<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protect OWA using a reverse proxy</title>
	<atom:link href="http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.hongens.nl</link>
	<description>A systems administrator's diary</description>
	<lastBuildDate>Thu, 22 Jul 2010 01:48:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Kyle</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36927</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Wed, 10 Feb 2010 17:34:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36927</guid>
		<description>&lt;blockquote&gt;I figured out the record too long thing&lt;/blockquote&gt;

And the answer was......?</description>
		<content:encoded><![CDATA[<blockquote><p>I figured out the record too long thing</p></blockquote>
<p>And the answer was&#8230;&#8230;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arch Willingham</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36729</link>
		<dc:creator>Arch Willingham</dc:creator>
		<pubDate>Wed, 27 Jan 2010 10:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36729</guid>
		<description>Oh well....thanks anyway!
Arch</description>
		<content:encoded><![CDATA[<p>Oh well&#8230;.thanks anyway!<br />
Arch</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: angelo</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36721</link>
		<dc:creator>angelo</dc:creator>
		<pubDate>Tue, 26 Jan 2010 18:52:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36721</guid>
		<description>I don&#039;t use RPC over http, I only use OWA.. Can&#039;t help you with that, sorry.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t use RPC over http, I only use OWA.. Can&#8217;t help you with that, sorry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arch Willingham</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36718</link>
		<dc:creator>Arch Willingham</dc:creator>
		<pubDate>Tue, 26 Jan 2010 16:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36718</guid>
		<description>I figured out the record too long thing....now I&#039;m stuck with the certificate problems (or whatever ever is keeping them from talking). OWA works but Outlook HTTP/RPC flat will not work  How did you do your certificates?.

Arch</description>
		<content:encoded><![CDATA[<p>I figured out the record too long thing&#8230;.now I&#8217;m stuck with the certificate problems (or whatever ever is keeping them from talking). OWA works but Outlook HTTP/RPC flat will not work  How did you do your certificates?.</p>
<p>Arch</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: angelo</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36716</link>
		<dc:creator>angelo</dc:creator>
		<pubDate>Tue, 26 Jan 2010 14:35:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36716</guid>
		<description>don&#039;t know, try http://www.google.com/search?q=squid+ssl_error_rx_record_too_long</description>
		<content:encoded><![CDATA[<p>don&#8217;t know, try <a href="http://www.google.com/search?q=squid+ssl_error_rx_record_too_long" rel="nofollow">http://www.google.com/search?q=squid+ssl_error_rx_record_too_long</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arch Willingham</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-36701</link>
		<dc:creator>Arch Willingham</dc:creator>
		<pubDate>Tue, 26 Jan 2010 01:41:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-36701</guid>
		<description>I have tried this and I can&#039;t get it to work.  I get errors about 

An error occurred during a connection to owa.oursite.com.

SSL received a record that exceeded the maximum permissible length.

(Error code: ssl_error_rx_record_too_long)


Then the /var/log/httpd/error_log   shows these errors:

[Mon Jan 25 20:36:05 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01
[Mon Jan 25 20:36:05 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01
[Mon Jan 25 20:36:22 2010] [error] [client 68.186.192.18] Invalid method in request \x16\x03\x01
[Mon Jan 25 20:36:26 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01
[Mon Jan 25 20:36:26 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01

Any ideas?

Arch</description>
		<content:encoded><![CDATA[<p>I have tried this and I can&#8217;t get it to work.  I get errors about </p>
<p>An error occurred during a connection to owa.oursite.com.</p>
<p>SSL received a record that exceeded the maximum permissible length.</p>
<p>(Error code: ssl_error_rx_record_too_long)</p>
<p>Then the /var/log/httpd/error_log   shows these errors:</p>
<p>[Mon Jan 25 20:36:05 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01<br />
[Mon Jan 25 20:36:05 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01<br />
[Mon Jan 25 20:36:22 2010] [error] [client 68.186.192.18] Invalid method in request \x16\x03\x01<br />
[Mon Jan 25 20:36:26 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01<br />
[Mon Jan 25 20:36:26 2010] [error] [client 68.60.30.212] Invalid method in request \x16\x03\x01</p>
<p>Any ideas?</p>
<p>Arch</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frederick</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-35301</link>
		<dc:creator>Frederick</dc:creator>
		<pubDate>Thu, 19 Nov 2009 00:41:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-35301</guid>
		<description>Hey man thanks for the tutorial. 
Just wondering do you know of any ways of getting any better performance out of squid?  It seems pretty darn slow.

Any help with fine-tuning it&#039;s performance would be appreciated.

In the meantime I&#039;ll be RTFM&#039;ing</description>
		<content:encoded><![CDATA[<p>Hey man thanks for the tutorial.<br />
Just wondering do you know of any ways of getting any better performance out of squid?  It seems pretty darn slow.</p>
<p>Any help with fine-tuning it&#8217;s performance would be appreciated.</p>
<p>In the meantime I&#8217;ll be RTFM&#8217;ing</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-34956</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Mon, 26 Oct 2009 21:06:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-34956</guid>
		<description>Wow... After banging my head against a wall for hours, I finally realized why I was getting that error.  I will write it down here in hopes that it will help someone else.

I needed the &#039;sslflags=DONT_VERIFY_PEER&#039; because I used an IP instead of a FQDN in the cache_peer line.  (I changed &#039;cache_peer 10.10.10.10 parent...&#039; to &#039;cache_peer yoursite.yourdomain.com parent....&#039; (Where yoursite.yourdomain.com = the FQDN of the server you want to reverse proxy) and then added an entry for that site in my /etc/hosts file (with the real IP for the server I wanted to reverse proxy))  

Again, I hope that the above gets picked up by the search engines and saves someone else a bit of pain.</description>
		<content:encoded><![CDATA[<p>Wow&#8230; After banging my head against a wall for hours, I finally realized why I was getting that error.  I will write it down here in hopes that it will help someone else.</p>
<p>I needed the &#8216;sslflags=DONT_VERIFY_PEER&#8217; because I used an IP instead of a FQDN in the cache_peer line.  (I changed &#8216;cache_peer 10.10.10.10 parent&#8230;&#8217; to &#8216;cache_peer yoursite.yourdomain.com parent&#8230;.&#8217; (Where yoursite.yourdomain.com = the FQDN of the server you want to reverse proxy) and then added an entry for that site in my /etc/hosts file (with the real IP for the server I wanted to reverse proxy))  </p>
<p>Again, I hope that the above gets picked up by the search engines and saves someone else a bit of pain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-34955</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Mon, 26 Oct 2009 20:34:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-34955</guid>
		<description>Can you explain why you had to use &#039;sslflags=DONT_VERIFY_PEER&#039;  

I have a valid SSL cert on my exchange server but for some reason, squid doesn&#039;t like it.  (It threw a whole lot of errors (fwdNegotiateSSL: Error negotiating SSL connection on FD 17: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed)

I was eventually able to make it work by adding it to my squid.conf file too...  but I don&#039;t understand why I had to do it.  The cert is valid and my browser doesn&#039;t complain about it when I connect directly to OWA on the exchange server.  Thoughts?</description>
		<content:encoded><![CDATA[<p>Can you explain why you had to use &#8216;sslflags=DONT_VERIFY_PEER&#8217;  </p>
<p>I have a valid SSL cert on my exchange server but for some reason, squid doesn&#8217;t like it.  (It threw a whole lot of errors (fwdNegotiateSSL: Error negotiating SSL connection on FD 17: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed)</p>
<p>I was eventually able to make it work by adding it to my squid.conf file too&#8230;  but I don&#8217;t understand why I had to do it.  The cert is valid and my browser doesn&#8217;t complain about it when I connect directly to OWA on the exchange server.  Thoughts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: angelo</title>
		<link>http://blog.hongens.nl/guides/protect-owa-using-a-reverse-proxy/comment-page-1/#comment-32584</link>
		<dc:creator>angelo</dc:creator>
		<pubDate>Thu, 23 Jul 2009 11:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hongens.nl/?page_id=70#comment-32584</guid>
		<description>Lucas, the certificate you have installed on your exchange box does not have anything to do with squid, it&#039;s just for internal use.

The squid acts as a client to your exchange box, that&#039;s it.</description>
		<content:encoded><![CDATA[<p>Lucas, the certificate you have installed on your exchange box does not have anything to do with squid, it&#8217;s just for internal use.</p>
<p>The squid acts as a client to your exchange box, that&#8217;s it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
