Re: ssl bump
Vacheslav <[email protected]> Fri, 17 Jul 2026 08:16:41 +0300
| Newsgroups | gmane.comp.web.squid.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============6234517381994712150==
Content-Type: multipart/alternative;
boundary="------------Lx0TZ8Ga1BuhHIGiButvUJ00"
Content-Language: en-US, ru-RU
This is a multi-part message in MIME format.
--------------Lx0TZ8Ga1BuhHIGiButvUJ00
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
16.07.2026 16:36, Alex Rousskov пишет:
> On 2026-07-16 01:57, Vacheslav wrote:
>
>> 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>
> We need to figure out why your security_file_certgen helpers are
> exiting. IIRC, those helpers have not been upgraded to report their
> fatal failures to cache.log. There are a few tricks you can use to see
> what the problem is, but I would probably start with these three:
>
> 1. Run security_file_certgen with sslcrtd_program parameters from the
> command line, as Squid user. If you are lucky, it will complain about
> something before it starts waiting for the helper request.
so far i managed to do this: stop squid and
sudo -u squid /usr/libexec/squid/security_file_certgen -s
/var/cache/squid/ssl_db/certs -M 4MB
2026/07/17 08:15:13 sslcrtd_program| FATAL: Cannot generate
certificates: Uninitialized SSL certificate database directory:
/var/cache/squid/ssl_db/certs. To initialize, run "security_file_certgen
-c -s /var/cache/squid/ssl_db/certs".
exception location: certificate_db.cc(497) load
> 2. Redirect security_file_certgen stderr (but not stdout!) output into
> a dedicated log file. It may be possible to do that right on the
> sslcrtd_program line, without wrapping the helper into another script.
how to do that?
> 3. Enable full debugging, reproduce the problem with a single
> transaction, and send a link to the corresponding compressed cache.log
> file for analysis as detailed at
> https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction
>
God willing and we be living i'll try this later
> Cheers,
>
> Alex.
>
--------------Lx0TZ8Ga1BuhHIGiButvUJ00
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body text="#26a269" bgcolor="#000000">
<br>
<br>
<div class="moz-cite-prefix">16.07.2026 16:36, Alex Rousskov пишет:<br>
</div>
<blockquote type="cite"
cite="mid:[email protected]">On
2026-07-16 01:57, Vacheslav wrote:
<br>
<br>
<blockquote type="cite">2026/07/16 08:34:24 kid1| WARNING:
sslcrtd_program #Hlpr1 exited
<br>
</blockquote>
<br>
We need to figure out why your security_file_certgen helpers are
exiting. IIRC, those helpers have not been upgraded to report
their fatal failures to cache.log. There are a few tricks you can
use to see what the problem is, but I would probably start with
these three:
<br>
<br>
1. Run security_file_certgen with sslcrtd_program parameters from
the command line, as Squid user. If you are lucky, it will
complain about something before it starts waiting for the helper
request. <br>
</blockquote>
<br>
so far i managed to do this: stop squid and <br>
sudo -u squid /usr/libexec/squid/security_file_certgen -s
/var/cache/squid/ssl_db/certs -M 4MB<br>
2026/07/17 08:15:13 sslcrtd_program| FATAL: Cannot generate
certificates: Uninitialized SSL certificate database directory:
/var/cache/squid/ssl_db/certs. To initialize, run
"security_file_certgen -c -s /var/cache/squid/ssl_db/certs".<br>
exception location: certificate_db.cc(497) load<br>
<br>
<br>
<br>
<br>
<blockquote type="cite"
cite="mid:[email protected]">2.
Redirect security_file_certgen stderr (but not stdout!) output
into a dedicated log file. It may be possible to do that right on
the sslcrtd_program line, without wrapping the helper into another
script. <br>
</blockquote>
<br>
how to do that?<br>
<br>
<blockquote type="cite"
cite="mid:[email protected]">3.
Enable full debugging, reproduce the problem with a single
transaction, and send a link to the corresponding compressed
cache.log file for analysis as detailed at
<a class="moz-txt-link-freetext" href="https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction">https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction</a> <br>
</blockquote>
<br>
God willing and we be living i'll try this later<br>
<br>
<blockquote type="cite"
cite="mid:[email protected]">Cheers,
<br>
<br>
Alex.
<br>
<br>
</blockquote>
<br>
</body>
</html>
--------------Lx0TZ8Ga1BuhHIGiButvUJ00--
--===============6234517381994712150==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users
--===============6234517381994712150==--