Re: [squid-users] What's the best way to ban Let's encrypt based certificates? or whitelist a very narrow list of Root and Intermediates CA?

2019-01-22 Thread Eliezer Croitoru
OK so, Every Root CA have differ level of certification. For example there are Root CA's which are allowed to sign only for encryption ...and basic domain ownership validation which can be verified against a Domain Regristrar. Compared to this there are couple other level's of Certificates like w

Re: [squid-users] squid 4.5, can't download certificate?

2019-01-22 Thread Dmitry Melekhov
23.01.2019 8:53, Amos Jeffries пишет: On 23/01/19 5:40 pm, Dmitry Melekhov wrote: Thank you for explanation, it is easier for me to contact rejik developer and ask him to pass traffic if client address is "-" as he already did for fff...fff.  So, I'll inform him that such change is planned and

Re: [squid-users] squid 4.5, can't download certificate?

2019-01-22 Thread Amos Jeffries
On 23/01/19 5:40 pm, Dmitry Melekhov wrote: > > Thank you for explanation, it is easier for me to contact rejik > developer and ask him to pass traffic if client address is "-" as he > already did for > > fff...fff.  So, I'll inform him that such change is planned and he will > be ready :-) Um,

Re: [squid-users] squid 4.5, can't download certificate?

2019-01-22 Thread Dmitry Melekhov
22.01.2019 19:51, Alex Rousskov пишет: It sounds like you misunderstood my questions. I will detail them below. I suspect that fff...fff comes from %>A (whether that %code comes from the default url_rewrite_extras in your configuration is unimportant). %>A is documented to to be a client FQDN.

Re: [squid-users] using clang to compile squid 4-5

2019-01-22 Thread Amos Jeffries
On 23/01/19 5:17 am, Alex Rousskov wrote: > On 1/22/19 6:21 AM, graf huy wrote: > >> The Makefile is modified so each line with gcc is replaced with clang >> and each line of g++ replaced with clang++. But gcc is still used. > > I am not sure you are doing that, Seconded. With both my Squid Proj

Re: [squid-users] Squid 4.5 Transparent Proxy, StrongSwan VPN - Working in Browser but not in any android apps

2019-01-22 Thread Amos Jeffries
On 22/01/19 9:19 pm, XploD wrote: > > Can anybody tell me what I have to do so that every android app accepts > the intercepted connection? > IIRC there is also a phone CA certificate store where it can be added. Though I do not recall exactly where it is right now. Even with that setup some ap

Re: [squid-users] ICAP and 403 Encapsulated answers (SSL denied domains)

2019-01-22 Thread Alex Rousskov
On 1/22/19 1:22 AM, FredB wrote: > Here a short tcpdump trace > https://nas.traceroot.fr:8081/owncloud/index.php/s/egrcXnU3lxiU0mi > >   1 - I'm surfing to the website https://www.toto.fr Yes (tcp.stream eq 30). >   2 - I receive a 403 (blank page) > HTTP/1.1 403 Forbidden > Server: e2guardia

Re: [squid-users] using clang to compile squid 4-5

2019-01-22 Thread Alex Rousskov
On 1/22/19 6:21 AM, graf huy wrote: > The Makefile is modified so each line with gcc is replaced with clang > and each line of g++ replaced with clang++. But gcc is still used. I am not sure you are doing that, but, just in case, you should not be modifying Makefiles (or any other files generated

Re: [squid-users] squid 4.5, can't download certificate?

2019-01-22 Thread Alex Rousskov
On 1/21/19 10:52 PM, Dmitry Melekhov wrote: > 21.01.2019 22:29, Alex Rousskov пишет: Your Squid (or some helper) appears to be adding an "-/...GETmyip=-myport=0" suffix to the crt.sectigo.com URL, resulting in a 404 response from that server. >>> Is there any reasons squid sends

Re: [squid-users] TCP_TUNNEL and ecap

2019-01-22 Thread Alex Rousskov
On 1/21/19 10:47 PM, Michael Hendrie wrote: > I understand that in most cases adaptation of a tunnelled HTTPS > response is pointless as it would result message corruption but > wondering if it is at all possible to get the TCP_TUNNEL response > seen by ecap It would be possible (and, in some

[squid-users] using clang to compile squid 4-5

2019-01-22 Thread graf huy
Hi, The purpose is to compile squid to get HTTPS or SSL with bump support, on Debian 10 (Buster). After trying to compile squid-4-5  with clang (clang version 7.0.1-4 (tags/RELEASE_701/final)), it doesn't work. Target: x86_64-pc-linux-gnu Thread model: posix InstalledDir: /usr/bin Found candida

Re: [squid-users] https debug

2019-01-22 Thread Eliezer Croitoru
I didn't knew it's such a known repo. It's weird when someone in the street recognized me and identified me as the Squid-Cache RPM repo . Or in japanse " Hazukashī ". :D Eliezer Croitoru Linux System Administrator Mobile: +972-5-28704261 Email: elie...@ngtech.co.il -Original Message-

Re: [squid-users] ICAP and 403 Encapsulated answers (SSL denied domains)

2019-01-22 Thread FredB
Hello Alex But unfortunately Squid adds a "Connection: keep-alive" header It is not clear _why_ you consider that header "unfortunate" and the connection "wasted". That header may or may not be wrong, and the connection may or may not be reusable, depending on many factors (that you have not s

[squid-users] Squid 4.5 Transparent Proxy, StrongSwan VPN - Working in Browser but not in any android apps

2019-01-22 Thread XploD
Hi. I've got a strange problem, and I don't know if you can help me: To secure my mobile phone, I have set up a VPN using Strongswan which is used anytime I use an open WiFi hotspot. This works fine. But to get rid of all the trackers applied to websites and android apps, I want to use a p