Re: SSL Bump differences at various steps

Andrey K <[email protected]> Fri, 13 Mar 2026 16:22:35 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <CADJd0Y0ED67RhfT=EeDqDyJ=V7kMKr_6VHXwAbvL5fn4Pmdqdg@mail.gmail.com>
--===============4563680676750208533==
Content-Type: multipart/alternative; boundary="000000000000dfde9a064ce7c3fe"

--000000000000dfde9a064ce7c3fe
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello, Amos,

Thank you for the comments.
I double-checked the results (I have squid-6.10).

The configurations:
    ssl_bump *stare *step1
    ssl_bump stare step2
    ssl_bump bump step3
and
    ssl_bump *peek *step1
    ssl_bump stare step2
    ssl_bump bump step3
produce the same result -  during TLS handshake with the Server, the Proxy
uses the cipher suite received from the original Client.

While in the case of the configuration
    ssl_bump stare step1
    ssl_bump bump step2
    ssl_bump bump step3
, the Proxy uses its own cipher suite.

It doesn't bother me at all, but I can share a debug-log if it helps improv=
e
SQUID.
I think debug level 83,9:
debug_options ALL,1 83,9
will be enough?


Kind regards,
Ankor



=D0=B2=D1=82, 10 =D0=BC=D0=B0=D1=80. 2026=E2=80=AF=D0=B3. =D0=B2 11:41, Amo=
s Jeffries <[email protected]>:

> On 06/03/2026 22:35, Andrey K wrote:
> > Hello,
> >
> > Iwaswonderingwhatare the differencesif we apply the sslbump
> > operationatdifferentsteps?
> > The documentation contains information about only one difference - when
> > we bump at the step1 Proxy first establishes a TLS connection with the
> > Client, and then with the Server, while in the other cases - first with
> > the Server, and then with the Client.
> >
> > I looked into this issue and tried to summarize the information I have
> > (I will not detail here the information available to the admin at each
> > of the three steps). Maybe it will help someone.
> >
>
> Thank you.
>
> Though, for anyone reading this in the future - be aware that Squid
> behaviour which is _not_ documented officially is subject to change
> without notice.
>
> There are still bugs being found and removed from this feature. For
> example, see below...
>
>
> > Bumping at steps 2 and 3 are very similar,butinthe firstcase,
> > ProxysendsClientHelloto a Server withitsownciphers,andinthe lattercase =
-
> > withciphers receivedfromthe Client.
> >
> > If anyone has any comments or additions, please feel free to complete i=
t.
> >
>
> This looks like a bug to me. Squid should only be preserving the client
> ciphers etc when "peek" is used - in order to permit step2/3 splice.
>
> The explicit configuration of "stare" in your tests should be enabling
> Squid to filter the ciphers it sends to make your test #2 and #3
> identical traffic.
>
> What your test #2 is showing is what I would expect from the slightly
> weird configuration:
>    ssl_bump peek step1
>    ssl_bump stare step2
>    ssl_bump bump step3
>
> or just,
>    ssl_bump stare step2
>    ssl_bump bump step3
>
>
> Cheers
> Amos
>
> _______________________________________________
> squid-users mailing list
> [email protected]
> https://lists.squid-cache.org/listinfo/squid-users
>

--000000000000dfde9a064ce7c3fe
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello, Amos,<div><br></div><div>Thank=C2=A0you for the com=
ments.</div><div>I double-checked the results (I have squid-6.10).</div><di=
v><br></div><div>The configurations:</div><div><font face=3D"monospace">=C2=
=A0 =C2=A0 ssl_bump <b>stare </b>step1<br>=C2=A0 =C2=A0 ssl_bump stare step=
2<br>=C2=A0 =C2=A0 ssl_bump bump step3</font><br></div><div>and=C2=A0</div>=
<div><font face=3D"monospace">=C2=A0 =C2=A0 ssl_bump <b>peek </b>step1<br>=
=C2=A0 =C2=A0 ssl_bump stare step2<br>=C2=A0 =C2=A0 ssl_bump bump step3</fo=
nt></div><div>produce the same result -=C2=A0<span style=3D"white-space-col=
lapse: preserve;"> during TLS handshake with the Server, </span>the<span st=
yle=3D"white-space-collapse: preserve;"> P</span><span class=3D"gmail-YPkS7=
KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">roxy</span><span=
 style=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-YPk=
S7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">uses</span><sp=
an style=3D"white-space-collapse: preserve;"> the </span><span class=3D"gma=
il-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">cipher</=
span><span style=3D"white-space-collapse: preserve;"> suite </span><span cl=
ass=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;=
">received</span><span style=3D"white-space-collapse: preserve;"> </span><s=
pan class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: pre=
serve;">from</span><span style=3D"white-space-collapse: preserve;"> the </s=
pan><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collaps=
e: preserve;">original</span><span style=3D"white-space-collapse: preserve;=
"> C</span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-=
collapse: preserve;">lient</span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9"=
 style=3D"white-space-collapse: preserve;">.</span></div><div><span style=
=3D"white-space-collapse: preserve;"><br></span></div><div><span style=3D"w=
hite-space-collapse: preserve;">While in the case of the configuration</spa=
n></div><div><span style=3D"font-family:monospace">=C2=A0 =C2=A0 ssl_bump s=
tare step1</span><br style=3D"font-family:monospace"><span style=3D"font-fa=
mily:monospace">=C2=A0 =C2=A0 ssl_bump bump step2</span><br style=3D"font-f=
amily:monospace"><span style=3D"font-family:monospace">=C2=A0 =C2=A0 ssl_bu=
mp bump step3</span>=C2=A0=C2=A0<span style=3D"white-space-collapse: preser=
ve;"></span></div><div>, the Proxy uses its own=C2=A0<span class=3D"gmail-Y=
PkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">cipher</span=
><span style=3D"white-space-collapse: preserve;"> suite.</span></div><div><=
span style=3D"white-space-collapse: preserve;"><br></span></div><div><span =
class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserv=
e;">It</span><span style=3D"white-space-collapse: preserve;"> </span><span =
class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserv=
e;">doesn</span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-s=
pace-collapse: preserve;">&#39;t</span><span style=3D"white-space-collapse:=
 preserve;"> </span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"whi=
te-space-collapse: preserve;">bother</span><span style=3D"white-space-colla=
pse: preserve;"> </span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D=
"white-space-collapse: preserve;">me</span><span style=3D"white-space-colla=
pse: preserve;"> at all</span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" st=
yle=3D"white-space-collapse: preserve;">,</span><span style=3D"white-space-=
collapse: preserve;"> </span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" sty=
le=3D"white-space-collapse: preserve;">but</span><span style=3D"white-space=
-collapse: preserve;"> </span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" st=
yle=3D"white-space-collapse: preserve;">I</span><span style=3D"white-space-=
collapse: preserve;"> </span><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" sty=
le=3D"white-space-collapse: preserve;">can</span><span style=3D"white-space=
-collapse: preserve;"> share a </span><span class=3D"gmail-YPkS7KbdpWfGdYKd=
3QB9" style=3D"white-space-collapse: preserve;">debug-log </span><span styl=
e=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-YPkS7Kbd=
pWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">if</span><span styl=
e=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-YPkS7Kbd=
pWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">it</span><span styl=
e=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-YPkS7Kbd=
pWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">helps</span><span s=
tyle=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-YPkS7=
KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">improve</span><s=
pan style=3D"white-space-collapse: preserve;"> </span><span class=3D"gmail-=
YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: preserve;">SQUID</span=
><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse: =
preserve;">.</span><span style=3D"white-space-collapse: preserve;"></span><=
/div><div><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-c=
ollapse: preserve;">I think debug level 83,9:</span></div><div><font face=
=3D"monospace"><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-sp=
ace-collapse: preserve;">    debug_options ALL,1 </span><span style=3D"whit=
e-space-collapse: preserve;">83,9</span></font></div><div><span style=3D"wh=
ite-space-collapse: preserve;">will be enough?</span></div><div><br></div><=
div><span style=3D"white-space-collapse: preserve;"><br></span></div><div><=
span style=3D"white-space-collapse: preserve;">Kind regards,</span></div><d=
iv><span style=3D"white-space-collapse: preserve;">    Ankor</span></div><d=
iv><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB9" style=3D"white-space-collapse=
: preserve;"><br></span></div><div><span class=3D"gmail-YPkS7KbdpWfGdYKd3QB=
9" style=3D"white-space-collapse: preserve;"><br></span></div></div><br><di=
v class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gma=
il_attr">=D0=B2=D1=82, 10 =D0=BC=D0=B0=D1=80. 2026=E2=80=AF=D0=B3. =D0=B2 1=
1:41, Amos Jeffries &lt;<a href=3D"mailto:[email protected]">squid3@tree=
net.co.nz</a>&gt;:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e=
x">On 06/03/2026 22:35, Andrey K wrote:<br>
&gt; Hello,<br>
&gt; <br>
&gt; Iwaswonderingwhatare the differencesif we apply the sslbump <br>
&gt; operationatdifferentsteps?<br>
&gt; The documentation contains information about only one difference - whe=
n <br>
&gt; we bump at the step1 Proxy first establishes a TLS connection with the=
 <br>
&gt; Client, and then with the Server, while in the other cases - first wit=
h <br>
&gt; the Server, and then with the Client.<br>
&gt; <br>
&gt; I looked into this issue and tried to summarize the information I have=
 <br>
&gt; (I will not detail here the information available to the admin at each=
 <br>
&gt; of the three steps). Maybe it will help someone.<br>
&gt; <br>
<br>
Thank you.<br>
<br>
Though, for anyone reading this in the future - be aware that Squid <br>
behaviour which is _not_ documented officially is subject to change <br>
without notice.<br>
<br>
There are still bugs being found and removed from this feature. For <br>
example, see below...<br>
<br>
<br>
&gt; Bumping at steps 2 and 3 are very similar,butinthe firstcase, <br>
&gt; ProxysendsClientHelloto a Server withitsownciphers,andinthe lattercase=
 - <br>
&gt; withciphers receivedfromthe Client.<br>
&gt; <br>
&gt; If anyone has any comments or additions, please feel free to complete =
it.<br>
&gt; <br>
<br>
This looks like a bug to me. Squid should only be preserving the client <br=
>
ciphers etc when &quot;peek&quot; is used - in order to permit step2/3 spli=
ce.<br>
<br>
The explicit configuration of &quot;stare&quot; in your tests should be ena=
bling <br>
Squid to filter the ciphers it sends to make your test #2 and #3 <br>
identical traffic.<br>
<br>
What your test #2 is showing is what I would expect from the slightly <br>
weird configuration:<br>
=C2=A0 =C2=A0ssl_bump peek step1<br>
=C2=A0 =C2=A0ssl_bump stare step2<br>
=C2=A0 =C2=A0ssl_bump bump step3<br>
<br>
or just,<br>
=C2=A0 =C2=A0ssl_bump stare step2<br>
=C2=A0 =C2=A0ssl_bump bump step3<br>
<br>
<br>
Cheers<br>
Amos<br>
<br>
_______________________________________________<br>
squid-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">squi=
[email protected]</a><br>
<a href=3D"https://lists.squid-cache.org/listinfo/squid-users" rel=3D"noref=
errer" target=3D"_blank">https://lists.squid-cache.org/listinfo/squid-users=
</a><br>
</blockquote></div>

--000000000000dfde9a064ce7c3fe--

--===============4563680676750208533==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============4563680676750208533==--