Re: [squid-users] Best practices for beefing up security for squid with ssl-bump

2017-05-16 Thread Masha Lifshin
Dear Amos, Thank you for these insights. I appreciate the clarification on Ssl Sever Cert Validator, and am putting in place your list of basics. -Masha On Sat, May 13, 2017 at 5:36 AM, Amos Jeffries wrote: > On 13/05/17 14:33, Masha Lifshin wrote: > >> Dear Squid Users list, >> >> I have a S

Re: [squid-users] Best practices for beefing up security for squid with ssl-bump

2017-05-13 Thread Amos Jeffries
On 13/05/17 14:33, Masha Lifshin wrote: Dear Squid Users list, I have a Squid 4 configured as explicit proxy with ssl-bump interception. I am working on making it as secure as possible, given the vulnerability risks with doing ssl inspection (https://insights.sei.cmu.edu/cert/2015/03/the-ris

[squid-users] Best practices for beefing up security for squid with ssl-bump

2017-05-12 Thread Masha Lifshin
Dear Squid Users list, I have a Squid 4 configured as explicit proxy with ssl-bump interception. I am working on making it as secure as possible, given the vulnerability risks with doing ssl inspection ( https://insights.sei.cmu.edu/cert/2015/03/the-risks-of-ssl-inspection.html). I am implementin