Re: ssl bump
Vacheslav <[email protected]> Fri, 17 Jul 2026 08:31:36 +0300
| Newsgroups | gmane.comp.web.squid.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============4689450370939726985== Content-Type: multipart/alternative; boundary="------------vYql6I2SoVVfvLgxi0oQT6nr" Content-Language: en-US, ru-RU This is a multi-part message in MIME format. --------------vYql6I2SoVVfvLgxi0oQT6nr Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit 16.07.2026 18:19, Andrey K пишет: > @Vacheslav: > > sudo /usr/libexec/squid/security_file_certgen -c -s > > /var/cache/squid/ssl_db/certs -M 4MB > You specified the wrong path (the correct one is > /var/cache/squid/ssl_db ). good catch: now running: sudo -u squid /usr/libexec/squid/security_file_certgen -s /var/cache/squid/ssl_db -M 4MB ^C produces nothing. 2026/07/17 08:17:35| Removing PID file (/run/squid.pid) 2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback. 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled. acl name: to_localhost configuration context: Default Configuration(15) acl 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled. acl name: to_localhost configuration context: Default Configuration(15) acl 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled. acl name: to_linklocal configuration context: Default Configuration(16) acl 2026/07/17 08:18:54| Processing Configuration File: /etc/squid/squid.conf (depth 0) 2026/07/17 08:18:55| Created PID file (/run/squid.pid) 2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback. 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled. acl name: to_localhost configuration context: Default Configuration(15) acl 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled. acl name: to_localhost configuration context: Default Configuration(15) acl 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled. acl name: to_linklocal configuration context: Default Configuration(16) acl 2026/07/17 08:18:55 kid1| Processing Configuration File: /etc/squid/squid.conf (depth 0) 2026/07/17 08:18:55 kid1| Set Current Directory to /var/cache/squid 2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6 for x86_64-suse-linux-gnu... 2026/07/17 08:18:55 kid1| Service Name: squid 2026/07/17 08:18:55 kid1| Process ID 3685 2026/07/17 08:18:55 kid1| Process Roles: worker 2026/07/17 08:18:55 kid1| With 4096 file descriptors available 2026/07/17 08:18:55 kid1| Initializing IP Cache... 2026/07/17 08:18:55 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7 2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from /etc/resolv.conf 2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from /etc/resolv.conf 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5 'security_file_certgen' processes 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16 'ufdbgclient' processes 2026/07/17 08:18:55 kid1| Logfile: opening log daemon:/var/log/squid/access.log 2026/07/17 08:18:55 kid1| Logfile Daemon: opening log /var/log/squid/access.log 2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39 2026/07/17 08:18:56 kid1| Local cache digest enabled; rebuild/rewrite every 3600/3600 sec 2026/07/17 08:18:56 kid1| Store logging disabled 2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB, estimated 311926 objects 2026/07/17 08:18:56 kid1| Target number of buckets: 15596 2026/07/17 08:18:56 kid1| Using 16384 Store buckets 2026/07/17 08:18:56 kid1| Max Mem size: 983040 KB 2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB 2026/07/17 08:18:56 kid1| Rebuilding storage in /var/cache/squid (clean log) 2026/07/17 08:18:56 kid1| Using Least Load store dir selection 2026/07/17 08:18:56 kid1| Set Current Directory to /var/cache/squid 2026/07/17 08:18:56 kid1| Finished loading MIME types and icons. 2026/07/17 08:18:56 kid1| HTCP Disabled. 2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44 2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0 2026/07/17 08:18:56 kid1| Adaptation support is off. 2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9 listening port: 8080 2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback. 2026/07/17 08:18:56 pinger| Initialising ICMP pinger ... 2026/07/17 08:18:56 pinger| ICMP socket opened. 2026/07/17 08:18:56 pinger| ICMPv6 socket opened 2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84% (4000 out of 217945) 2026/07/17 08:18:59 kid1| Done reading /var/cache/squid swaplog (217944 entries) 2026/07/17 08:18:59 kid1| Finished rebuilding storage from disk. 217944 Entries scanned 0 Invalid entries 0 With invalid flags 217944 Objects loaded 0 Objects expired 0 Objects canceled 0 Duplicate URLs purged 0 Swapfile clashes avoided Took 2.85 seconds (76435.29 objects/sec). 2026/07/17 08:18:59 kid1| Beginning Validation Procedure 2026/07/17 08:18:59 kid1| Completed Validation Procedure Validated 217930 Entries store_swap_size = 2764788.00 KB 2026/07/17 08:18:59 kid1| storeLateRelease: released 0 objects 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master55 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master55 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master55 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master57 ........ 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS connection problem: failure error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1 current master transaction: master57 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited current master transaction: master57 2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes are running (need 1/5) active processes: 4 processes configured to start at (re)configuration: 5 current master transaction: master57 2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5 'security_file_certgen' processes current master transaction: master57 2026/07/17 08:21:33 kid1| Preparing for shutdown after 761 requests 2026/07/17 08:21:33 kid1| Waiting 30 seconds for active connections to finish 2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080 listening port: 8080 2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44 2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite: daemon:/var/log/squid/access.log: error writing ((32) Broken pipe) connection: conn2846 local=10.0.0.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs: Starting... connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| 65536 entries written so far. connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| 131072 entries written so far. connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| 196608 entries written so far. connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| Finished. Wrote 217944 entries. connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| Took 0.08 seconds (2736133.78 entries/sec). connection: conn2846 local=10.10.10.18:8080 remote=10.16.0.7:53255 flags=1 2026/07/17 08:21:33 kid1| FATAL: I don't handle this error well! connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6): Terminated abnormally. connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1 CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys Maximum Resident Size: 314320 KB Page faults with physical i/o: 0 > > To recreate a certificate database you should do: > > sudo rm -rf /var/cache/squid/ssl_db > sudo /usr/libexec/squid/security_file_certgen -c > -s /var/cache/squid/ssl_db -M 4MB > sudo chown -R squid:squid /var/cache/squid/ssl_db > > чт, 16 июл. 2026 г. в 16:36, Alex Rousskov > <[email protected]>: > > On 2026-07-16 01:57, Vacheslav wrote: > > > 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program #Hlpr1 exited > > We need to figure out why your security_file_certgen helpers are > exiting. IIRC, those helpers have not been upgraded to report their > fatal failures to cache.log. There are a few tricks you can use to > see > what the problem is, but I would probably start with these three: > > 1. Run security_file_certgen with sslcrtd_program parameters from the > command line, as Squid user. If you are lucky, it will complain about > something before it starts waiting for the helper request. > > 2. Redirect security_file_certgen stderr (but not stdout!) output > into a > dedicated log file. It may be possible to do that right on the > sslcrtd_program line, without wrapping the helper into another script. > > 3. Enable full debugging, reproduce the problem with a single > transaction, and send a link to the corresponding compressed > cache.log > file for analysis as detailed at > https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction > > > Cheers, > > Alex. > > _______________________________________________ > squid-users mailing list > [email protected] > https://lists.squid-cache.org/listinfo/squid-users > --------------vYql6I2SoVVfvLgxi0oQT6nr Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body text="#26a269" bgcolor="#000000"> <br> <br> <div class="moz-cite-prefix">16.07.2026 18:19, Andrey K пишет:<br> </div> <blockquote type="cite" cite="mid:CADJd0Y0BdfYdAH_T7DosdLFzg3LCbOi24nMvT8L2Lhb9ysgTmg@mail.gmail.com"> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <div dir="ltr">@Vacheslav: <div>> sudo /usr/libexec/squid/security_file_certgen -c -s </div> <div>> /var/cache/squid/ssl_db/certs -M 4MB </div> <div>You specified the wrong path (the correct one is /var/cache/squid/ssl_db ).</div> </div> </blockquote> <br> <br> good catch:<br> now running: <br> sudo -u squid /usr/libexec/squid/security_file_certgen -s /var/cache/squid/ssl_db -M 4MB<br> ^C<br> produces nothing.<br> <br> 2026/07/17 08:17:35| Removing PID file (/run/squid.pid)<br> 2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback.<br> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_localhost<br> configuration context: Default Configuration(15) acl<br> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_localhost<br> configuration context: Default Configuration(15) acl<br> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_linklocal<br> configuration context: Default Configuration(16) acl<br> 2026/07/17 08:18:54| Processing Configuration File: /etc/squid/squid.conf (depth 0)<br> 2026/07/17 08:18:55| Created PID file (/run/squid.pid)<br> 2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback.<br> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_localhost<br> configuration context: Default Configuration(15) acl<br> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_localhost<br> configuration context: Default Configuration(15) acl<br> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.<br> acl name: to_linklocal<br> configuration context: Default Configuration(16) acl<br> 2026/07/17 08:18:55 kid1| Processing Configuration File: /etc/squid/squid.conf (depth 0)<br> 2026/07/17 08:18:55 kid1| Set Current Directory to /var/cache/squid<br> 2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6 for x86_64-suse-linux-gnu...<br> 2026/07/17 08:18:55 kid1| Service Name: squid<br> 2026/07/17 08:18:55 kid1| Process ID 3685<br> 2026/07/17 08:18:55 kid1| Process Roles: worker<br> 2026/07/17 08:18:55 kid1| With 4096 file descriptors available<br> 2026/07/17 08:18:55 kid1| Initializing IP Cache...<br> 2026/07/17 08:18:55 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7<br> 2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from /etc/resolv.conf<br> 2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from /etc/resolv.conf<br> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5 'security_file_certgen' processes<br> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16 'ufdbgclient' processes<br> 2026/07/17 08:18:55 kid1| Logfile: opening log daemon:/var/log/squid/access.log<br> 2026/07/17 08:18:55 kid1| Logfile Daemon: opening log /var/log/squid/access.log<br> 2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39<br> 2026/07/17 08:18:56 kid1| Local cache digest enabled; rebuild/rewrite every 3600/3600 sec<br> 2026/07/17 08:18:56 kid1| Store logging disabled<br> 2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB, estimated 311926 objects<br> 2026/07/17 08:18:56 kid1| Target number of buckets: 15596<br> 2026/07/17 08:18:56 kid1| Using 16384 Store buckets<br> 2026/07/17 08:18:56 kid1| Max Mem size: 983040 KB<br> 2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB<br> 2026/07/17 08:18:56 kid1| Rebuilding storage in /var/cache/squid (clean log)<br> 2026/07/17 08:18:56 kid1| Using Least Load store dir selection<br> 2026/07/17 08:18:56 kid1| Set Current Directory to /var/cache/squid<br> 2026/07/17 08:18:56 kid1| Finished loading MIME types and icons.<br> 2026/07/17 08:18:56 kid1| HTCP Disabled.<br> 2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44<br> 2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0<br> 2026/07/17 08:18:56 kid1| Adaptation support is off.<br> 2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9<br> listening port: 8080<br> 2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation. Detected non-functional IPv6 loopback.<br> 2026/07/17 08:18:56 pinger| Initialising ICMP pinger ...<br> 2026/07/17 08:18:56 pinger| ICMP socket opened.<br> 2026/07/17 08:18:56 pinger| ICMPv6 socket opened<br> 2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84% (4000 out of 217945)<br> 2026/07/17 08:18:59 kid1| Done reading /var/cache/squid swaplog (217944 entries)<br> 2026/07/17 08:18:59 kid1| Finished rebuilding storage from disk.<br> 217944 Entries scanned<br> 0 Invalid entries<br> 0 With invalid flags<br> 217944 Objects loaded<br> 0 Objects expired<br> 0 Objects canceled<br> 0 Duplicate URLs purged<br> 0 Swapfile clashes avoided<br> Took 2.85 seconds (76435.29 objects/sec).<br> 2026/07/17 08:18:59 kid1| Beginning Validation Procedure<br> 2026/07/17 08:18:59 kid1| Completed Validation Procedure<br> Validated 217930 Entries<br> store_swap_size = 2764788.00 KB<br> 2026/07/17 08:18:59 kid1| storeLateRelease: released 0 objects<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master55<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master55<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master55<br> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master57<br> <br> ........<br> <br> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS connection<br> problem: failure<br> error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1<br> current master transaction: master57<br> 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited<br> current master transaction: master57<br> 2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes are running (need 1/5)<br> active processes: 4<br> processes configured to start at (re)configuration: 5<br> current master transaction: master57<br> 2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5 'security_file_certgen' processes<br> current master transaction: master57<br> 2026/07/17 08:21:33 kid1| Preparing for shutdown after 761 requests<br> 2026/07/17 08:21:33 kid1| Waiting 30 seconds for active connections to finish<br> 2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080<br> listening port: 8080<br> 2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44<br> 2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite: daemon:/var/log/squid/access.log: error writing ((32) Broken pipe)<br> connection: conn2846 local=10.0.0.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs: Starting...<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| 65536 entries written so far.<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| 131072 entries written so far.<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| 196608 entries written so far.<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| Finished. Wrote 217944 entries.<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| Took 0.08 seconds (2736133.78 entries/sec).<br> connection: conn2846 local=10.10.10.18:8080 remote=10.16.0.7:53255 flags=1<br> 2026/07/17 08:21:33 kid1| FATAL: I don't handle this error well!<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> 2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6): Terminated abnormally.<br> connection: conn2846 local=10.10.10.18:8080 remote=10.1.0.17:53255 flags=1<br> CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys<br> Maximum Resident Size: 314320 KB<br> Page faults with physical i/o: 0 <blockquote type="cite" cite="mid:CADJd0Y0BdfYdAH_T7DosdLFzg3LCbOi24nMvT8L2Lhb9ysgTmg@mail.gmail.com"> <div dir="ltr"> <div><br> </div> <div>To recreate a certificate database you should do: <div><br> </div> <div>sudo rm -rf <span style="background-color:transparent">/var/cache/squid/ssl_db</span></div> <div>sudo /usr/libexec/squid/security_file_certgen -c -s /var/cache/squid/ssl_db -M 4MB</div> <div>sudo chown -R squid:squid <span style="background-color:transparent">/var/cache/squid/ssl_db</span></div> </div> </div> <br> <div class="gmail_quote gmail_quote_container"> <div dir="ltr" class="gmail_attr">чт, 16 июл. 2026 г. в 16:36, Alex Rousskov <<a href="mailto:[email protected]" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>>:<br> </div> <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 2026-07-16 01:57, Vacheslav wrote:<br> <br> > 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program #Hlpr1 exited<br> <br> We need to figure out why your security_file_certgen helpers are <br> exiting. IIRC, those helpers have not been upgraded to report their <br> fatal failures to cache.log. There are a few tricks you can use to see <br> what the problem is, but I would probably start with these three:<br> <br> 1. Run security_file_certgen with sslcrtd_program parameters from the <br> command line, as Squid user. If you are lucky, it will complain about <br> something before it starts waiting for the helper request.<br> <br> 2. Redirect security_file_certgen stderr (but not stdout!) output into a <br> dedicated log file. It may be possible to do that right on the <br> sslcrtd_program line, without wrapping the helper into another script.<br> <br> 3. Enable full debugging, reproduce the problem with a single <br> transaction, and send a link to the corresponding compressed cache.log <br> file for analysis as detailed at <br> <a href="https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction" rel="noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction</a><br> <br> <br> Cheers,<br> <br> Alex.<br> <br> _______________________________________________<br> squid-users mailing list<br> <a href="mailto:[email protected]" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> <a href="https://lists.squid-cache.org/listinfo/squid-users" rel="noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.squid-cache.org/listinfo/squid-users</a><br> </blockquote> </div> </blockquote> <br> </body> </html> --------------vYql6I2SoVVfvLgxi0oQT6nr-- --===============4689450370939726985== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ squid-users mailing list [email protected] https://lists.squid-cache.org/listinfo/squid-users --===============4689450370939726985==--