On 14/03/2026 02:22, Andrey K wrote:
Hello, Amos,
Thank you for the comments.
I double-checked the results (I have squid-6.10).
The configurations:
ssl_bump *stare *step1
ssl_bump stare step2
ssl_bump bump step3
and
ssl_bump *peek *step1
ssl_bump stare step2
ssl_bump bump step3
produce the same result - during TLS handshake with the Server,
theProxyusesthe ciphersuite receivedfromthe originalClient.
Great. Thank you for the confirmation.
Bug in the "stare" case handling of SslBump2 protocol stage. Failure to
filter the ciphers etc. sent to the server down to the union set of what
client & squid are both capable of supporting.
At least for Squid v6.
I am not sure when/if anyone will be able to fix this.
Cheers
Amos
_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users