Re: [squid-users] Problem with ssl_choose_client_version:inappropriate fallback on some sites when using TLS1.2

2019-11-20 Thread John Sweet-Escott
Hi Tanner Unfortunately not. We have tried everything we can think of, plus suggested items from this list, with no success. If you figure it out let me know. Many thanks John Sent from my iPhone > On 20 Nov 2019, at 21:34, tannmann wrote: > > Hey John, > > It looks like we have a very

Re: [squid-users] Problem with ssl_choose_client_version:inappropriate fallback on some sites when using TLS1.2

2019-11-20 Thread tannmann
Hey John, It looks like we have a very similar setup and configuration as you, and we are experiencing the same problem. Have you been able to figure out a way to get connections to google to work with Squid 4.8 as a transparent proxy? Thanks, Tanner -- Sent from: http://squid-web-proxy-cach

Re: [squid-users] Changing the time format for access_log

2019-11-20 Thread James Moe
On 2019-11-19 10:12 PM, Amos Jeffries wrote: > IIRC, modern > Squids support a natural position for such parameters -- after the > %code. Here is an untested example: > > %tl{%Y-%m-%dT%H:%M:%S} > Thank you. That works quite nicely. -- James Moe moe dot james at sohnen-moe dot com 520.743.3936

Re: [squid-users] squid 4.1 transparent https issue "curl: (60) SSL certificate problem: self signed certificate in certificate chain"

2019-11-20 Thread Alex Rousskov
On 11/20/19 3:31 AM, Berger J Nicklas wrote: > squid 4.1 Start by upgrading to the latest Squid v4 available. > curl: (60) SSL certificate problem: self signed certificate in > certificate chain What was Squid trying to tell curl? Was Squid sending an error response? Tell curl to run --insecur

[squid-users] squid 4.1 transparent https issue "curl: (60) SSL certificate problem: self signed certificate in certificate chain"

2019-11-20 Thread Berger J Nicklas
Hello, I want to start saying I'm new working with squid so bear with me. We are at my company trying to use squid as egress solution for our servers running in AWS. We need to have a whitelisting function in place. HTTP works fine but not HTTPS. When trying to run curl from another server using