[squid-users] squid 4.5, can't download certificate?

2019-01-16 Thread Dmitry Melekhov
Hello! While accessing site I can't access it through ssl bump. See in cache log: 2019/01/17 09:18:21 kid1| ERROR: negotiating TLS on FD 55: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (1/-1/0) In access log: 1547702300.945  0 192.168.22.229 NONE/

Re: [squid-users] ssl bump, CA certificate renewal, how to?

2019-01-16 Thread eliezer
+1 If the certificate is still working do the updates step by step and when you have successfully distributed the certificate make the switch. Eliezer Eliezer Croitoru Linux System Administrator Mobile: +972-5-28704261 Email: elie...@ngtech.co.il -Original Message- From: squid-us

Re: [squid-users] Squid 4.5 and intermediate CA

2019-01-16 Thread eliezer
There is no way to automatically add ROOT CA into browsers or software If a software does that it's only based on a pre-defined rules. At my page: http://ngtech.co.il/static/myCA/autoinstaller/ There are three examples and one of them is for linux (Ubuntu,Debian,CentOS). You can see the right

Re: [squid-users] Squid 4.5 and intermediate CA

2019-01-16 Thread FredB
Hi Amos, Yes it works, and I guess I found where the problem is, this is a pkix-cert mime type and I wonder, but maybe I'm wrong, that Squid can't use the file openssl x509 -inform DER -in myfile shows the CA as text file, after that I can use the CA file with browser unable to download CA (

Re: [squid-users] Squid 4.5 and intermediate CA

2019-01-16 Thread Amos Jeffries
On 16/01/19 8:30 pm, FredB wrote: > Yes it works, my first issue is now resolved > > There is a 200 when automatic download occurs, so this part is good > > Unfortunately still there is a code 503 at the third request, a specific > bump configuration is needed ?  > Have you double-checked that

Re: [squid-users] Squid 4.5 and intermediate CA

2019-01-16 Thread FredB
Yes it works, my first issue is now resolved There is a 200 when automatic download occurs, so this part is good Unfortunately still there is a code 503 at the third request, a specific bump configuration is needed ? - - - [15/Jan/2019:16:33:43 +0100] "GET http://cert.int-x3.letsencrypt.org/

Re: [squid-users] FTP inspection configuration

2019-01-16 Thread Amos Jeffries
On 16/01/19 3:10 pm, eugene.elyashev wrote: > Hello, > I'm trying to configure squid 3.5.6 as an FTP proxy for native FTP uploads > to be inspected by an ICAP service. Please try an upgrade, there have been a lot of fixes in the 3+ years since that release. Current production/stable release is v4.

Re: [squid-users] ssl bump, CA certificate renewal, how to?

2019-01-16 Thread Dmitry Melekhov
15.01.2019 21:33, Bruno de Paula Larini пишет: Em 15/01/2019 15:01, Dmitry Melekhov escreveu: 5 years, really, not very long period of time, if I'll be sure to not work here in 5 years then I'll use this ;-) , unfortunately I'm not :-( I don't need to replace certificate every year or so, bu