[squid-users] SSL Bump missing facebook app traffic (resumed SSL sessions?)

2016-05-09 Thread Cohen-Rose, Adam
Hi there, We¹re running squid with SSL bump as a transparent proxy in order to control access to particular SSL sites. We¹ve noticed an issue with access to facebook from within the facebook app -- specifically it can get through the proxy even though it is *not* listed as a domain to splice. Acc

Re: [squid-users] SSL Bump matching Subject Alternative Names

2016-03-08 Thread Cohen-Rose, Adam
On 27/02/2016 01:54, "squid-users on behalf of Amos Jeffries" wrote: >On 27/02/2016 6:33 a.m., Cohen-Rose, Adam wrote: >> Amos, thanks so much for your help -- we're now seeing those requests >>get >> through when they were just being dropped before. >>

Re: [squid-users] SSL Bump matching Subject Alternative Names

2016-02-26 Thread Cohen-Rose, Adam
expect? All our cacheing is turned off -- we’re just using squid as access control. Thank you once again! Happy to help with more details of our config if required. Adam On 25/02/2016 22:18, "squid-users on behalf of Amos Jeffries" wrote: >On 26/02/2016 12:38 a.m., Cohen-Rose,

[squid-users] SSL Bump matching Subject Alternative Names

2016-02-25 Thread Cohen-Rose, Adam
We¹re trying to use SSL bump to splice traffic from a CDN (cdn.teads.tv) The CDN server certificate uses Subject Alternative Names in its certificate to identify the cdn.teads.tv domain rather than the Common Name (which is set to aka.proceau.net). Can we use SSL bump to splice requests to cdn.te