Re: [squid-users] problem with some ssl services

2015-06-21 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 In other words, Amos, the new version is almost never be able to perform a bump, I understand you correctly? And there is no full configuration that will work in the same way as 3.4? 21.06.15 18:40, Amos Jeffries пишет: > *some* issues that Squid

Re: [squid-users] problem with some ssl services

2015-06-21 Thread Harley Peters
On 06/18/2015 06:01 AM, HackXBack wrote: acl exclude_acl ssl::server_name .yahoo.com .gmail.com .googlemail.com s.yimg.com .yahooapis.com .akamaihd.net .fbcdn.net .facebook.com .google.com ssl_bump peek step1 all ssl_bump splice step2 exclude_acl ssl_bump stare step2 all ssl_bump bump step3 all s

Re: [squid-users] problem with some ssl services

2015-06-21 Thread Amos Jeffries
On 21/06/2015 11:55 p.m., HackXBack wrote: > for example the problem is in facebook app on iphone, > i need to trace the ip's then none ssl bump to this ip to make the facebook > app work, > now am using 3.5, you said that it can be make this automatically ? *some* issues that Squid detects as cl

Re: [squid-users] problem with some ssl services

2015-06-21 Thread HackXBack
for example the problem is in facebook app on iphone, i need to trace the ip's then none ssl bump to this ip to make the facebook app work, now am using 3.5, you said that it can be make this automatically ? but with which peak and splice conf ? need to give a try . Thanks amos -- View this mes

Re: [squid-users] problem with some ssl services

2015-06-18 Thread HackXBack
i upgrade to 3.5.5 and i use this conf always_direct allow all acl step1 at_step SslBump1 acl step2 at_step SslBump2 acl step3 at_step SslBump3 acl exclude_acl ssl::server_name .yahoo.com .gmail.com .googlemail.com s.yimg.com .yahooapis.com .akamaihd.net .fbcdn.net .facebook.com .google.com s

Re: [squid-users] problem with some ssl services

2015-06-17 Thread Amos Jeffries
On 17/06/2015 6:52 p.m., Jason Haar wrote: > On 15/06/15 11:58, Amos Jeffries wrote: >> Ensure that you are using the very latest Squid version to avoid >> problems with unsupported TLS mechanisms. The latest Squid will also >> automatically splice if its determined that the TLS connection cannot b

Re: [squid-users] problem with some ssl services

2015-06-16 Thread Jason Haar
On 15/06/15 11:58, Amos Jeffries wrote: > Ensure that you are using the very latest Squid version to avoid > problems with unsupported TLS mechanisms. The latest Squid will also > automatically splice if its determined that the TLS connection cannot be > bumped. Is that supposed to be in 3.5.5? I j

Re: [squid-users] problem with some ssl services

2015-06-15 Thread HackXBack
what peak and splice conf should i use to make it work fine ? am still using 3.4, i will upgrade to 3.5 -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/problem-with-some-ssl-services-tp4671733p4671736.html Sent from the Squid - Users mailing list archive at N

Re: [squid-users] problem with some ssl services

2015-06-14 Thread Amos Jeffries
On 15/06/2015 9:21 a.m., HackXBack wrote: > In some applications on mobiles, (ANDROID , APPLE) > there is problem with ssl connections from squid. > like GOOGLE PLAY app, facebook app, some games app, > the app will not open when i redirect traffic to squid , but when i make > torch on the traffic

[squid-users] problem with some ssl services

2015-06-14 Thread HackXBack
In some applications on mobiles, (ANDROID , APPLE) there is problem with ssl connections from squid. like GOOGLE PLAY app, facebook app, some games app, the app will not open when i redirect traffic to squid , but when i make torch on the traffic and i got the ip that are not passed, and then i put