Re: [squid-users] Ubuntu 18 LTS repository for Squid 4.4 (rebuilt with sslbump support from sources in Debian unstable)

2018-11-01 Thread Mark James
Debian seem to be unwilling to push squid4 through to stretch-backports. There is a libc change in testing that makes it difficult to get the one from testing or unstable without building your own. I have emailed their packaging team a couple of times. Given squid 3.5 is unsupported you would t

Re: [squid-users] URL Regex ACLs Don't Evaluate After Bumping

2018-11-01 Thread Alex Rousskov
On 11/1/18 2:46 PM, Shane Poage wrote: > I have my proxy configured to bump all traffic so that the > urlpath_regex ACL can be applied, but it appears to not have any > effect post-bump. Your proxy will deny any first post-bump request and close the tunnel because you deny all CONNECT requests th

Re: [squid-users] Ubuntu 18 LTS repository for Squid 4.4 (rebuilt with sslbump support from sources in Debian unstable)

2018-11-01 Thread Rafael Akchurin
Hello Jose, Latest Squid is already available in Debian unstable, no need to use Ubuntu recompilation. Best regards, Rafael Akchurin > Op 1 nov. 2018 om 21:08 heeft José J. Rodriguez > het volgende geschreven: > > Rafael Akchurin wrote: >> Greeting all, >> The online repository with latest S

[squid-users] URL Regex ACLs Don't Evaluate After Bumping

2018-11-01 Thread Shane Poage
Hello, I have a proxy configured to bump all traffic in order to do traffic filtering to a target server (Artifactory, in my case) from a particular environment. The proxy needs to be able to allow or permit traffic based on the path part of the URL in order to only allow access to a certain se

Re: [squid-users] Ubuntu 18 LTS repository for Squid 4.4 (rebuilt with sslbump support from sources in Debian unstable)

2018-11-01 Thread José J . Rodriguez
Rafael Akchurin wrote: Greeting all, The online repository with latest Squid 4.4 (rebuilt from Debian unstable with sslbump support) for Ubuntu 18 LTS 64-bit is available at squid44.diladele.com. Github repo at https://github.com/diladele/squid-ubuntu contains the scripts we used to make thi

Re: [squid-users] Squid 4.3: SSL Bump fails to send client certificate

2018-11-01 Thread Alex Rousskov
On 10/31/18 10:55 PM, Sid wrote: > Actually in my case Server is looking for a certificate to be sent by > client; How to configure Squid to get > this certificate from client for mutual authentication? It is technically impossible to meaningfully forward a client certificate to the origin server

Re: [squid-users] Squid 4.3: SSL Bump fails to send client certificate

2018-11-01 Thread Amos Jeffries
On 1/11/18 5:55 PM, Sid wrote: > Thank you Alex. > >> Sounds good. Does the generated fake certificate contain the right origin > server name? > Sid: Yes, It does contain correct IP Address in Server name sent by client. > Alex asked about *name*. IP address is not part of the considerations b