solution .<br>
>>><br>
>>> the quick solution i made was i removed the
certs in file :<br>
>>> *rm -rfv /var/lib/ssl_db/*<br>
>>> *<br>
>>> *<br>
>>> *then reinitiated the DB using cmd below :*<br>
>>> /lib/squid/ssl_crtd -c -s /var/lib/ssl_db<br>
>>> chown -R squid.squid /var/lib/ssl_db<br>
>>> chown-R squid.squid /var/lib/ssl_db<br>
>>><br>
>>> the restarted squid .<br>
>>><br>
>>> but this is not a solution becuase squid get
crashed again after<br>
>>> certain time and i don’t know why !<br>
>>> my version is 3.5.2<br>
>>><br>
>>> here is squid.conf :<br>
>>> /etc/squid/squid.conf<br>
>>> visible_hostname pcloud<br>
>>> acl ip1 myip 10.1.0.1<br>
>>> acl ip2 myip 192.168.10.210<br>
>>> tcp_outgoing_address 192.168.10.210 ip1<br>
>>> tcp_outgoing_address 192.168.10.210 ip2<br>
>>> #<br>
>>> # Recommended minimum configuration:<br>
>>> #<br>
>>><br>
>>> # Example rule allowing access from your local
networks.<br>
>>> # Adapt to list your (internal) IP networks
from where browsing<br>
>>> # should be allowed<br>
>>> acl localnet src <a moz-do-not-send="true"
href="http://10.0.0.0/8" rel="noreferrer" target="_blank">10.0.0.0/8</a>
# RFC1918 possible internal network<br>
>>> acl localnet src <a moz-do-not-send="true"
href="http://172.16.0.0/12" rel="noreferrer"
target="_blank">172.16.0.0/12</a> # RFC1918 possible
internal network<br>
>>> acl localnet src <a moz-do-not-send="true"
href="http://192.168.0.0/16" rel="noreferrer"
target="_blank">192.168.0.0/16</a> # RFC1918 possible
internal network<br>
>>> acl localnet src fc00::/7 # RFC 4193
local private network range<br>
>>> acl localnet src fe80::/10 # RFC 4291
link-local (directly<br>
>>> plugged) machines<br>
>>><br>
>>> acl SSL_ports port 443<br>
>>> acl Safe_ports port 80 # http<br>
>>> acl Safe_ports port 21 # ftp<br>
>>> acl Safe_ports port 443 # https<br>
>>> acl Safe_ports port 70 # gopher<br>
>>> acl Safe_ports port 210 # wais<br>
>>> acl Safe_ports port 1025-65535 # unregistered
ports<br>
>>> acl Safe_ports port 280 # http-mgmt<br>
>>> acl Safe_ports port 488 # gss-http<br>
>>> acl Safe_ports port 591 # filemaker<br>
>>> acl Safe_ports port 777 # multiling
http<br>
>>> acl CONNECT method CONNECT<br>
>>><br>
>>> #<br>
>>> # Recommended minimum Access Permission
configuration:<br>
>>> #<br>
>>> # Deny requests to certain unsafe ports<br>
>>> http_access deny !Safe_ports<br>
>>><br>
>>> # Deny CONNECT to other than secure SSL ports<br>
>>> http_access deny CONNECT !SSL_ports<br>
>>> http_access allow CONNECT<br>
>>> # Only allow cachemgr access from localhost<br>
>>> http_access allow localhost manager<br>
>>> http_access deny manager<br>
>>><br>
>>> # We strongly recommend the following be
uncommented to protect innocent<br>
<br>
>>> # web applications running on the proxy server
who think the only<br>
>>> # one who can access services on "localhost" is
a local user<br>
>>> #http_access deny to_localhost<br>
>>><br>
>>> #<br>
>>> # INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS
FROM YOUR CLIENTS<br>
>>> #<br>
>>><br>
>>> # Example rule allowing access from your local
networks.<br>
>>> # Adapt localnet in the ACL section to list
your (internal) IP networks<br>
>>> # from where browsing should be allowed<br>
>>> http_access allow localnet<br>
>>> http_access allow localhost<br>
>>><br>
>>> # And finally deny all other access to this
proxy<br>
>>> http_access deny all<br>
>>><br>
>>> # Squid normally listens to port 3128<br>
>>> http_port 3128<br>
>>><br>
>>> # Uncomment and adjust the following to add a
disk cache directory.<br>
>>> #cache_dir ufs /var/cache/squid 100 16 256<br>
>>><br>
>>> # Leave coredumps in the first cache dir<br>
>>> #coredump_dir /var/cache/squid<br>
>>><br>
>>> #<br>
>>> # Add any of your own refresh_pattern entries
above these.<br>
>>> #<br>
>>> #<br>
>>><br>
>>> http_port 3126<br>
>>> #http_port 3128<br>
>>> ##############################<wbr>#########<br>
>>> #cache_swap_low 90<br>
>>> #cache_swap_high 95<br>
>>> ############################<br>
>>> cache_effective_user squid<br>
>>> cache_effective_group squid<br>
>>> memory_replacement_policy lru<br>
>>> cache_replacement_policy heap LFUDA<br>
>>> ########################<br>
>>> maximum_object_size 10000 MB<br>
>>> #cache_mem 5000 MB<br>
>>> maximum_object_size_in_memory 10 MB<br>
>>> #########################<br>
>>> logfile_rotate 2<br>
>>> max_filedescriptors 131072<br>
>>> ##############################<wbr>#<br>
>>> ############<br>
>>> cache_dir aufs /var/cache/squid 600000 64 128<br>
>>> ##############################<wbr>#########<br>
>>> https_port 3129 intercept ssl-bump
generate-host-certificates=on<br>
>>> dynamic_cert_mem_cache_size=<wbr>4MB<br>
>>> cert=/usr/local/squid/ssl_<wbr>cert/myca.pem<br>
>>> key=/usr/local/squid/ssl_cert/<wbr>myca.pem<br>
>>> ssl_bump server-first all<br>
>>> sslcrtd_program /lib/squid/ssl_crtd -s
/var/lib/ssl_db -M 4MB<br>
>>> sslcrtd_children 1000 startup=1 idle=1<br>
>>> ###<br>
>>> minimum_object_size 0 bytes<br>
>>> #refresh patterns for caching static files<br>
>>> refresh_pattern ^ftp: 1440 20% 10080<br>
>>> refresh_pattern ^gopher: 1440 0% 1440<br>
>>> refresh_pattern -i .(gif|png|jpg|jpeg|ico)$
10080 90% 43200<br>
>>> override-expire ignore-no-cache ignore-no-store
ignore-private<br>
>>> refresh_pattern -i .(iso|avi|wav|mp3|mp4|mpeg|<wbr>swf|flv|x-flv)$
43200<br>
>>> 90% 432000 override-expire ignore-no-cache
ignore-no-store<br>
>>> ignore-private<br>
>>> refresh_pattern -i<br>
>>> .(deb|rpm|exe|zip|tar|tgz|ram|<wbr>rar|bin|ppt|doc|tiff)$
10080 90% 43200<br>
>>> override-expire ignore-no-cache ignore-no-store
ignore-private<br>
>>> refresh_pattern -i .index.(html|htm)$ 0 40%
10080<br>
>>> refresh_pattern -i .(html|htm|css|js)$ 1440 40%
40320<br>
>>> refresh_pattern . 0 40% 40320<br>
>>><br>
>>><br>
>>><br>
>>><br>
>>><br>
>>><br>
>>><br>
>>><br>
>>> any Joy Guys ?<br>
>>><br>
>>> should i update squid ? or downgrade squid ?<br>
>>><br>
>>> kind regards<br>
>>><br>
>>><br>
>>><br>
>>> ______________________________<wbr>_________________<br>
>>> squid-users mailing list<br>
>>> <a moz-do-not-send="true"
href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.<wbr>org</a><br>
>>> <a moz-do-not-send="true"
href="http://lists.squid-cache.org/listinfo/squid-users"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>listinfo/squid-users</a><br>
>><br>
>> --<br>
>> Bugs to the Future<br>
><br>
> --<br>
> Bugs to the Future<br>
<br>
--<br>
Bugs to the Future<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a moz-do-not-send="true"
href="http://lists.squid-cache.org/pipermail/squid-users/attachments/20170303/f5499462/attachment.html"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>pipermail/squid-users/<wbr>attachments/20170303/f5499462/<wbr>attachment.html</a>><br>
-------------- next part --------------<br>
A non-text attachment was scrubbed...<br>
Name: 0x613DEC46.asc<br>
Type: application/pgp-keys<br>
Size: 2437 bytes<br>
Desc: not available<br>
URL: <<a moz-do-not-send="true"
href="http://lists.squid-cache.org/pipermail/squid-users/attachments/20170303/f5499462/attachment.key"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>pipermail/squid-users/<wbr>attachments/20170303/f5499462/<wbr>attachment.key</a>><br>
-------------- next part --------------<br>
A non-text attachment was scrubbed...<br>
Name: signature.asc<br>
Type: application/pgp-signature<br>
Size: 473 bytes<br>
Desc: OpenPGP digital signature<br>
URL: <<a moz-do-not-send="true"
href="http://lists.squid-cache.org/pipermail/squid-users/attachments/20170303/f5499462/attachment.sig"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>pipermail/squid-users/<wbr>attachments/20170303/f5499462/<wbr>attachment.sig</a>><br>
<br>
------------------------------<br>
<br>
Subject: Digest Footer<br>
<br>
______________________________<wbr>_________________<br>
squid-users mailing list<br>
<a moz-do-not-send="true"
href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.<wbr>org</a><br>
<a moz-do-not-send="true"
href="http://lists.squid-cache.org/listinfo/squid-users"
rel="noreferrer" target="_blank">http://lists.squid-cache.org/<wbr>listinfo/squid-users</a><br>
<br>
<br>
------------------------------<br>
<br>
End of squid-users Digest, Vol 31, Issue 9<br>
******************************<wbr>************<br>
</blockquote>
</div>
<br>
<br clear="all">
<br>
-- <br>
<div class="gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr">I hate to advocate <span
style="color:rgb(255,153,0)"><b>drugs</b></span>, <span
style="color:rgb(255,153,0)"><b>alcohol</b></span>,<b> <span
style="color:rgb(255,153,0)">violence</span> </b><span
style="background-color:rgb(255,255,255)"><span
style="color:rgb(255,153,0)"></span></span>or <br>
<span style="color:rgb(255,153,0)"><b>insanity</b></span> to
anyone,<span style="color:rgb(255,153,0)"> <b>but</b></span>
they've <b><span style="color:rgb(255,153,0)">always</span></b>
worked for<b> <span style="color:rgb(255,153,0)">me</span></b><span
style="background-color:rgb(255,153,0)"></span><br>
<br>
- Hunter S. Thompson<br>
</div>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
squid-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a>
<a class="moz-txt-link-freetext" href="http://lists.squid-cache.org/listinfo/squid-users">http://lists.squid-cache.org/listinfo/squid-users</a>
</pre>
</blockquote>
<br>
<div class="moz-signature">-- <br>
Bugs to the Future</div>
</body>
</html>