[squid-users] Domain fronting detection

2022-03-15 Thread Jason Spashett
Hello squid-users, I wonder if there is a set of workable acls at present that can detect and/or block domain fronting. By way of my understanding, that would be comparing the TLS SNI during a client connecting to squid and issuing a CONNECT method. Squid would bump that TLS request to also examin

Re: [squid-users] Openssl 3 compliance

2022-03-15 Thread Amos Jeffries
On 15/03/22 03:45, The Doctor wrote: I just read that opensssl 1.X will be end of life. When will Squid comply with both openssl 1.X and openssl 3.x? We have a PR with initial support that can be used if you really need it. FWIW, Ubuntu Jamm

Re: [squid-users] SQUID refuses to listen on any TCP Port

2022-03-15 Thread ben
Hi Eliezer, It worked! Now I can set my IPV6 input policy back to DROP.Anyway, this is my only ipv6-related firewall rules and anything else are defaults. Thank you! I have verified that the Pinger process is at fault. I don't know if it's a bug or not. You can disable pinger and it will wor