Re: [squid-users] About SSL peek-n-splice/bump configurations

2018-09-13 Thread Julian Perconti
> > Example: > > > > ssl_bump splice noBumpSites # this will be totally ignored by Squid if a > stare rule precedes this. > > No, this is incorrect. There are many cases were a previous stare rule will > not > have the effect you state it will. For example: > > # Squid may splice at step2 de

Re: [squid-users] Long delays with TLS

2018-09-13 Thread Alex Rousskov
On 09/13/2018 01:00 PM, James Moe wrote: > Hello, > squid 4.0.23 > linux 4.12.14-lp150.12.7-default x86_64 > > We have been seeing frequent, but not consistent, delays when proxying > TLS requests while browsing. By disabling the proxy, those delays > stopped occurring. FYI: Your Squid is n

[squid-users] Long delays with TLS

2018-09-13 Thread James Moe
Hello, squid 4.0.23 linux 4.12.14-lp150.12.7-default x86_64 We have been seeing frequent, but not consistent, delays when proxying TLS requests while browsing. By disabling the proxy, those delays stopped occurring. I can see no obvious hint in either the access or cache logs. (Is there

Re: [squid-users] Squid Cache Server

2018-09-13 Thread Mujtaba Hassan Madani
Hi Amos, Iam looking for building a Squid proxy server on Ubuntu for my LAN serving up to 25 PC's I just want the maximum potential of the server capability to enhance the network performance and gain better users expectation of the service. regards Mujtaba H, __

Re: [squid-users] Unable to Disable sslv3

2018-09-13 Thread Amos Jeffries
On 14/09/18 3:35 AM, Alex Rousskov wrote: > On 09/12/2018 10:27 PM, Amos Jeffries wrote: > >> OpenSSL options to disable SSLv3 were not added until Squid-3.2 when >> TLS-only support was added. > > What makes you think that? AFAICT, support for disabling SSLv3 on > https_port was added years befo

Re: [squid-users] Unable to Disable sslv3

2018-09-13 Thread Alex Rousskov
On 09/12/2018 10:27 PM, Amos Jeffries wrote: > OpenSSL options to disable SSLv3 were not added until Squid-3.2 when > TLS-only support was added. What makes you think that? AFAICT, support for disabling SSLv3 on https_port was added years before Squid v3.1 was branched: https://github.com/squid-c

Re: [squid-users] About SSL peek-n-splice/bump configurations

2018-09-13 Thread Alex Rousskov
On 09/12/2018 09:02 PM, Julian Perconti wrote: > ssl_bump peek step1 > ssl_bump peek noBumpSites > ssl_bump stare all ssl_bump peek noBumpSites # As there no step specified, squid match at any step >> Not exactly. Squid will evaluate this rule at any step that (a) reaches >> this line