squid with Java Problem - Idrac 6 Hp servers

classic Classic list List threaded Threaded
9 messages Options
Reply | Threaded
Open this post in threaded view
|

squid with Java Problem - Idrac 6 Hp servers

--Ahmad--
Hello Folks ,

i have a severs who run java and we need to access it from IDRAC console .

squid is 4.8 not able to get it work .
always i have error of java prompt , Unable to launch application .

if i use without proxy it work , if i use with squid it don’t work .

tried to add the directive below :

#####################
acl Java browser Java/1.4 Java/1.5 Java/1.6  Java/1.7  Java/1.8  Java/1.9
http_access allow Java
############################



Let me know Guys if there is a way to get it work or its not possible .

Thanks
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Matus UHLAR - fantomas
On 10.11.19 13:07, --Ahmad-- wrote:
>i have a severs who run java and we need to access it from IDRAC console .
>
>squid is 4.8 not able to get it work .
>always i have error of java prompt , Unable to launch application .
>
>if i use without proxy it work , if i use with squid it don’t work .

do you mean, if you configure proxy in java?
(java has own proxy settings)

If so, you should check squid logs first so see what requests have been
denied to your client IP.

probably your idrac console port is not alowed in squid, shouldbe
listed in ssl_ports probably.

--
Matus UHLAR - fantomas, [hidden email] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
"Two words: Windows survives." - Craig Mundie, Microsoft senior strategist
"So does syphillis. Good thing we have penicillin." - Matthew Alton
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Matus UHLAR - fantomas
In reply to this post by --Ahmad--
On 10.11.19 13:07, --Ahmad-- wrote:
tried to add the directive below :
>
>#####################
>acl Java browser Java/1.4 Java/1.5 Java/1.6  Java/1.7  Java/1.8  Java/1.9
>http_access allow Java
>############################

never do this, you will open your proxy to attacks where it could help
or you won't get any difference when it won't.

see my previous reply.

--
Matus UHLAR - fantomas, [hidden email] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Linux is like a teepee: no Windows, no Gates and an apache inside...
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

--Ahmad--
In reply to this post by Matus UHLAR - fantomas
Hi ,

i have HP server which access it over IDRAC https and need java support .

i have proxy in same lan .
proxy ip is 10.0.0.200
ip of Idrac is 10.0.0.70 


i can’t access Console of Idrac using squid , that’d what i need to do  .

i need to be ale to access server Console “ which need java” too .

so not sure if its possible or not .

again its over https so i believe its listed already in squid safe ports 

let me know your thoughts .

Kind regards 



On Nov 10, 2019, at 10:55 PM, Matus UHLAR - fantomas <[hidden email]> wrote:

listed in ssl_ports probably.


_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Matus UHLAR - fantomas
On 12.11.19 16:20, --Ahmad-- wrote:
>i have HP server which access it over IDRAC https and need java support .

you don't need java support. Apparently your java needs to be configured
with proxy. And maybe the proxy needs to allow access to idrac ports.
for that you must have rejection in proxy logs.

>i have proxy in same lan .
>proxy ip is 10.0.0.200
>ip of Idrac is 10.0.0.70
>
>
>i can’t access Console of Idrac using squid , that’d what i need to do  .
>
>i need to be ale to access server Console “ which need java” too .
>
>so not sure if its possible or not .
>
>again its over https so i believe its listed already in squid safe ports
>
>let me know your thoughts .
>
>Kind regards
>
>
>
>> On Nov 10, 2019, at 10:55 PM, Matus UHLAR - fantomas <[hidden email]> wrote:
>>
>> listed in ssl_ports probably.

--
Matus UHLAR - fantomas, [hidden email] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Fighting for peace is like fucking for virginity...
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

--Ahmad--
Hi Matus ,


Here is Log file squid , there is no Denied At all !

####################
1573682647.451      0 213.133.221.224 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1573682647.455      0 213.133.221.224 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1573682647.455      0 213.133.221.224 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1573682647.456      0 213.133.221.224 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1573682651.117    952 213.133.221.224 TCP_TUNNEL/200 2690 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682651.365   1200 213.133.221.224 TCP_TUNNEL/200 20663 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682651.414   1246 213.133.221.224 TCP_TUNNEL/200 11190 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682652.490   2935 213.133.221.224 TCP_TUNNEL/200 41968 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682657.175      0 213.133.221.224 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1573682661.827   8037 213.133.221.224 TCP_TUNNEL/200 63802 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682701.740  60994 213.133.221.224 TCP_TUNNEL/200 3680 CONNECT incoming.telemetry.mozilla.org:443 - HIER_DIRECT/52.35.171.123 -
1573682713.170  72358 213.133.221.224 TCP_TUNNEL/200 110961 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682714.170  62607 213.133.221.224 TCP_TUNNEL/200 1340 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -
1573682723.173  73017 213.133.221.224 TCP_TUNNEL/200 71908 CONNECT 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -

####################################



Here is Java Error log :

<?xml version="1.0" encoding="UTF-8"?>
<jnlp codebase="https://10.0.10.22:443" spec="1.0+">
<information>
  <title>iDRAC6 Virtual Console Client</title>
  <vendor>Dell Inc.</vendor>
   <icon href="https://10.0.10.22:443/images/logo.gif" kind="splash"/>
   <shortcut online="true"/>
 </information>
 <application-desc main-class="com.avocent.idrac.kvm.Main">
   <argument>ip=10.0.10.22</argument>
   <argument>vmprivilege=true</argument>
   <argument>title=idrac-20RDVR1%2C+PowerEdge+R610%2C+User%3Aroot</argument>
   <argument>user=35005211</argument>
   <argument>passwd=521595368</argument>
   <argument>kmport=5900</argument>
   <argument>vport=5900</argument>
   <argument>apcp=1</argument>
   <argument>version=2</argument>
 </application-desc>
 <security>
   <all-permissions/>
 </security>
 <resources>
   <j2se version="1.6+"/>
   <jar href="https://10.0.10.22:443/software/avctKVM.jar" download="eager" main="true" />
 </resources>
 <resources os="Windows" arch="x86">
   <nativelib href="https://10.0.10.22:443/software/avctKVMIOWin32.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMWin32.jar" download="eager"/>
 </resources>
 <resources os="Windows" arch="amd64">
   <nativelib href="https://10.0.10.22:443/software/avctKVMIOWin64.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMWin64.jar" download="eager"/>
 </resources>
 <resources os="Windows" arch="x86_64">
   <nativelib href="https://10.0.10.22:443/software/avctKVMIOWin64.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMWin64.jar" download="eager"/>
 </resources>
  <resources os="Linux" arch="x86">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux32.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux32.jar" download="eager"/>
  </resources>
  <resources os="Linux" arch="i386">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux32.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux32.jar" download="eager"/>
  </resources>
  <resources os="Linux" arch="i586">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux32.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux32.jar" download="eager"/>
  </resources>
  <resources os="Linux" arch="i686">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux32.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux32.jar" download="eager"/>
  </resources>
  <resources os="Linux" arch="amd64">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux64.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux64.jar" download="eager"/>
  </resources>
  <resources os="Linux" arch="x86_64">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOLinux64.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMLinux64.jar" download="eager"/>
  </resources>
  <resources os="Mac OS X" arch="x86_64">
    <nativelib href="https://10.0.10.22:443/software/avctKVMIOMac64.jar" download="eager"/>
   <nativelib href="https://10.0.10.22:443/software/avctVMMac64.jar" download="eager"/>
  </resources>
</jnlp>




java.net.ConnectException: Operation timed out (Connection timed out)
at java.net.PlainSocketImpl.socketConnect(Native Method)
at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:350)
at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:206)
at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:188)
at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
at java.net.Socket.connect(Socket.java:589)
at sun.security.ssl.SSLSocketImpl.connect(SSLSocketImpl.java:666)
at sun.security.ssl.BaseSSLSocketImpl.connect(BaseSSLSocketImpl.java:173)
at sun.net.NetworkClient.doConnect(NetworkClient.java:180)
at sun.net.www.http.HttpClient.openServer(HttpClient.java:463)
at sun.net.www.http.HttpClient.openServer(HttpClient.java:558)
at sun.net.www.protocol.https.HttpsClient.<init>(HttpsClient.java:264)
at sun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)
at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)
at sun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1156)
at sun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1040)
at sun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1038)
at java.security.AccessController.doPrivileged(Native Method)
at java.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)
at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1037)
at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)
at sun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1564)
at sun.net.www.protocol.http.HttpURLConnection.access$200(HttpURLConnection.java:91)
at sun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1484)
at sun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1482)
at java.security.AccessController.doPrivileged(Native Method)
at java.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)
at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1481)
at sun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:263)
at com.sun.deploy.net.HttpUtils.followRedirects(Unknown Source)
at com.sun.deploy.net.BasicHttpRequest.doRequest(Unknown Source)
at com.sun.deploy.net.BasicHttpRequest.doGetRequestEX(Unknown Source)
at com.sun.deploy.net.DownloadEngine.actionDownload(Unknown Source)
at com.sun.deploy.net.DownloadEngine.downloadResource(Unknown Source)
at com.sun.deploy.cache.ResourceProviderImpl.getResource(Unknown Source)
at com.sun.deploy.cache.ResourceProviderImpl.getResource(Unknown Source)
at com.sun.javaws.LaunchDownload$DownloadTask.call(Unknown Source)
at java.util.concurrent.FutureTask.run(FutureTask.java:266)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)




com.sun.deploy.net.FailedDownloadException: Unable to load resource: https://10.0.10.22:443/software/avctKVM.jar
at com.sun.deploy.net.DownloadEngine.actionDownload(Unknown Source)
at com.sun.deploy.net.DownloadEngine.downloadResource(Unknown Source)
at com.sun.deploy.cache.ResourceProviderImpl.getResource(Unknown Source)
at com.sun.deploy.cache.ResourceProviderImpl.getResource(Unknown Source)
at com.sun.javaws.LaunchDownload$DownloadTask.call(Unknown Source)
at java.util.concurrent.FutureTask.run(FutureTask.java:266)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)



On Nov 13, 2019, at 11:09 PM, Matus UHLAR - fantomas <[hidden email]> wrote:

On 12.11.19 16:20, --Ahmad-- wrote:
i have HP server which access it over IDRAC https and need java support .

you don't need java support. Apparently your java needs to be configured
with proxy. And maybe the proxy needs to allow access to idrac ports.
for that you must have rejection in proxy logs.

i have proxy in same lan .
proxy ip is 10.0.0.200
ip of Idrac is 10.0.0.70


i can’t access Console of Idrac using squid , that’d what i need to do  .

i need to be ale to access server Console “ which need java” too .

so not sure if its possible or not .

again its over https so i believe its listed already in squid safe ports

let me know your thoughts .

Kind regards



On Nov 10, 2019, at 10:55 PM, Matus UHLAR - fantomas <[hidden email]> wrote:

listed in ssl_ports probably.

-- 
Matus UHLAR - fantomas, [hidden email] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Fighting for peace is like fucking for virginity...
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users


_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Amos Jeffries
Administrator
On 14/11/19 6:09 pm, --Ahmad-- wrote:
> Hi Matus ,
>
>
> Here is Log file squid , there is no Denied At all !
>
> ####################
> 1573682647.451      0 213.133.221.224 NONE/000 0 NONE
> error:transaction-end-before-headers - HIER_NONE/- -

These are the client connecting, doing nothing. Then closing the connection.

No Squid problem visible. Whatever is going wrong is in the client
software. We see these a lot with "Happy Eyeballs" connections, so maybe
no problem at all there.


> 1573682651.117    952 213.133.221.224 TCP_TUNNEL/200 2690 CONNECT
> 10.0.10.22:443 - HIER_DIRECT/10.0.10.22 -

These are the client opening a tunnel to the origin server 10.0.10.22.
Which is successful and transfers some data around.

No Squid problem there either. Whatever is going wrong is in either the
client or server software - they are communicating directly with each
other over that tunnel.


> ####################################
>
>
>
> Here is Java Error log :
...
>
> java.net.ConnectException: Operation timed out (Connection timed out)
> at java.net.PlainSocketImpl.socketConnect(Native Method)

I suggest solving that problem. It does not seem related to Squid.


Amos
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Matus UHLAR - fantomas
>On 14/11/19 6:09 pm, --Ahmad-- wrote:
>> ####################################
>>
>>
>>
>> Here is Java Error log :
>...
>>
>> java.net.ConnectException: Operation timed out (Connection timed out)
>> at java.net.PlainSocketImpl.socketConnect(Native Method)

On 14.11.19 20:49, Amos Jeffries wrote:
>I suggest solving that problem. It does not seem related to Squid.

either the javaws does not have proxy set, or the iDrac6 HP
(are you sure it's idrac HP? idrac is the DELL And HP is not dell, HPs have
ILO) does not support proxy.

--
Matus UHLAR - fantomas, [hidden email] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
WinError #98652: Operation completed successfully.
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users
Reply | Threaded
Open this post in threaded view
|

Re: squid with Java Problem - Idrac 6 Hp servers

Amos Jeffries
Administrator
In reply to this post by --Ahmad--
On 19/11/19 4:58 pm, --Ahmad-- wrote:
> Hello Amos , Are you able to help me out ?
>

Apart from what Matus has already mentioned ...

* the Java traceback shows TCP socket setup is timing out.

* Squid access.log is showing those NONE transactions opening sockets
then timing out before any data arrives.

I would do a packet trace of the TCP the client software is sending to
Squid to find out what is happening to those TCP sockets.
 * Are they actually going to Squid or elsewhere?
 * Are the SYN+ACK packets getting back to the client software?

Amos
_______________________________________________
squid-users mailing list
[hidden email]
http://lists.squid-cache.org/listinfo/squid-users