Re: [squid-users] peek and splice with gnutls

2019-12-12 Thread Amos Jeffries
On 13/12/2019 08:27, Matus UHLAR - fantomas wrote: > Hello, > > are any of peek and splice (optionally stare) options available when squid > is compiled with gnutls? Unfortunately no. But to compensate we have made it so that if you compile using --with-openssl that will be the library used ev

Re: [squid-users] peek and splice with gnutls

2019-12-12 Thread Amos Jeffries
On 13/12/2019 08:27, Matus UHLAR - fantomas wrote: > Hello, > > are any of peek and splice (optionally stare) options available when squid > is compiled with gnutls? Unfortunately no. But to compensate we have made it so that if you compile using --with-openssl that will be the library used ev

[squid-users] peek and splice with gnutls

2019-12-12 Thread Matus UHLAR - fantomas
Hello, are any of peek and splice (optionally stare) options available when squid is compiled with gnutls? Thanks -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: [squid-users] Resolved: Peek-and-splice not working when mixing TLS1.3 servers and TLS1.2 clients

2019-12-12 Thread tannmann
I've also compiled from Nikolaus's branch and get the same results as John. It appears to fix the issues with inappropriate fallback, but I get the same "Error parsing SSL Server Hello Message on FD 15". Interestingly, I also get those errors when I compile from the branch suggested by Alex at ht

Re: [squid-users] Squid Proxy SSL Bump can not retrieve SSL session back to the client?

2019-12-12 Thread GeorgeShen
Right. that works now. thanks. - George -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Resolved: Peek-and-splice not working when mixing TLS1.3 servers and TLS1.2 clients

2019-12-12 Thread John
Hi Nikolaus I have taken your patch, applied it to squid http://http.debian.net/debian/pool/main/s/squid/squid_4.9-2.dsc, built it as a deb package and tested it. In use I am getting many errors of the form: 2019/12/12 16:50:19 kid1| Error parsing SSL Server Hello Message on FD 15 Turning on deb

Re: [squid-users] Squid Proxy SSL Bump can not retrieve SSL session back to the client?

2019-12-12 Thread Amos Jeffries
On 12/12/19 11:38 am, GeorgeShen wrote: > > did a 'openssl dhparam -out dhparams.pem 4096' to generate the dhparams.pem > file, and added those into the squid.conf: > > http_port 3129 ssl-bump cert=/usr/local/squid/etc/ssl_cert/myCA.pem > generate-host-certificates=on dynamic_cert_mem_cache_size=

Re: [squid-users] Sibling peer cache not working, ver 3.5.27

2019-12-12 Thread Matus UHLAR - fantomas
On 11.12.19 22:04, leonyuuu wrote: Thanks Amos for quick response! It helps a lot in understanding the previous logs like "forward proxy port not configured", and I adjusted my configuration later today to do another test. However, now the two proxies even doesn't send ICP/HTTP request to each o