HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.


All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: 10 Oct 2008 11:38 
Offline

Joined: 10 Oct 2008 11:27
Posts: 17
Hi,

I have a setup like this:
User/browser ==> Havp ==> Squid ==> Internet
It is compiled with --enable-ssl-tunnel --with-scanner=libclamav

I can access http & https websites just fine.

However, on connecting to certains https sides I have problems.
I use the brz (baraar source code versioning) to download sources from the internet.
When https://user:password@site.example.com/bzr/project/

bzr says: ERROR: Transport error: Server refuses to fullfil the request

And Havp says: Invalid request from browser

If I disable havp and go directly to squid, there is no problem.

Since havp should just tunnel https, has anyone an idea why it would give errors based on the https headers or content?

Thanks in advance,


Top
 Profile  
 
PostPosted: 10 Oct 2008 11:43 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
It maybe be some strange HTTPS requirement that HAVP doesn't know how to fullfill.

My advice is to not use HAVP to tunnel, it has drawbacks and no positives. Point your browser SSL to to Squid or don't proxy it.


Top
 Profile  
 
PostPosted: 10 Oct 2008 14:18 
Offline

Joined: 10 Oct 2008 11:27
Posts: 17
Hmm.
But I need to make that change transparent to my users, and don't have a way to push a proxypac either. Browsers are configured to connected to http://proxy.mydomain.com:80.

I could try doing the "squid sandwich" that is mentioned elsewhere in the forum:
User > Squid > Havp > Squid > Internet
but it does sound alot more complicated to manage..


Top
 Profile  
 
PostPosted: 10 Oct 2008 14:23 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Well, it might be slightly more complicated, but it allows a lot more flexibility regarding acls, forwarding etc.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group