On 14/03/2026 02:22, Andrey K wrote:
Hello, Amos,

Thank you for the comments.
I double-checked the results (I have squid-6.10).

The configurations:
     ssl_bump *stare *step1
     ssl_bump stare step2
     ssl_bump bump step3
and
     ssl_bump *peek *step1
     ssl_bump stare step2
     ssl_bump bump step3
produce the same result - during TLS handshake with the Server, theProxyusesthe ciphersuite receivedfromthe originalClient.


Great. Thank you for the confirmation.

Bug in the "stare" case handling of SslBump2 protocol stage. Failure to filter the ciphers etc. sent to the server down to the union set of what client & squid are both capable of supporting.
  At least for Squid v6.

I am not sure when/if anyone will be able to fix this.

Cheers
Amos

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

Reply via email to