Re: [squid-users] Trusted first verification regarding cross root cert

2020-06-29 Thread mikio . kishi
Hi Amos, Thank you for your reply and I apologize for the missing information. The following is the detailed one. > * Squid version * squid version 3.5.26 (probably, ver4.X also might have same issue) * OpenSSL 1.0.2k > * details of the chain being delivered to Squid > * details of the expected

Re: [squid-users] Trusted first verification regarding cross root cert

2020-06-29 Thread Amos Jeffries
On 29/06/20 7:29 pm, mikio.kishi wrote: > Hi Amos, > > Thank you for your reply and I apologize for the missing information. > The following is the detailed one. > >> * Squid version > * squid version 3.5.26 (probably, ver4.X also might have same issue) > * OpenSSL 1.0.2k > >> * details of the c

Re: [squid-users] Trusted first verification regarding cross root cert

2020-06-29 Thread mikio . kishi
Hi Amos, >Ah. This is a feature of OpenSSL v1.1. Apparently your OpenSSL v1.0 has >had the feature *partially* backported to it. >I suggest you upgrade to Squid-4 and build against OpenSSL v1.1 where >this "feature" is the default behaviour. Yes, Exactly. However, currently I am using CentOS7 wh

Re: [squid-users] Trusted first verification regarding cross root cert

2020-06-29 Thread NgTech LTD
Upgrading to 1.1 on a running os is a challenge for any sysadmin. Eliezer On Mon, Jun 29, 2020, 13:30 wrote: > Hi Amos, > > >Ah. This is a feature of OpenSSL v1.1. Apparently your OpenSSL v1.0 has > >had the feature *partially* backported to it. > >I suggest you upgrade to Squid-4 and build aga

[squid-users] Squid 4.11 Howto create SSL Bump certificates with only 3-12 months date of expiry

2020-06-29 Thread info
Hi Squid Community, how can I configure Squid to create SSL Bump Certifications with only 3-12 months date of expiry? Currently, Squid SSL bumped Certifications are valid 20 years in my case, way too long, as Apple & Google & Mozilla will trust only <1 Year SSL certifications in the future. T

[squid-users] Squid 4.12 Arch Linux Google Chrome fails - OpenSSL 1.1.1g (was Re: SQUID 4.12 (Debian 10, OpenSSL 1.1.1d) - SSL bump no server helllo)

2020-06-29 Thread Amish
On 16/06/20 1:13 pm, Loučanský Lukáš wrote: But the client on the intercepted connection (via changed routing table under mikrotik and then prerouted to correct squid ports for http and ssl traffic) running Chrome 83 http://download.kjj.cz/pub/ssl/idnes.cz_chrome.83.0.4103.97.pcapng sends Cl

Re: [squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Eliezer Croitoru
Hey Vieri, This connections is being bumped and it’s based on a CONNECT connection to the proxy.I believe what you are looking for is at:https://wiki.squid-cache.org/ConfigExamples/Chat/Whatsapp Hope It Helps,Eliezer  Eliezer CroitoruTech SupportMobile: +972-5-28704261Email: ngtech1...@gmail.co

Re: [squid-users] Squid 4.12 Arch Linux Google Chrome fails - OpenSSL 1.1.1g

2020-06-29 Thread Alex Rousskov
On 6/29/20 11:18 AM, Amish wrote: > I am using Arch Linux and today I upgraded squid to 4.12 (from 4.10) > Firefox and IE work fine. But in Google chrome - sites dont open. You may need a fix for TLS GREASEd values. The following master/v6 PR has not been backported to v4 yet AFAICT, but it might

[squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Vieri
Hi, I'd like to allow whatsapp web through a transparent tproxy sslbump Squid setup. The target site is not loading: wss://web.whatsapp.com/ws I get TCP_MISS/400 305 GET https://web.whatsapp.com/ws in Squid cache log. I'm not sure I know how to use the on_unsupported_protocol diective. I have

Re: [squid-users] no response from the proxy squid parent

2020-06-29 Thread yannick . rousseau
Thanks a lot: it works fine now ! The line forwarded_for transparent was the solution. Thanks again. Yannick -- Envoi sécurisé avec Tutanota. Obtenez votre propre adresse email chiffrée : https://tutanota.com 27 juin 2020 à 11:49 de squ...@treenet.co.nz: > On 28/06/20 3:09 am, yannick.rou

Re: [squid-users] Squid 4.12 Arch Linux Google Chrome fails - OpenSSL 1.1.1g

2020-06-29 Thread Amish
On 30/06/20 1:22 am, Alex Rousskov wrote: On 6/29/20 11:18 AM, Amish wrote: I am using Arch Linux and today I upgraded squid to 4.12 (from 4.10) Firefox and IE work fine. But in Google chrome - sites dont open. You may need a fix for TLS GREASEd values. The following master/v6 PR has not been b

Re: [squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Vieri
On Monday, June 29, 2020, 6:41:41 PM GMT+2, Eliezer Croitoru wrote: > > > I believe what you are looking for is at: > https://wiki.squid-cache.org/ConfigExamples/Chat/Whatsapp   Thanks, but the article doesn't work for me. I still see Firefox complaining (console) about not being able to conne

Re: [squid-users] Squid 4 and on_unsupported_protocol

2020-06-29 Thread Eliezer Croitoru
I can try to re-produce this setup locally to make sure that it works as described in the docs.So couple details:PC Windows(What OS?) client with firefoxAre you Intercepting the traffic or using Squid as a simple forward proxy defined in the browser or OS proxy settings? Can you share a basic squid