ffischer
(usa Red Hat)
Enviado em 12/07/2012 - 14:29h
Fala pessoal boa tarde,
De uma semana pra cá temos enfrentado um problema com o nosso proxy, algumas mensagens de warning e erro vem aparecendo no nosso arquivo cache.log, conforme vou listar para vocês abaixo:
2012/07/12 14:17:50| WARNING: HTTP header contains NULL characters {Accept: */*
Content-Type: application/x-www-form-urlencoded}
NULL
{Accept: */*
E principalmente estas duas:
2012/07/12 13:49:28| AuthConfig::CreateAuthUser: Unsupported or unconfigured/inactive proxy-auth scheme, 'NTLM TlRMTVNTUAABAAAAB7IIogcABwAxAAAACQAJACgAAAAFASgKAAAAD1NPUFJPLTA0WElOTUVUUk8='
2012/07/12 14:13:37| assertion failed: AclProxyAuth.cc:229: "authenticateUserAuthenticated(Filled(checklist)->auth_user_request)"
Acontece que depois de receber esta última mensagem a aplicação "restarta" sozinha, segue abaixo o debug:
2012/07/12 14:13:40| Starting Squid Cache version 3.1.6 for x86_64-unknown-linux-gnu...
2012/07/12 14:13:40| Process ID 18583
2012/07/12 14:13:40| With 16384 file descriptors available
2012/07/12 14:13:40| Initializing IP Cache...
2012/07/12 14:13:40| DNS Socket created at [::], FD 7
2012/07/12 14:13:40| DNS Socket created at 0.0.0.0, FD 8
2012/07/12 14:13:40| Adding nameserver AD1 from squid.conf
2012/07/12 14:13:40| Adding nameserver AD2 from squid.conf
2012/07/12 14:13:40| helperOpenServers: Starting 400/400 'squid_ldap_auth' processes
2012/07/12 14:13:41| Unlinkd pipe opened on FD 813
2012/07/12 14:13:41| Store logging disabled
2012/07/12 14:13:41| Swap maxSize 51200000 + 2097152 KB, estimated 4099780 objects
2012/07/12 14:13:41| Target number of buckets: 204989
2012/07/12 14:13:41| Using 262144 Store buckets
2012/07/12 14:13:41| Max Mem size: 2097152 KB
2012/07/12 14:13:41| Max Swap size: 51200000 KB
2012/07/12 14:13:41| Version 1 of swap file without LFS support detected...
2012/07/12 14:13:41| Rebuilding storage in /mnt/cache/squid (DIRTY)
2012/07/12 14:13:41| Using Least Load store dir selection
2012/07/12 14:13:41| Set Current Directory to /var/cache/squid
2012/07/12 14:13:41| Loaded Icons.
2012/07/12 14:13:41| Accepting HTTP connections at [::]:3128, FD 816.
2012/07/12 14:13:41| HTCP Disabled.
2012/07/12 14:13:41| Squid modules loaded: 0
2012/07/12 14:13:41| Ready to serve requests.
2012/07/12 14:13:41| Store rebuilding is 0.02% complete
2012/07/12 14:15:43| Done reading /mnt/cache/squid swaplog (17191910 entries)
2012/07/12 14:15:43| Finished rebuilding storage from disk.
2012/07/12 14:15:43| 9625878 Entries scanned
2012/07/12 14:15:43| 0 Invalid entries.
2012/07/12 14:15:43| 0 With invalid flags.
2012/07/12 14:15:43| 2060000 Objects loaded.
2012/07/12 14:15:43| 0 Objects expired.
2012/07/12 14:15:43| 7565878 Objects cancelled.
2012/07/12 14:15:43| 0 Duplicate URLs purged.
2012/07/12 14:15:43| 0 Swapfile clashes avoided.
2012/07/12 14:15:43| Took 121.54 seconds (16949.11 objects/sec).
2012/07/12 14:15:43| Beginning Validation Procedure
2012/07/12 14:15:43| 262144 Entries Validated so far.
2012/07/12 14:15:43| 524288 Entries Validated so far.
2012/07/12 14:15:43| 786432 Entries Validated so far.
2012/07/12 14:15:43| 1835008 Entries Validated so far.
2012/07/12 14:15:44| 2097152 Entries Validated so far.
2012/07/12 14:15:44| 2359296 Entries Validated so far.
2012/07/12 14:15:44| 3145728 Entries Validated so far.
2012/07/12 14:15:44| 3407872 Entries Validated so far.
2012/07/12 14:15:44| 3932160 Entries Validated so far.
2012/07/12 14:15:44| Completed Validation Procedure
2012/07/12 14:15:44| Validated 4120019 Entries
2012/07/12 14:15:44| store_swap_size = 46265416
2012/07/12 14:15:44| storeLateRelease: released 0 objects
Já li algumas informações, que não são muitas que existe o bug 2305, e que este problema está sendo corrigdo na versão beta 3.2.
Meu número de processos filhos são 400, pois nesse proxy temos cerca de 1600 pessoas utilizando.
Uso Ubuntu 11 com 4 gb de memória
Abaixo a linhas do meu squid.conf referentes a autenticação ldap:
# Linha para autenticacao LDAP para dominio AD
auth_param basic program /usr/local/squid/libexec/squid_ldap_auth -R -b "dc=meudc,dc=local" -D "cn=meuusuarioad,cn=users,dc=meudc,dc=local" -w "minhasenhaad" -f sAMAccountName=%s -h IPdoAD
auth_param basic children 400
auth_param basic realm Autenticacao necessaria para utilizacao da Internet
auth_param basic credentialsttl 1 hours
Se alguem já passou por isto ou pode me dar alguma referencia pra resolver tal problema fico agradecido. Qualquer outra informação para me ajudar a resolver o problema basta me pedir.
Obrigado mais uma vez a todos
Fábio Fischer