Re: [squid-users] LEGACY_SERVER_CONNECT, ALLOW_UNSAFE_LEGACY_RENEGOTIATION does not work - SSL bump, OpenSSL 3

2022-12-27 Thread Amish
Hi Alex, Thanks again for your reply. To find answers to your questions, I added few debugs() lines to PeerOptions.cc. The diff file (patch) is attached. It prints parsedOptions and options retrieved from SSL context and session objects at several stages. Here is tls_outgoing_options sett

Re: [squid-users] LEGACY_SERVER_CONNECT, ALLOW_UNSAFE_LEGACY_RENEGOTIATION does not work - SSL bump, OpenSSL 3

2022-12-27 Thread Alex Rousskov
On 12/27/22 10:42, Amish wrote: On 26/12/22 21:31, Alex Rousskov wrote: tls_outgoing_options options=0x4,0x4 With numeric hex values, I do not see the ERROR on stderr. But it still does not seem to be working as expected. Squid still does not open the page and gives same legacy negotia

Re: [squid-users] LEGACY_SERVER_CONNECT, ALLOW_UNSAFE_LEGACY_RENEGOTIATION does not work - SSL bump, OpenSSL 3

2022-12-27 Thread Amish
Hi Alex, Thank you for putting so much efforts in reply. Unfortunately, something is still wrong somewhere, as below. On 26/12/22 21:31, Alex Rousskov wrote: On 12/26/22 00:46, Amish wrote: I am using squid v5.7 with OpenSSL 3.0.7. (Arch Linux) squid.conf: # workaround for legacy / unpat