Re: [squid-users] handshake problems with stare and bump

2016-10-05 Thread Marc
Hi, Thanks for the replies. I've figured out more details. First, my assumption that sslproxy_cipher was ignored in my setup was incorrect. I confused it with what I've read about sslproxy_options on http://bazaar.launchpad.net/~yadi/squid/warnings/revision/13928 . Thanks Yuri for making me come t

Re: [squid-users] handshake problems with stare and bump

2016-10-03 Thread Alex Rousskov
On 10/03/2016 11:50 AM, Marc wrote: > 2) Squid forwards the Client Hello, including ciphers the host running > squid doesn't support (in my case, the DES and RC4 ones). This could > also potentially lead to problems. Why doesn't squid filter them out > from the Client Hello sent from squid to the

Re: [squid-users] handshake problems with stare and bump

2016-10-03 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 http://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit#Hardening 03.10.2016 23:50, Marc пишет: > Hi, > > I've got an issue with squid stare and bump, hope someone can help! > > I'm staring and bumping everything, using transparent p

[squid-users] handshake problems with stare and bump

2016-10-03 Thread Marc
Hi, I've got an issue with squid stare and bump, hope someone can help! I'm staring and bumping everything, using transparent proxy on Fedora Core 24 using squid-3.5.20-1.fc24.x86_64 (see below for config). Now the client (iphone app) does TLS v1.0 and has the following ciphers in the Client Hell