Re: ssl bump

Vacheslav <[email protected]> Thu, 23 Jul 2026 08:22:48 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============4697690215031224580==
Content-Type: multipart/alternative;
 boundary="------------2SpC4Y0ZkYSPEfFo0hmLBAjI"
Content-Language: en-US, ru-RU

This is a multi-part message in MIME format.
--------------2SpC4Y0ZkYSPEfFo0hmLBAjI
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit



20.07.2026 20:15, Alex Rousskov пишет:
> On 2026-07-20 01:27, Vacheslav wrote:
>> 17.07.2026 15:44, Alex Rousskov пишет:
>>> On 2026-07-17 01:31, Vacheslav wrote:
>>>
>>>> 16.07.2026 18:19, Andrey K пишет:
>>>>> @Vacheslav:
>>>>> > sudo /usr/libexec/squid/security_file_certgen -c -s
>>>>> > /var/cache/squid/ssl_db/certs -M 4MB
>>>>> You specified the wrong path (the correct one is 
>>>>> /var/cache/squid/ssl_db ).
>>>>
>>>>
>>>> good catch:
>>>> now running:
>>>>   sudo -u squid /usr/libexec/squid/security_file_certgen -s 
>>>> /var/cache/squid/ssl_db -M 4MB
>>>> ^C
>>>> produces nothing.
>>>
>>> That lack of output is a good sign -- the helper managed to start 
>>> successfully.
>>>
>>>
>>>> 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>
>>> Helpers are still dying, but it looks like they do it while handling 
>>> traffic.
>>>
>>>
>>>>> 2. Redirect security_file_certgen stderr (but not stdout!) output
>>>>> into a dedicated log file. It may be possible to do that right on
>>>>> the sslcrtd_program line, without wrapping the helper into another
>>>>> script.
>>>
>>>> how to do that?
>>>
>>> Try using shell redirection when specifying how to run the helper. 
>>> Something along these lines may work:
>>>
>>>     sslcrtd_program /usr/local/... -M 4MB >> /tmp/sslcrtd.error.log
>
>
> My bad. I missed "2" to redirect stderr rather than stdout. Fixed 
> below. The missing file descriptor is _not_ the reason your test is 
> not working though (as detailed below).
>
>
>> now the configuration looks like this:
>>
>> sslcrtd_program /usr/libexec/squid/security_file_certgen -s 
>> /var/cache/squid/ssl_db -M 4MB >> /tmp/sslcrtd.error.log
>
>
> To capture stderr:
>
> sslcrtd_program /usr/libexec/squid/security_file_certgen -s
> /var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
>
>
>> in tmp there is no sslcrtd.error.log file.
>
>
> AFAICT, your Squid does not start sslcrtd_program helper. What does 
> "squid -v" say? If there is no '--enable-ssl-crtd' there, then you 
> need to rebuild your Squid executable from scratch. Also, at least one 
> http_port or https_port directive in your squid.conf should have both 
> "generate-host-certificates" and "ssl-bump" options.

sudo squid -v | grep "enable-ssl-crtd"
........'--enable-arp-acl' '--enable-ssl-crtd'.............

> When done right, you should see the debugging file created in /tmp/ 
> and, in cache log, Squid logging "Starting ..." lines mentioning your 
> helper (similar to your existing lines for the ufdbgclient helper).
here is the configuration with the 8080 sslbump port open:


forwarded_for delete

delay_pools 1
delay_class 1 3
delay_access 1 allow slower
delay_access 1 deny all
delay_parameters 1 128000/128000 -1/-1 128000/64000

http_access allow localnet
http_access allow localhost



# And finally deny all other access to this proxy
http_access deny all

# Squid normally listens to port 3128
#http_port 8080



http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem 
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB




##acl step1 at_step SslBump1
##ssl_bump peek step1
##ssl_bump bump all

##sslcrtd_program /usr/libexec/squid/security_file_certgen -s 
/var/lib/squid/ssl_db -M 4MB
##sslcrtd_children 5

acl     tls_s1_connect            at_step SslBump1
acl     tls_s2_client_hello     at_step SslBump2
acl     tls_s3_server_hello     at_step SslBump3

# define acls for sites that must not be actively bumped

acl     tls_allowed_hsts        ssl::server_name  .akamaihd.net
acl     tls_allowed_hsts        ssl::server_name  .proxy.skko.by
#acl     tls_server_is_bank         ssl::server_name  .abnamro.nl
#acl     tls_server_is_bank         ssl::server_name  .abnamro.com
acl     tls_server_is_bank         ssl::server_name 
"/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"
acl     tls_to_splice             any-of  tls_allowed_hsts        
tls_server_is_bank

# TLS/SSL bumping steps

ssl_bump         peek                tls_s1_connect         # peek at 
TLS/SSL connect data
ssl_bump         splice                 tls_to_splice        # splice 
some: no active bump
ssl_bump         stare                 all                    # 
stare(peek) at server
                                                         # properties of 
the webserver
ssl_bump         bump                                    # bump if we 
can (if the stare succeeded)

ssl_bump peek tls_s1_connect
ssl_bump splice all


#ssl_bump peek all
############ssl_bump splice all


sslcrtd_program /usr/libexec/squid/security_file_certgen -s 
/var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
sslcrtd_children 1 startup=1 idle=1

ssl_bump server-first all

sslproxy_cert_error allow all

#tls_outgoing_options options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE 
cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS

# Uncomment and adjust the following to add a disk cache directory.
# Updates: chrome and acrobat
#refresh_pattern -i gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf) 43200 80% 
129600 reload-into-ims
#refresh_pattern -i adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf) 43200 
80% 129600 reload-into-ims



#range_offset_limit 200 MB
#maximum_object_size 200 MB
#quick_abort_min -1

# DONT MODIFY THESE LINES
#refresh_pattern \^ftp:           1440    20%     10080
#refresh_pattern \^gopher:        1440    0%      1440
#refresh_pattern -i (/cgi-bin/|\?) 0      0%      0
#refresh_pattern .                   0      20%     43200

cache_dir ufs /var/cache/squid 3000 16 256

# Leave coredumps in the first cache dir
coredump_dir /var/cache/squid

cache_mem 960 MB

netdb_filename none

logformat squidx %err_code/%err_detail
#access_log daemon:/var/log/squid/accessX.log squidx
#access_log squidx

#
# Add any of your own refresh_pattern entries above these.
#
refresh_pattern ^ftp:                1440    20%    10080
refresh_pattern ^gopher:            1440    0%    1440
refresh_pattern -i (/cgi-bin/|\?)     0        0%    0
refresh_pattern .                    0        20%    4320

url_rewrite_extras "%>a/%>A %un %>rm bump_mode=%ssl::bump_mode 
sni=\"%ssl::>sni\" referer=\"%{Referer}>h\""
url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient -m 4 -l 
/var/log/squid/
url_rewrite_children 16 startup=8 idle=2 concurrency=4 queue-size=64
#debug_options ALL,1 33,2 28,9

> HTH,
>
> Alex. 

i finally noticed an empty sslcrtd.error.log file in /tmp created on 
20.07.2026, for some reason i was looking for a folder, stupid me.

i'm getting certificate errors when browsing sites in firefox. some 
sites provide a warning to proceed to site (dangerous) other sites just 
put 3 tab one of them is to see the certificate.

here is the cache.log:


2026/07/23 07:32:59 kid1| Processing Configuration File: 
/etc/squid/squid.conf (depth 0)
2026/07/23 07:32:59 kid1| Set Current Directory to /var/cache/squid
2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6 for 
x86_64-suse-linux-gnu...
2026/07/23 07:32:59 kid1| Service Name: squid
2026/07/23 07:32:59 kid1| Process ID 3183
2026/07/23 07:32:59 kid1| Process Roles: worker
2026/07/23 07:32:59 kid1| With 4096 file descriptors available
2026/07/23 07:32:59 kid1| Initializing IP Cache...
2026/07/23 07:32:59 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46 from 
/etc/resolv.conf
2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5 from /etc/resolv.conf
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1 
'security_file_certgen' processes
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16 'ufdbgclient' 
processes
2026/07/23 07:32:59 kid1| Logfile: opening log 
daemon:/var/log/squid/access.log
2026/07/23 07:32:59 kid1| Logfile Daemon: opening log 
/var/log/squid/access.log
2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31
2026/07/23 07:33:00 kid1| Local cache digest enabled; rebuild/rewrite 
every 3600/3600 sec
2026/07/23 07:33:00 kid1| Store logging disabled
2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040 KB, estimated 
311926 objects
2026/07/23 07:33:00 kid1| Target number of buckets: 15596
2026/07/23 07:33:00 kid1| Using 16384 Store buckets
2026/07/23 07:33:00 kid1| Max Mem  size: 983040 KB
2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB
2026/07/23 07:33:00 kid1| Rebuilding storage in /var/cache/squid (clean log)
2026/07/23 07:33:00 kid1| Using Least Load store dir selection
2026/07/23 07:33:00 kid1| Set Current Directory to /var/cache/squid
2026/07/23 07:33:00 kid1| Finished loading MIME types and icons.
2026/07/23 07:33:00 kid1| HTCP Disabled.
2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36
2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0
2026/07/23 07:33:00 kid1| Adaptation support is off.
2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket connections 
at conn20 local=0.0.0.0:8080 remote=[::] FD 34 flags=9
     listening port: 8080
2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation. Detected 
non-functional IPv6 loopback.
2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...
2026/07/23 07:33:00 pinger| ICMP socket opened.
2026/07/23 07:33:00 pinger| ICMPv6 socket opened
2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84% (4000 out of 216863)
2026/07/23 07:33:03 kid1| Done reading /var/cache/squid swaplog (216862 
entries)
2026/07/23 07:33:03 kid1| Finished rebuilding storage from disk.
      216862 Entries scanned
           0 Invalid entries
           0 With invalid flags
      216862 Objects loaded
           0 Objects expired
           0 Objects canceled
           0 Duplicate URLs purged
           0 Swapfile clashes avoided
     Took 3.16 seconds (68526.49 objects/sec).
2026/07/23 07:33:03 kid1| Beginning Validation Procedure
2026/07/23 07:33:03 kid1| Completed Validation Procedure
     Validated 216848 Entries
     store_swap_size = 2764352.00 KB
2026/07/23 07:33:03 kid1| storeLateRelease: released 0 objects
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
     problem: failure
     error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
     current master transaction: master58
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
     problem: failure
     error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
     current master transaction: master58
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
     problem: failure
     error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
     current master transaction: master58
.........


>>>> 2026/07/17 08:17:35| Removing PID file (/run/squid.pid)
>>>> 2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected 
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_localhost
>>>>      configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_localhost
>>>>      configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_linklocal
>>>>      configuration context: Default Configuration(16) acl
>>>> 2026/07/17 08:18:54| Processing Configuration File: 
>>>> /etc/squid/squid.conf (depth 0)
>>>> 2026/07/17 08:18:55| Created PID file (/run/squid.pid)
>>>> 2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation. Detected 
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_localhost
>>>>      configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_localhost
>>>>      configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>>      acl name: to_linklocal
>>>>      configuration context: Default Configuration(16) acl
>>>> 2026/07/17 08:18:55 kid1| Processing Configuration File: 
>>>> /etc/squid/squid.conf (depth 0)
>>>> 2026/07/17 08:18:55 kid1| Set Current Directory to /var/cache/squid
>>>> 2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6 for 
>>>> x86_64-suse-linux-gnu...
>>>> 2026/07/17 08:18:55 kid1| Service Name: squid
>>>> 2026/07/17 08:18:55 kid1| Process ID 3685
>>>> 2026/07/17 08:18:55 kid1| Process Roles: worker
>>>> 2026/07/17 08:18:55 kid1| With 4096 file descriptors available
>>>> 2026/07/17 08:18:55 kid1| Initializing IP Cache...
>>>> 2026/07/17 08:18:55 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
>>>> 2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from 
>>>> /etc/resolv.conf
>>>> 2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from 
>>>> /etc/resolv.conf
>>>> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5 
>>>> 'security_file_certgen' processes
>>>> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16 
>>>> 'ufdbgclient' processes
>>>> 2026/07/17 08:18:55 kid1| Logfile: opening log 
>>>> daemon:/var/log/squid/access.log
>>>> 2026/07/17 08:18:55 kid1| Logfile Daemon: opening log 
>>>> /var/log/squid/access.log
>>>> 2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39
>>>> 2026/07/17 08:18:56 kid1| Local cache digest enabled; 
>>>> rebuild/rewrite every 3600/3600 sec
>>>> 2026/07/17 08:18:56 kid1| Store logging disabled
>>>> 2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB, 
>>>> estimated 311926 objects
>>>> 2026/07/17 08:18:56 kid1| Target number of buckets: 15596
>>>> 2026/07/17 08:18:56 kid1| Using 16384 Store buckets
>>>> 2026/07/17 08:18:56 kid1| Max Mem  size: 983040 KB
>>>> 2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB
>>>> 2026/07/17 08:18:56 kid1| Rebuilding storage in /var/cache/squid 
>>>> (clean log)
>>>> 2026/07/17 08:18:56 kid1| Using Least Load store dir selection
>>>> 2026/07/17 08:18:56 kid1| Set Current Directory to /var/cache/squid
>>>> 2026/07/17 08:18:56 kid1| Finished loading MIME types and icons.
>>>> 2026/07/17 08:18:56 kid1| HTCP Disabled.
>>>> 2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44
>>>> 2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0
>>>> 2026/07/17 08:18:56 kid1| Adaptation support is off.
>>>> 2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket 
>>>> connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9
>>>>      listening port: 8080
>>>> 2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation. Detected 
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:56 pinger| Initialising ICMP pinger ...
>>>> 2026/07/17 08:18:56 pinger| ICMP socket opened.
>>>> 2026/07/17 08:18:56 pinger| ICMPv6 socket opened
>>>> 2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84% (4000 out 
>>>> of 217945)
>>>> 2026/07/17 08:18:59 kid1| Done reading /var/cache/squid swaplog 
>>>> (217944 entries)
>>>> 2026/07/17 08:18:59 kid1| Finished rebuilding storage from disk.
>>>>       217944 Entries scanned
>>>>            0 Invalid entries
>>>>            0 With invalid flags
>>>>       217944 Objects loaded
>>>>            0 Objects expired
>>>>            0 Objects canceled
>>>>            0 Duplicate URLs purged
>>>>            0 Swapfile clashes avoided
>>>>      Took 2.85 seconds (76435.29 objects/sec).
>>>> 2026/07/17 08:18:59 kid1| Beginning Validation Procedure
>>>> 2026/07/17 08:18:59 kid1| Completed Validation Procedure
>>>>      Validated 217930 Entries
>>>>      store_swap_size = 2764788.00 KB
>>>> 2026/07/17 08:18:59 kid1| storeLateRelease: released 0 objects
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>>
>>>> ........
>>>>
>>>> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS connection
>>>>      problem: failure
>>>>      error detail: 
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes are 
>>>> running (need 1/5)
>>>>      active processes: 4
>>>>      processes configured to start at (re)configuration: 5
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5 
>>>> 'security_file_certgen' processes
>>>>      current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| Preparing for shutdown after 761 requests
>>>> 2026/07/17 08:21:33 kid1| Waiting 30 seconds for active connections 
>>>> to finish
>>>> 2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080
>>>>      listening port: 8080
>>>> 2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44
>>>> 2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite: 
>>>> daemon:/var/log/squid/access.log: error writing ((32) Broken pipe)
>>>>      connection: conn2846 local=10.0.0.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs: Starting...
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1|     65536 entries written so far.
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1|    131072 entries written so far.
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1|    196608 entries written so far.
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1|   Finished.  Wrote 217944 entries.
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1|   Took 0.08 seconds (2736133.78 
>>>> entries/sec).
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.16.0.7:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| FATAL: I don't handle this error well!
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6): Terminated 
>>>> abnormally.
>>>>      connection: conn2846 local=10.10.10.18:8080 
>>>> remote=10.1.0.17:53255 flags=1
>>>> CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
>>>> Maximum Resident Size: 314320 KB
>>>> Page faults with physical i/o: 0
>>>>>
>>>>> To recreate a certificate database you should do:
>>>>>
>>>>> sudo rm -rf /var/cache/squid/ssl_db
>>>>> sudo /usr/libexec/squid/security_file_certgen -c 
>>>>> -s /var/cache/squid/ssl_db -M 4MB
>>>>> sudo chown -R squid:squid /var/cache/squid/ssl_db
>>>>>
>>>>> чт, 16 июл. 2026 г. в 16:36, Alex Rousskov 
>>>>> <[email protected]>:
>>>>>
>>>>>     On 2026-07-16 01:57, Vacheslav wrote:
>>>>>
>>>>>     > 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program #Hlpr1 
>>>>> exited
>>>>>
>>>>>     We need to figure out why your security_file_certgen helpers are
>>>>>     exiting. IIRC, those helpers have not been upgraded to report 
>>>>> their
>>>>>     fatal failures to cache.log. There are a few tricks you can 
>>>>> use to
>>>>>     see
>>>>>     what the problem is, but I would probably start with these three:
>>>>>
>>>>>     1. Run security_file_certgen with sslcrtd_program parameters 
>>>>> from the
>>>>>     command line, as Squid user. If you are lucky, it will 
>>>>> complain about
>>>>>     something before it starts waiting for the helper request.
>>>>>
>>>>>     2. Redirect security_file_certgen stderr (but not stdout!) output
>>>>>     into a
>>>>>     dedicated log file. It may be possible to do that right on the
>>>>>     sslcrtd_program line, without wrapping the helper into another 
>>>>> script.
>>>>>
>>>>>     3. Enable full debugging, reproduce the problem with a single
>>>>>     transaction, and send a link to the corresponding compressed
>>>>>     cache.log
>>>>>     file for analysis as detailed at
>>>>> https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction 
>>>>>
>>>>>
>>>>>
>>>>>     Cheers,
>>>>>
>>>>>     Alex.
>>>>>
>>>>>     _______________________________________________
>>>>>     squid-users mailing list
>>>>> [email protected]
>>>>> https://lists.squid-cache.org/listinfo/squid-users
>>>>>
>>>>
>>>
>>
>

--------------2SpC4Y0ZkYSPEfFo0hmLBAjI
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#26a269" bgcolor="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">20.07.2026 20:15, Alex Rousskov пишет:<br>
    </div>
    <blockquote type="cite"
cite="mid:[email protected]">On
      2026-07-20 01:27, Vacheslav wrote:
      <br>
      <blockquote type="cite">17.07.2026 15:44, Alex Rousskov пишет:
        <br>
        <blockquote type="cite">On 2026-07-17 01:31, Vacheslav wrote:
          <br>
          <br>
          <blockquote type="cite">16.07.2026 18:19, Andrey K пишет:
            <br>
            <blockquote type="cite">@Vacheslav:
              <br>
              &gt; sudo /usr/libexec/squid/security_file_certgen -c -s
              <br>
              &gt; /var/cache/squid/ssl_db/certs -M 4MB
              <br>
              You specified the wrong path (the correct one is
              /var/cache/squid/ssl_db ).
              <br>
            </blockquote>
            <br>
            <br>
            good catch:
            <br>
            now running:
            <br>
              sudo -u squid /usr/libexec/squid/security_file_certgen -s
            /var/cache/squid/ssl_db -M 4MB
            <br>
            ^C
            <br>
            produces nothing.
            <br>
          </blockquote>
          <br>
          That lack of output is a good sign -- the helper managed to
          start successfully.
          <br>
          <br>
          <br>
          <blockquote type="cite">2026/07/17 08:21:33 kid1| WARNING:
            sslcrtd_program #Hlpr1 exited
            <br>
          </blockquote>
          <br>
          Helpers are still dying, but it looks like they do it while
          handling traffic.
          <br>
          <br>
          <br>
          <blockquote type="cite">
            <blockquote type="cite">2. Redirect security_file_certgen
              stderr (but not stdout!) output
              <br>
              into a dedicated log file. It may be possible to do that
              right on
              <br>
              the sslcrtd_program line, without wrapping the helper into
              another
              <br>
              script.
              <br>
            </blockquote>
          </blockquote>
          <br>
          <blockquote type="cite">how to do that?
            <br>
          </blockquote>
          <br>
          Try using shell redirection when specifying how to run the
          helper. Something along these lines may work:
          <br>
          <br>
              sslcrtd_program /usr/local/... -M 4MB &gt;&gt;
          /tmp/sslcrtd.error.log
          <br>
        </blockquote>
      </blockquote>
      <br>
      <br>
      My bad. I missed "2" to redirect stderr rather than stdout. Fixed
      below. The missing file descriptor is _not_ the reason your test
      is not working though (as detailed below).
      <br>
      <br>
      <br>
      <blockquote type="cite">now the configuration looks like this:
        <br>
        <br>
        sslcrtd_program /usr/libexec/squid/security_file_certgen -s
        /var/cache/squid/ssl_db -M 4MB &gt;&gt; /tmp/sslcrtd.error.log
        <br>
      </blockquote>
      <br>
      <br>
      To capture stderr:
      <br>
      <br>
      sslcrtd_program /usr/libexec/squid/security_file_certgen -s
      <br>
      /var/cache/squid/ssl_db -M 4MB 2&gt;&gt; /tmp/sslcrtd.error.log
      <br>
      <br>
      <br>
      <blockquote type="cite">in tmp there is no sslcrtd.error.log file.
        <br>
      </blockquote>
      <br>
      <br>
      AFAICT, your Squid does not start sslcrtd_program helper. What
      does "squid -v" say? If there is no '--enable-ssl-crtd' there,
      then you need to rebuild your Squid executable from scratch. Also,
      at least one http_port or https_port directive in your squid.conf
      should have both "generate-host-certificates" and "ssl-bump"
      options. <br>
    </blockquote>
    <br>
    sudo squid -v | grep "enable-ssl-crtd"<br>
    ........'--enable-arp-acl' '--enable-ssl-crtd'.............<br>
    <br>
    <blockquote type="cite"
cite="mid:[email protected]">When
      done right, you should see the debugging file created in /tmp/
      and, in cache log, Squid logging "Starting ..." lines mentioning
      your helper (similar to your existing lines for the ufdbgclient
      helper). <br>
    </blockquote>
    here is the configuration with the 8080 sslbump port open:<br>
    <br>
    <br>
    forwarded_for delete<br>
    <br>
    delay_pools 1<br>
    delay_class 1 3<br>
    delay_access 1 allow slower<br>
    delay_access 1 deny all<br>
    delay_parameters 1 128000/128000 -1/-1 128000/64000<br>
    <br>
    http_access allow localnet <br>
    http_access allow localhost<br>
    <br>
    <br>
    <br>
    # And finally deny all other access to this proxy<br>
    http_access deny all<br>
    <br>
    # Squid normally listens to port 3128<br>
    #http_port 8080<br>
    <br>
    <br>
    <br>
    http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem
    generate-host-certificates=on dynamic_cert_mem_cache_size=8MB<br>
    <br>
    <br>
    <br>
    <br>
    ##acl step1 at_step SslBump1                       <br>
    ##ssl_bump peek step1                       <br>
    ##ssl_bump bump all<br>
    <br>
    ##sslcrtd_program /usr/libexec/squid/security_file_certgen -s
    /var/lib/squid/ssl_db -M 4MB<br>
    ##sslcrtd_children 5<br>
    <br>
    acl     tls_s1_connect            at_step SslBump1<br>
    acl     tls_s2_client_hello     at_step SslBump2<br>
    acl     tls_s3_server_hello     at_step SslBump3<br>
    <br>
    # define acls for sites that must not be actively bumped<br>
    <br>
    acl     tls_allowed_hsts        ssl::server_name           
     .akamaihd.net<br>
    acl     tls_allowed_hsts        ssl::server_name           
     .proxy.skko.by<br>
    #acl     tls_server_is_bank         ssl::server_name           
     .abnamro.nl<br>
    #acl     tls_server_is_bank         ssl::server_name           
     .abnamro.com<br>
    acl     tls_server_is_bank         ssl::server_name           
    "/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"<br>
    acl     tls_to_splice             any-of                       
     tls_allowed_hsts        tls_server_is_bank<br>
    <br>
    # TLS/SSL bumping steps<br>
    <br>
    ssl_bump         peek                tls_s1_connect         # peek
    at TLS/SSL connect data<br>
    ssl_bump         splice                 tls_to_splice        #
    splice some: no active bump<br>
    ssl_bump         stare                 all                    #
    stare(peek) at server<br>
                                                            # properties
    of the webserver<br>
    ssl_bump         bump                                    # bump if
    we can (if the stare succeeded)<br>
    <br>
    ssl_bump peek tls_s1_connect<br>
    ssl_bump splice all<br>
    <br>
    <br>
    #ssl_bump peek all<br>
    ############ssl_bump splice all<br>
    <br>
    <br>
    sslcrtd_program /usr/libexec/squid/security_file_certgen -s
    /var/cache/squid/ssl_db -M 4MB 2&gt;&gt; /tmp/sslcrtd.error.log<br>
    sslcrtd_children 1 startup=1 idle=1<br>
    <br>
    ssl_bump server-first all<br>
    <br>
    sslproxy_cert_error allow all<br>
    <br>
    #tls_outgoing_options options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE
cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS<br>
    <br>
    # Uncomment and adjust the following to add a disk cache directory.<br>
    # Updates: chrome and acrobat<br>
    #refresh_pattern -i gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf) 43200
    80% 129600 reload-into-ims<br>
    #refresh_pattern -i adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)
    43200 80% 129600 reload-into-ims<br>
    <br>
                  <br>
    <br>
    #range_offset_limit 200 MB <br>
    #maximum_object_size 200 MB<br>
    #quick_abort_min -1<br>
    <br>
    # DONT MODIFY THESE LINES<br>
    #refresh_pattern \^ftp:           1440    20%     10080<br>
    #refresh_pattern \^gopher:        1440    0%      1440<br>
    #refresh_pattern -i (/cgi-bin/|\?) 0      0%      0<br>
    #refresh_pattern .                   0      20%     43200<br>
    <br>
    cache_dir ufs /var/cache/squid 3000 16 256<br>
    <br>
    # Leave coredumps in the first cache dir<br>
    coredump_dir /var/cache/squid<br>
    <br>
    cache_mem 960 MB<br>
    <br>
    netdb_filename none<br>
    <br>
    logformat squidx %err_code/%err_detail<br>
    #access_log daemon:/var/log/squid/accessX.log squidx<br>
    #access_log squidx<br>
    <br>
    #<br>
    # Add any of your own refresh_pattern entries above these.<br>
    #<br>
    refresh_pattern ^ftp:                1440    20%    10080<br>
    refresh_pattern ^gopher:            1440    0%    1440<br>
    refresh_pattern -i (/cgi-bin/|\?)     0        0%    0<br>
    refresh_pattern .                    0        20%    4320<br>
    <br>
    url_rewrite_extras "%&gt;a/%&gt;A %un %&gt;rm
    bump_mode=%ssl::bump_mode sni=\"%ssl::&gt;sni\"
    referer=\"%{Referer}&gt;h\""<br>
    url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient -m 4 -l
    /var/log/squid/<br>
    url_rewrite_children 16 startup=8 idle=2 concurrency=4 queue-size=64<br>
    #debug_options ALL,1 33,2 28,9<br>
    <br>
    <blockquote type="cite"
cite="mid:[email protected]">HTH,
      <br>
      <br>
      Alex. </blockquote>
    <br>
    i finally noticed an empty sslcrtd.error.log file in /tmp created on
    20.07.2026, for some reason i was looking for a folder, stupid me.<br>
    <br>
    i'm getting certificate errors when browsing sites in firefox. some
    sites provide a warning to proceed to site (dangerous) other sites
    just put 3 tab one of them is to see the certificate.<br>
    <br>
    here is the cache.log:<br>
    <br>
    <br>
    2026/07/23 07:32:59 kid1| Processing Configuration File:
    /etc/squid/squid.conf (depth 0)<br>
    2026/07/23 07:32:59 kid1| Set Current Directory to /var/cache/squid<br>
    2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6 for
    x86_64-suse-linux-gnu...<br>
    2026/07/23 07:32:59 kid1| Service Name: squid<br>
    2026/07/23 07:32:59 kid1| Process ID 3183<br>
    2026/07/23 07:32:59 kid1| Process Roles: worker<br>
    2026/07/23 07:32:59 kid1| With 4096 file descriptors available<br>
    2026/07/23 07:32:59 kid1| Initializing IP Cache...<br>
    2026/07/23 07:32:59 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7<br>
    2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46 from
    /etc/resolv.conf<br>
    2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5 from
    /etc/resolv.conf<br>
    2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1
    'security_file_certgen' processes<br>
    2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16
    'ufdbgclient' processes<br>
    2026/07/23 07:32:59 kid1| Logfile: opening log
    daemon:/var/log/squid/access.log<br>
    2026/07/23 07:32:59 kid1| Logfile Daemon: opening log
    /var/log/squid/access.log<br>
    2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31<br>
    2026/07/23 07:33:00 kid1| Local cache digest enabled;
    rebuild/rewrite every 3600/3600 sec<br>
    2026/07/23 07:33:00 kid1| Store logging disabled<br>
    2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040 KB,
    estimated 311926 objects<br>
    2026/07/23 07:33:00 kid1| Target number of buckets: 15596<br>
    2026/07/23 07:33:00 kid1| Using 16384 Store buckets<br>
    2026/07/23 07:33:00 kid1| Max Mem  size: 983040 KB<br>
    2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB<br>
    2026/07/23 07:33:00 kid1| Rebuilding storage in /var/cache/squid
    (clean log)<br>
    2026/07/23 07:33:00 kid1| Using Least Load store dir selection<br>
    2026/07/23 07:33:00 kid1| Set Current Directory to /var/cache/squid<br>
    2026/07/23 07:33:00 kid1| Finished loading MIME types and icons.<br>
    2026/07/23 07:33:00 kid1| HTCP Disabled.<br>
    2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36<br>
    2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0<br>
    2026/07/23 07:33:00 kid1| Adaptation support is off.<br>
    2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket
    connections at conn20 local=0.0.0.0:8080 remote=[::] FD 34 flags=9<br>
        listening port: 8080<br>
    2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation. Detected
    non-functional IPv6 loopback.<br>
    2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...<br>
    2026/07/23 07:33:00 pinger| ICMP socket opened.<br>
    2026/07/23 07:33:00 pinger| ICMPv6 socket opened<br>
    2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84% (4000 out of
    216863)<br>
    2026/07/23 07:33:03 kid1| Done reading /var/cache/squid swaplog
    (216862 entries)<br>
    2026/07/23 07:33:03 kid1| Finished rebuilding storage from disk.<br>
         216862 Entries scanned<br>
              0 Invalid entries<br>
              0 With invalid flags<br>
         216862 Objects loaded<br>
              0 Objects expired<br>
              0 Objects canceled<br>
              0 Duplicate URLs purged<br>
              0 Swapfile clashes avoided<br>
        Took 3.16 seconds (68526.49 objects/sec).<br>
    2026/07/23 07:33:03 kid1| Beginning Validation Procedure<br>
    2026/07/23 07:33:03 kid1| Completed Validation Procedure<br>
        Validated 216848 Entries<br>
        store_swap_size = 2764352.00 KB<br>
    2026/07/23 07:33:03 kid1| storeLateRelease: released 0 objects<br>
    2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection<br>
        problem: failure<br>
        error detail:
    SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1<br>
        current master transaction: master58<br>
    2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection<br>
        problem: failure<br>
        error detail:
    SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
        current master transaction: master58<br>
    2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection<br>
        problem: failure<br>
        error detail:
    SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
        current master transaction: master58<br>
    .........<br>
    <br>
    <br>
    <blockquote type="cite"
cite="mid:[email protected]">
      <blockquote type="cite">
        <blockquote type="cite">
          <blockquote type="cite">2026/07/17 08:17:35| Removing PID file
            (/run/squid.pid)
            <br>
            2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected
            non-functional IPv6 loopback.
            <br>
            2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been
            enabled.
            <br>
                 acl name: to_localhost
            <br>
                 configuration context: Default Configuration(15) acl
            <br>
            2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been
            enabled.
            <br>
                 acl name: to_localhost
            <br>
                 configuration context: Default Configuration(15) acl
            <br>
            2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been
            enabled.
            <br>
                 acl name: to_linklocal
            <br>
                 configuration context: Default Configuration(16) acl
            <br>
            2026/07/17 08:18:54| Processing Configuration File:
            /etc/squid/squid.conf (depth 0)
            <br>
            2026/07/17 08:18:55| Created PID file (/run/squid.pid)
            <br>
            2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation.
            Detected non-functional IPv6 loopback.
            <br>
            2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not
            been enabled.
            <br>
                 acl name: to_localhost
            <br>
                 configuration context: Default Configuration(15) acl
            <br>
            2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not
            been enabled.
            <br>
                 acl name: to_localhost
            <br>
                 configuration context: Default Configuration(15) acl
            <br>
            2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not
            been enabled.
            <br>
                 acl name: to_linklocal
            <br>
                 configuration context: Default Configuration(16) acl
            <br>
            2026/07/17 08:18:55 kid1| Processing Configuration File:
            /etc/squid/squid.conf (depth 0)
            <br>
            2026/07/17 08:18:55 kid1| Set Current Directory to
            /var/cache/squid
            <br>
            2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6
            for x86_64-suse-linux-gnu...
            <br>
            2026/07/17 08:18:55 kid1| Service Name: squid
            <br>
            2026/07/17 08:18:55 kid1| Process ID 3685
            <br>
            2026/07/17 08:18:55 kid1| Process Roles: worker
            <br>
            2026/07/17 08:18:55 kid1| With 4096 file descriptors
            available
            <br>
            2026/07/17 08:18:55 kid1| Initializing IP Cache...
            <br>
            2026/07/17 08:18:55 kid1| DNS IPv4 socket created at
            0.0.0.0, FD 7
            <br>
            2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from
            /etc/resolv.conf
            <br>
            2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from
            /etc/resolv.conf
            <br>
            2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5
            'security_file_certgen' processes
            <br>
            2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16
            'ufdbgclient' processes
            <br>
            2026/07/17 08:18:55 kid1| Logfile: opening log
            daemon:/var/log/squid/access.log
            <br>
            2026/07/17 08:18:55 kid1| Logfile Daemon: opening log
            /var/log/squid/access.log
            <br>
            2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39
            <br>
            2026/07/17 08:18:56 kid1| Local cache digest enabled;
            rebuild/rewrite every 3600/3600 sec
            <br>
            2026/07/17 08:18:56 kid1| Store logging disabled
            <br>
            2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB,
            estimated 311926 objects
            <br>
            2026/07/17 08:18:56 kid1| Target number of buckets: 15596
            <br>
            2026/07/17 08:18:56 kid1| Using 16384 Store buckets
            <br>
            2026/07/17 08:18:56 kid1| Max Mem  size: 983040 KB
            <br>
            2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB
            <br>
            2026/07/17 08:18:56 kid1| Rebuilding storage in
            /var/cache/squid (clean log)
            <br>
            2026/07/17 08:18:56 kid1| Using Least Load store dir
            selection
            <br>
            2026/07/17 08:18:56 kid1| Set Current Directory to
            /var/cache/squid
            <br>
            2026/07/17 08:18:56 kid1| Finished loading MIME types and
            icons.
            <br>
            2026/07/17 08:18:56 kid1| HTCP Disabled.
            <br>
            2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44
            <br>
            2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0
            <br>
            2026/07/17 08:18:56 kid1| Adaptation support is off.
            <br>
            2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket
            connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42
            flags=9
            <br>
                 listening port: 8080
            <br>
            2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation.
            Detected non-functional IPv6 loopback.
            <br>
            2026/07/17 08:18:56 pinger| Initialising ICMP pinger ...
            <br>
            2026/07/17 08:18:56 pinger| ICMP socket opened.
            <br>
            2026/07/17 08:18:56 pinger| ICMPv6 socket opened
            <br>
            2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84%
            (4000 out of 217945)
            <br>
            2026/07/17 08:18:59 kid1| Done reading /var/cache/squid
            swaplog (217944 entries)
            <br>
            2026/07/17 08:18:59 kid1| Finished rebuilding storage from
            disk.
            <br>
                  217944 Entries scanned
            <br>
                       0 Invalid entries
            <br>
                       0 With invalid flags
            <br>
                  217944 Objects loaded
            <br>
                       0 Objects expired
            <br>
                       0 Objects canceled
            <br>
                       0 Duplicate URLs purged
            <br>
                       0 Swapfile clashes avoided
            <br>
                 Took 2.85 seconds (76435.29 objects/sec).
            <br>
            2026/07/17 08:18:59 kid1| Beginning Validation Procedure
            <br>
            2026/07/17 08:18:59 kid1| Completed Validation Procedure
            <br>
                 Validated 217930 Entries
            <br>
                 store_swap_size = 2764788.00 KB
            <br>
            2026/07/17 08:18:59 kid1| storeLateRelease: released 0
            objects
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master55
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master55
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master55
            <br>
            2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            <br>
            ........
            <br>
            <br>
            2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS
            connection
            <br>
                 problem: failure
            <br>
                 error detail:
            SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1
            exited
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes
            are running (need 1/5)
            <br>
                 active processes: 4
            <br>
                 processes configured to start at (re)configuration: 5
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5
            'security_file_certgen' processes
            <br>
                 current master transaction: master57
            <br>
            2026/07/17 08:21:33 kid1| Preparing for shutdown after 761
            requests
            <br>
            2026/07/17 08:21:33 kid1| Waiting 30 seconds for active
            connections to finish
            <br>
            2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080
            <br>
                 listening port: 8080
            <br>
            2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44
            <br>
            2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite:
            daemon:/var/log/squid/access.log: error writing ((32) Broken
            pipe)
            <br>
                 connection: conn2846 local=10.0.0.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs:
            Starting...
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1|     65536 entries written so far.
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1|    131072 entries written so far.
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1|    196608 entries written so far.
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1|   Finished.  Wrote 217944 entries.
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1|   Took 0.08 seconds (2736133.78
            entries/sec).
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.16.0.7:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1| FATAL: I don't handle this error
            well!
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6):
            Terminated abnormally.
            <br>
                 connection: conn2846 local=10.10.10.18:8080
            remote=10.1.0.17:53255 flags=1
            <br>
            CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
            <br>
            Maximum Resident Size: 314320 KB
            <br>
            Page faults with physical i/o: 0
            <br>
            <blockquote type="cite">
              <br>
              To recreate a certificate database you should do:
              <br>
              <br>
              sudo rm -rf /var/cache/squid/ssl_db
              <br>
              sudo /usr/libexec/squid/security_file_certgen -c
              -s /var/cache/squid/ssl_db -M 4MB
              <br>
              sudo chown -R squid:squid /var/cache/squid/ssl_db
              <br>
              <br>
              чт, 16 июл. 2026 г. в 16:36, Alex Rousskov
              <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>:
              <br>
              <br>
                  On 2026-07-16 01:57, Vacheslav wrote:
              <br>
              <br>
                  &gt; 2026/07/16 08:34:24 kid1| WARNING:
              sslcrtd_program #Hlpr1 exited
              <br>
              <br>
                  We need to figure out why your security_file_certgen
              helpers are
              <br>
                  exiting. IIRC, those helpers have not been upgraded to
              report their
              <br>
                  fatal failures to cache.log. There are a few tricks
              you can use to
              <br>
                  see
              <br>
                  what the problem is, but I would probably start with
              these three:
              <br>
              <br>
                  1. Run security_file_certgen with sslcrtd_program
              parameters from the
              <br>
                  command line, as Squid user. If you are lucky, it will
              complain about
              <br>
                  something before it starts waiting for the helper
              request.
              <br>
              <br>
                  2. Redirect security_file_certgen stderr (but not
              stdout!) output
              <br>
                  into a
              <br>
                  dedicated log file. It may be possible to do that
              right on the
              <br>
                  sslcrtd_program line, without wrapping the helper into
              another script.
              <br>
              <br>
                  3. Enable full debugging, reproduce the problem with a
              single
              <br>
                  transaction, and send a link to the corresponding
              compressed
              <br>
                  cache.log
              <br>
                  file for analysis as detailed at
              <br>
<a class="moz-txt-link-freetext" href="https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction">https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction</a>
              <br>
              <br>
              <br>
                  Cheers,
              <br>
              <br>
                  Alex.
              <br>
              <br>
                  _______________________________________________
              <br>
                  squid-users mailing list
              <br>
              <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
              <br>
              <a class="moz-txt-link-freetext" href="https://lists.squid-cache.org/listinfo/squid-users">https://lists.squid-cache.org/listinfo/squid-users</a>
              <br>
              <br>
            </blockquote>
            <br>
          </blockquote>
          <br>
        </blockquote>
        <br>
      </blockquote>
      <br>
    </blockquote>
    <br>
  </body>
</html>

--------------2SpC4Y0ZkYSPEfFo0hmLBAjI--

--===============4697690215031224580==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============4697690215031224580==--