Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
GMT+08:00 adam900710 : > Some extra clue: > > Cache log says: > -- > 2015/07/07 08:55:54 kid1| Accepting SSL bumped HTTP Socket connections > at local=[::]:3128 remote=[::] FD 23 flags=9 > 2015/07/07 08:55:55 kid1| storeLateRelease: released 0 objects > 2015/07/07 08:55:5

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
che_peer. http://squid-web-proxy-cache.1019090.n4.nabble.com/Behind-enemy-lines-squid-behind-proxy-td4668223.html If so, I think I'd better seek other solutions like use direct_allow with tsocks/proxychains... Thanks. 2015-07-07 8:54 GMT+08:00 adam900710 : > Tried your config in my environment

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
, don't do SSL Bump in NAT transparent interception > environment. > > 06.07.15 20:21, adam900710 пишет: >> 2015-07-06 22:05 GMT+08:00 Yuri Voinov : >>> >> My own solution in conjunction with Tor + Privoxy looks like this (Note: >> for Squid 3.4.13): >&g

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
te is not the fake one. (Issuer is not my fake one) So I consider the ssl-bump not working in that case. I'd like to reply when I set it up later to test. Thanks > sslproxy_capath /etc/opt/csw/ssl/certs > sslproxy_options NO_SSLv2 NO_SSLv3 > sslcrtd_program /usr/local/squid/libexec/ssl_crtd -s

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
> sslproxy_capath /etc/opt/csw/ssl/certs > sslproxy_options NO_SSLv2 NO_SSLv3 > sslcrtd_program /usr/local/squid/libexec/ssl_crtd -s /var/lib/ssl_db -M 4MB > > Generally, > > works like charm. > > 06.07.15 15:22, adam900710 пишет: > > Hi all, > > > > I tr

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
2015-07-06 20:06 GMT+08:00 Amos Jeffries : > On 6/07/2015 9:30 p.m., adam900710 wrote: >> >> Here is some of my experiments: >> 1) Remove "never_direct" >> Then ssl_bump works as expected, but all traffic doesn't goes through >> the SOCKS5 proxy

Re: [squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
#x27;--enable-ssl-crtd' '--disable-arch-native' '--disable-strict-error-checking' '--enable-wccpv2' 'CFLAGS=-march=x86-64 -mtune=generic -O2 -pipe -fstack-protector-strong --param=ssp-buffer-size=4' 'LDFLAGS=-Wl,-O1,--sort-common,--as-needed,-z,relro'

[squid-users] ssl_bump with cache_peer problem: Handshake fail after Client Hello.

2015-07-06 Thread adam900710
Hi all, I tried to build a ssl bumping proxy with up level proxy, but client failed to connect like the following. The error: --- $ curl https://www.google.co.jp - -k * Rebuilt URL to: https://www.google.co.jp/ * Trying ::1... * Connected to localhost (::1) port 3128 (#0) * Establish HTTP pro