Re: [squid-users] Squid blocking own OCSP/AIA requests

2017-03-22 Thread Markus Wernig
y/download/5B257B96A465517EB839F3C078665EE83AE7F0EE: AIA for Root CA. Since squid is sslbumping the connection, it must be doing the AIA lookups (presumably for SSL verification). Does anybody have an idea why it is blocking its own requests? Best /markus On 03/21/2017 11:35 AM, Markus Wernig wrote: > Hi all > > I have conf

[squid-users] Squid blocking own OCSP/AIA requests

2017-03-21 Thread Markus Wernig
Hi all I have configured Squid 4.0.18 (CentOS) with sslbump and clamav as ecap_service. This works well. One thing I've noticed though, are constant log entries like this in access.log: 2017-03-21 10:35:08.338 +0100 000137 - TCP_DENIED/403 3607 GET http://apps.identrust.com/roots/dstrootcax3.p7c