[squid-users] ssl_bump problem with tw.bid.yahoo.com in transparent proxy

2015-04-01 Thread Yu-Hsuan Liao
Hello Everyone, I got 'ssl_error_bad_cert_domain' message from browser when I was trying to bump tw.bid.yahoo.com in transparent mode I found that the certificate is signed to tw.otplogin.reg.yahoo.com, which should be signed to tw.bid.yahoo.com but for now I can't bypass using the following co

[squid-users] Skype bypass using ssl_bump peek

2014-12-17 Thread Yu-Hsuan Liao
> Only if "skype_list" matches the TCP packet IP address (without rDNS > being looked up) will the peek happen. > I think you need to add at_step ACL test to peek always at step1, then > do the other actions at step2 once SNI (domain name) is possibly > available. Hello Amos, What if a non-SSL o

[squid-users] Skype bypass using ssl_bump peek

2014-12-12 Thread Yu-Hsuan Liao
Hello everyone, I'm trying to using Squid 3.5's new feature peek-and-splice to bypass Skype connection I'm a little confused about ssl_bump steps, the wiki says that peek Receive client (step SslBump1) or server (step SslBump2) certificate while preserving the possibility of splicing the connecti