ssl bump

Vacheslav <[email protected]> Tue, 14 Jul 2026 08:06:06 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============3205112299040600176==
Content-Type: multipart/alternative;
 boundary="------------CaHL6vOMOutYbu0V56yJqMoS"
Content-Language: en-US, ru-RU

This is a multi-part message in MIME format.
--------------CaHL6vOMOutYbu0V56yJqMoS
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Peace, my squid certificate has expired, so i regenerated a new one and 
tried to enable ssl bump without success.

here is the configuration:

http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem 
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB

acl     tls_s1_connect            at_step SslBump1
acl     tls_s2_client_hello     at_step SslBump2
acl     tls_s3_server_hello     at_step SslBump3

# define acls for sites that must not be actively bumped

acl     tls_allowed_hsts        ssl::server_name  .akamaihd.net
acl     tls_allowed_hsts        ssl::server_name  .proxy.skko.by
acl     tls_server_is_bank         ssl::server_name 
"/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"
acl     tls_to_splice             any-of  tls_allowed_hsts        
tls_server_is_bank

# TLS/SSL bumping steps

ssl_bump         peek                tls_s1_connect         # peek at 
TLS/SSL connect data
ssl_bump         splice                 tls_to_splice        # splice 
some: no active bump
ssl_bump         stare                 all                    # 
stare(peek) at server
                                                         # properties of 
the webserver
ssl_bump         bump                                    # bump if we 
can (if the stare succeeded)

ssl_bump peek tls_s1_connect
ssl_bump splice all


#ssl_bump peek all
####ssl_bump splice all


sslcrtd_program /usr/libexec/squid/security_file_certgen -s 
/var/cache/squid/ssl_db -M 4M
sslcrtd_children 5

ssl_bump server-first all

sslproxy_cert_error allow all

that produces in cache.log:

Logfile: opening log daemon:/var/log/squid/access.log
2026/07/14 07:37:45 kid1| Logfile Daemon: opening log 
/var/log/squid/access.log
2026/07/14 07:37:45 kid1| Unlinkd pipe opened on FD 39
2026/07/14 07:37:45 kid1| Local cache digest enabled; rebuild/rewrite 
every 3600/3600 sec
2026/07/14 07:37:45 kid1| Store logging disabled
2026/07/14 07:37:45 kid1| Swap maxSize 3072000 + 983040 KB, estimated 
311926 objects
2026/07/14 07:37:45 kid1| Target number of buckets: 15596
2026/07/14 07:37:45 kid1| Using 16384 Store buckets
2026/07/14 07:37:45 kid1| Max Mem  size: 983040 KB
2026/07/14 07:37:45 kid1| Max Swap size: 3072000 KB
2026/07/14 07:37:45 kid1| Rebuilding storage in /var/cache/squid (clean log)
2026/07/14 07:37:45 kid1| Using Least Load store dir selection
2026/07/14 07:37:45 kid1| Set Current Directory to /var/cache/squid
2026/07/14 07:37:45 kid1| Finished loading MIME types and icons.
2026/07/14 07:37:45 kid1| HTCP Disabled.
2026/07/14 07:37:45 kid1| Pinger socket opened on FD 44
2026/07/14 07:37:45 kid1| Squid plugin modules loaded: 0
2026/07/14 07:37:45 kid1| Adaptation support is off.
2026/07/14 07:37:45 kid1| Accepting SSL bumped HTTP Socket connections 
at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9
     listening port: 8080
2026/07/14 07:37:45 pinger| WARNING: BCP 177 violation. Detected 
non-functional IPv6 loopback.
2026/07/14 07:37:45 pinger| Initialising ICMP pinger ...
2026/07/14 07:37:45 pinger| ICMP socket opened.
2026/07/14 07:37:45 pinger| ICMPv6 socket opened
2026/07/14 07:37:45 kid1| Indexing cache entries: 1.83% (4000 out of 218271)
2026/07/14 07:37:48 kid1| Done reading /var/cache/squid swaplog (218270 
entries)
2026/07/14 07:37:48 kid1| Finished rebuilding storage from disk.
      218270 Entries scanned
           0 Invalid entries
           0 With invalid flags
      218270 Objects loaded
           0 Objects expired
           0 Objects canceled
           0 Duplicate URLs purged
           0 Swapfile clashes avoided
     Took 3.01 seconds (72461.41 objects/sec).
2026/07/14 07:37:48 kid1| Beginning Validation Procedure
2026/07/14 07:37:48 kid1| Completed Validation Procedure
     Validated 218255 Entries
     store_swap_size = 2764788.00 KB
2026/07/14 07:37:49 kid1| storeLateRelease: released 0 objects
2026/07/14 07:37:49 kid1| WARNING: sslcrtd_program #Hlpr1 exited
2026/07/14 07:37:49 kid1| Too few sslcrtd_program processes are running 
(need 1/5)
     active processes: 4
     processes configured to start at (re)configuration: 5
2026/07/14 07:37:49 kid1| Closing HTTP(S) port 0.0.0.0:8080
     listening port: 8080
2026/07/14 07:37:49 kid1| storeDirWriteCleanLogs: Starting...
2026/07/14 07:37:49 kid1|     65536 entries written so far.
2026/07/14 07:37:49 kid1|    131072 entries written so far.
2026/07/14 07:37:49 kid1|    196608 entries written so far.
2026/07/14 07:37:49 kid1|   Finished.  Wrote 218270 entries.
2026/07/14 07:37:49 kid1|   Took 0.08 seconds (2835117.16 entries/sec).
2026/07/14 07:37:49 kid1| FATAL: The sslcrtd_program helpers are 
crashing too rapidly, need help!
2026/07/14 07:37:49 kid1| Squid Cache (Version 7.6): Terminated abnormally.
CPU Usage: 3.853 seconds = 2.203 user + 1.651 sys
Maximum Resident Size: 271744 KB
Page faults with physical i/o: 0
2026/07/14 07:37:49 kid1| Closing Pinger socket on FD 44
2026/07/14 07:37:49 kid1| WARNING: BCP 177 violation. Detected 
non-functional IPv6 loopback.
2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been enabled.
     acl name: to_localhost
     configuration context: Default Configuration(15) acl
2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been enabled.
     acl name: to_localhost
     configuration context: Default Configuration(15) acl
2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been enabled.
     acl name: to_linklocal
     configuration context: Default Configuration(16) acl
2026/07/14 07:37:49 kid1| Processing Configuration File: 
/etc/squid/squid.conf (depth 0)
2026/07/14 07:37:49 kid1| Set Current Directory to /var/cache/squid
2026/07/14 07:37:49 kid1| Starting Squid Cache version 7.6 for 
x86_64-suse-linux-gnu...
2026/07/14 07:37:49 kid1| Service Name: squid
2026/07/14 07:37:49 kid1| Process ID 54511
2026/07/14 07:37:49 kid1| Process Roles: worker
2026/07/14 07:37:49 kid1| With 4096 file descriptors available
2026/07/14 07:37:49 kid1| Initializing IP Cache...
2026/07/14 07:37:49 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
2026/07/14 07:37:49 kid1| Adding nameserver 10.86.0.26 from /etc/resolv.conf
2026/07/14 07:37:49 kid1| Adding nameserver 10.10.10.3 from /etc/resolv.conf
2026/07/14 07:37:49 kid1| helperOpenServers: Starting 5/5 
'security_file_certgen' processes
2026/07/14 07:37:49 kid1| helperOpenServers: Starting 8/16 'ufdbgclient' 
processes
2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate 
certificates: Unknown bytes unit: M
     exception location: security_file_certgen.cc(101) parseBytesUnits
2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate 
certificates: Unknown bytes unit: M
     exception location: security_file_certgen.cc(101) parseBytesUnits
2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate 
certificates: Unknown bytes unit: M
     exception location: security_file_certgen.cc(101) parseBytesUnits
2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate 
certificates: Unknown bytes unit: M
     exception location: security_file_certgen.cc(101) parseBytesUnits
2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate 
certificates: Unknown bytes unit: M
     exception location: security_file_certgen.cc(101) parseBytesUnits

running the command:

sudo /usr/libexec/squid/security_file_certgen -c -s 
/var/cache/squid/ssl_db/certs -M 4MB
Initialization SSL db...
2026/07/14 07:42:00 sslcrtd_program| FATAL: Cannot generate 
certificates: Cannot create /var/cache/squid/ssl_db/certs
     exception location: certificate_db.cc(374) Create

/var/cache/squid/ssl_db/certs certs is empty

how to solve the problem?
--------------CaHL6vOMOutYbu0V56yJqMoS
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body text="#26a269" bgcolor="#000000">
    Peace, my squid certificate has expired, so i regenerated a new one
    and tried to enable ssl bump without success.<br>
    <br>
    here is the configuration:<br>
    <br>
    http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem
    generate-host-certificates=on dynamic_cert_mem_cache_size=8MB<br>
    <br>
    acl     tls_s1_connect            at_step SslBump1<br>
    acl     tls_s2_client_hello     at_step SslBump2<br>
    acl     tls_s3_server_hello     at_step SslBump3<br>
    <br>
    # define acls for sites that must not be actively bumped<br>
    <br>
    acl     tls_allowed_hsts        ssl::server_name           
     .akamaihd.net<br>
    acl     tls_allowed_hsts        ssl::server_name           
     .proxy.skko.by<br>
    acl     tls_server_is_bank         ssl::server_name           
    "/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"<br>
    acl     tls_to_splice             any-of                       
     tls_allowed_hsts        tls_server_is_bank<br>
    <br>
    # TLS/SSL bumping steps<br>
    <br>
    ssl_bump         peek                tls_s1_connect         # peek
    at TLS/SSL connect data<br>
    ssl_bump         splice                 tls_to_splice        #
    splice some: no active bump<br>
    ssl_bump         stare                 all                    #
    stare(peek) at server<br>
                                                            # properties
    of the webserver<br>
    ssl_bump         bump                                    # bump if
    we can (if the stare succeeded)<br>
    <br>
    ssl_bump peek tls_s1_connect<br>
    ssl_bump splice all<br>
    <br>
    <br>
    #ssl_bump peek all<br>
    ####ssl_bump splice all<br>
    <br>
    <br>
    sslcrtd_program /usr/libexec/squid/security_file_certgen -s
    /var/cache/squid/ssl_db -M 4M<br>
    sslcrtd_children 5<br>
    <br>
    ssl_bump server-first all<br>
    <br>
    sslproxy_cert_error allow all<br>
    <br>
    that produces in cache.log:<br>
    <br>
    Logfile: opening log daemon:/var/log/squid/access.log<br>
    2026/07/14 07:37:45 kid1| Logfile Daemon: opening log
    /var/log/squid/access.log<br>
    2026/07/14 07:37:45 kid1| Unlinkd pipe opened on FD 39<br>
    2026/07/14 07:37:45 kid1| Local cache digest enabled;
    rebuild/rewrite every 3600/3600 sec<br>
    2026/07/14 07:37:45 kid1| Store logging disabled<br>
    2026/07/14 07:37:45 kid1| Swap maxSize 3072000 + 983040 KB,
    estimated 311926 objects<br>
    2026/07/14 07:37:45 kid1| Target number of buckets: 15596<br>
    2026/07/14 07:37:45 kid1| Using 16384 Store buckets<br>
    2026/07/14 07:37:45 kid1| Max Mem  size: 983040 KB<br>
    2026/07/14 07:37:45 kid1| Max Swap size: 3072000 KB<br>
    2026/07/14 07:37:45 kid1| Rebuilding storage in /var/cache/squid
    (clean log)<br>
    2026/07/14 07:37:45 kid1| Using Least Load store dir selection<br>
    2026/07/14 07:37:45 kid1| Set Current Directory to /var/cache/squid<br>
    2026/07/14 07:37:45 kid1| Finished loading MIME types and icons.<br>
    2026/07/14 07:37:45 kid1| HTCP Disabled.<br>
    2026/07/14 07:37:45 kid1| Pinger socket opened on FD 44<br>
    2026/07/14 07:37:45 kid1| Squid plugin modules loaded: 0<br>
    2026/07/14 07:37:45 kid1| Adaptation support is off.<br>
    2026/07/14 07:37:45 kid1| Accepting SSL bumped HTTP Socket
    connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9<br>
        listening port: 8080<br>
    2026/07/14 07:37:45 pinger| WARNING: BCP 177 violation. Detected
    non-functional IPv6 loopback.<br>
    2026/07/14 07:37:45 pinger| Initialising ICMP pinger ...<br>
    2026/07/14 07:37:45 pinger| ICMP socket opened.<br>
    2026/07/14 07:37:45 pinger| ICMPv6 socket opened<br>
    2026/07/14 07:37:45 kid1| Indexing cache entries: 1.83% (4000 out of
    218271)<br>
    2026/07/14 07:37:48 kid1| Done reading /var/cache/squid swaplog
    (218270 entries)<br>
    2026/07/14 07:37:48 kid1| Finished rebuilding storage from disk.<br>
         218270 Entries scanned<br>
              0 Invalid entries<br>
              0 With invalid flags<br>
         218270 Objects loaded<br>
              0 Objects expired<br>
              0 Objects canceled<br>
              0 Duplicate URLs purged<br>
              0 Swapfile clashes avoided<br>
        Took 3.01 seconds (72461.41 objects/sec).<br>
    2026/07/14 07:37:48 kid1| Beginning Validation Procedure<br>
    2026/07/14 07:37:48 kid1| Completed Validation Procedure<br>
        Validated 218255 Entries<br>
        store_swap_size = 2764788.00 KB<br>
    2026/07/14 07:37:49 kid1| storeLateRelease: released 0 objects<br>
    2026/07/14 07:37:49 kid1| WARNING: sslcrtd_program #Hlpr1 exited<br>
    2026/07/14 07:37:49 kid1| Too few sslcrtd_program processes are
    running (need 1/5)<br>
        active processes: 4<br>
        processes configured to start at (re)configuration: 5<br>
    2026/07/14 07:37:49 kid1| Closing HTTP(S) port 0.0.0.0:8080<br>
        listening port: 8080<br>
    2026/07/14 07:37:49 kid1| storeDirWriteCleanLogs: Starting...<br>
    2026/07/14 07:37:49 kid1|     65536 entries written so far.<br>
    2026/07/14 07:37:49 kid1|    131072 entries written so far.<br>
    2026/07/14 07:37:49 kid1|    196608 entries written so far.<br>
    2026/07/14 07:37:49 kid1|   Finished.  Wrote 218270 entries.<br>
    2026/07/14 07:37:49 kid1|   Took 0.08 seconds (2835117.16
    entries/sec).<br>
    2026/07/14 07:37:49 kid1| FATAL: The sslcrtd_program helpers are
    crashing too rapidly, need help!<br>
    2026/07/14 07:37:49 kid1| Squid Cache (Version 7.6): Terminated
    abnormally.<br>
    CPU Usage: 3.853 seconds = 2.203 user + 1.651 sys<br>
    Maximum Resident Size: 271744 KB<br>
    Page faults with physical i/o: 0<br>
    2026/07/14 07:37:49 kid1| Closing Pinger socket on FD 44<br>
    2026/07/14 07:37:49 kid1| WARNING: BCP 177 violation. Detected
    non-functional IPv6 loopback.<br>
    2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been
    enabled.<br>
        acl name: to_localhost<br>
        configuration context: Default Configuration(15) acl<br>
    2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been
    enabled.<br>
        acl name: to_localhost<br>
        configuration context: Default Configuration(15) acl<br>
    2026/07/14 07:37:49 kid1| aclIpParseIpData: IPv6 has not been
    enabled.<br>
        acl name: to_linklocal<br>
        configuration context: Default Configuration(16) acl<br>
    2026/07/14 07:37:49 kid1| Processing Configuration File:
    /etc/squid/squid.conf (depth 0)<br>
    2026/07/14 07:37:49 kid1| Set Current Directory to /var/cache/squid<br>
    2026/07/14 07:37:49 kid1| Starting Squid Cache version 7.6 for
    x86_64-suse-linux-gnu...<br>
    2026/07/14 07:37:49 kid1| Service Name: squid<br>
    2026/07/14 07:37:49 kid1| Process ID 54511<br>
    2026/07/14 07:37:49 kid1| Process Roles: worker<br>
    2026/07/14 07:37:49 kid1| With 4096 file descriptors available<br>
    2026/07/14 07:37:49 kid1| Initializing IP Cache...<br>
    2026/07/14 07:37:49 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7<br>
    2026/07/14 07:37:49 kid1| Adding nameserver 10.86.0.26 from
    /etc/resolv.conf<br>
    2026/07/14 07:37:49 kid1| Adding nameserver 10.10.10.3 from
    /etc/resolv.conf<br>
    2026/07/14 07:37:49 kid1| helperOpenServers: Starting 5/5
    'security_file_certgen' processes<br>
    2026/07/14 07:37:49 kid1| helperOpenServers: Starting 8/16
    'ufdbgclient' processes<br>
    2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate
    certificates: Unknown bytes unit: M<br>
        exception location: security_file_certgen.cc(101)
    parseBytesUnits<br>
    2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate
    certificates: Unknown bytes unit: M<br>
        exception location: security_file_certgen.cc(101)
    parseBytesUnits<br>
    2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate
    certificates: Unknown bytes unit: M<br>
        exception location: security_file_certgen.cc(101)
    parseBytesUnits<br>
    2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate
    certificates: Unknown bytes unit: M<br>
        exception location: security_file_certgen.cc(101)
    parseBytesUnits<br>
    2026/07/14 07:37:49 sslcrtd_program| FATAL: Cannot generate
    certificates: Unknown bytes unit: M<br>
        exception location: security_file_certgen.cc(101)
    parseBytesUnits<br>
    <br>
    running the command:<br>
    <br>
    sudo /usr/libexec/squid/security_file_certgen -c -s
    /var/cache/squid/ssl_db/certs -M 4MB<br>
    Initialization SSL db...<br>
    2026/07/14 07:42:00 sslcrtd_program| FATAL: Cannot generate
    certificates: Cannot create /var/cache/squid/ssl_db/certs<br>
        exception location: certificate_db.cc(374) Create<br>
    <br>
    /var/cache/squid/ssl_db/certs certs is empty<br>
    <br>
    how to solve the problem?
  </body>
</html>

--------------CaHL6vOMOutYbu0V56yJqMoS--

--===============3205112299040600176==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============3205112299040600176==--