Re: ssl bump

Vacheslav <[email protected]> Thu, 23 Jul 2026 14:38:10 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2770530707340702711==
Content-Type: multipart/alternative;
 boundary="------------MbtEixSrJshsMr0DldZG6dc7"
Content-Language: en-US, ru-RU

This is a multi-part message in MIME format.
--------------MbtEixSrJshsMr0DldZG6dc7
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit



23.07.2026 12:53, Andrey K пишет:
> Hello, Vacheslav,
>
> It seems that the logs from 2026/07/23 no longer show any 
> security_file_certgen crashes, but the browser errors are still there. 
> Is it possible that the browsers are simply rejecting the new proxy 
> certificate because it's not trusted?
even though i imported the new certificate, the browser was using the 
old certificate with the same certificate name, so i reissued the new 
der certificate and imported it into firefox and now it visible as the 
new certificate but the websites are not opening as they display a mixed 
certificate between the site and the squid certificate.
now the conf reconfigured is:
http_port 8080 ssl-bump  cert=/etc/squid/certs/squid-ca-cert-key.pem 
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB

>
>
> On 23.07.2026 08:22, Vacheslav <[email protected]> wrote:
>
>
>
>     20.07.2026 20:15, Alex Rousskov пишет:
>>     On 2026-07-20 01:27, Vacheslav wrote:
>>>     17.07.2026 15:44, Alex Rousskov пишет:
>>>>     On 2026-07-17 01:31, Vacheslav wrote:
>>>>
>>>>>     16.07.2026 18:19, Andrey K пишет:
>>>>>>     @Vacheslav:
>>>>>>     > sudo /usr/libexec/squid/security_file_certgen -c -s
>>>>>>     > /var/cache/squid/ssl_db/certs -M 4MB
>>>>>>     You specified the wrong path (the correct one is
>>>>>>     /var/cache/squid/ssl_db ).
>>>>>
>>>>>
>>>>>     good catch:
>>>>>     now running:
>>>>>       sudo -u squid /usr/libexec/squid/security_file_certgen -s
>>>>>     /var/cache/squid/ssl_db -M 4MB
>>>>>     ^C
>>>>>     produces nothing.
>>>>
>>>>     That lack of output is a good sign -- the helper managed to
>>>>     start successfully.
>>>>
>>>>
>>>>>     2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>>
>>>>     Helpers are still dying, but it looks like they do it while
>>>>     handling traffic.
>>>>
>>>>
>>>>>>     2. Redirect security_file_certgen stderr (but not stdout!)
>>>>>>     output
>>>>>>     into a dedicated log file. It may be possible to do that
>>>>>>     right on
>>>>>>     the sslcrtd_program line, without wrapping the helper into
>>>>>>     another
>>>>>>     script.
>>>>
>>>>>     how to do that?
>>>>
>>>>     Try using shell redirection when specifying how to run the
>>>>     helper. Something along these lines may work:
>>>>
>>>>         sslcrtd_program /usr/local/... -M 4MB >>
>>>>     /tmp/sslcrtd.error.log
>>
>>
>>     My bad. I missed "2" to redirect stderr rather than stdout. Fixed
>>     below. The missing file descriptor is _not_ the reason your test
>>     is not working though (as detailed below).
>>
>>
>>>     now the configuration looks like this:
>>>
>>>     sslcrtd_program /usr/libexec/squid/security_file_certgen -s
>>>     /var/cache/squid/ssl_db -M 4MB >> /tmp/sslcrtd.error.log
>>
>>
>>     To capture stderr:
>>
>>     sslcrtd_program /usr/libexec/squid/security_file_certgen -s
>>     /var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
>>
>>
>>>     in tmp there is no sslcrtd.error.log file.
>>
>>
>>     AFAICT, your Squid does not start sslcrtd_program helper. What
>>     does "squid -v" say? If there is no '--enable-ssl-crtd' there,
>>     then you need to rebuild your Squid executable from scratch.
>>     Also, at least one http_port or https_port directive in your
>>     squid.conf should have both "generate-host-certificates" and
>>     "ssl-bump" options.
>
>     sudo squid -v | grep "enable-ssl-crtd"
>     ........'--enable-arp-acl' '--enable-ssl-crtd'.............
>
>>     When done right, you should see the debugging file created in
>>     /tmp/ and, in cache log, Squid logging "Starting ..." lines
>>     mentioning your helper (similar to your existing lines for the
>>     ufdbgclient helper).
>     here is the configuration with the 8080 sslbump port open:
>
>
>     forwarded_for delete
>
>     delay_pools 1
>     delay_class 1 3
>     delay_access 1 allow slower
>     delay_access 1 deny all
>     delay_parameters 1 128000/128000 -1/-1 128000/64000
>
>     http_access allow localnet
>     http_access allow localhost
>
>
>
>     # And finally deny all other access to this proxy
>     http_access deny all
>
>     # Squid normally listens to port 3128
>     #http_port 8080
>
>
>
>     http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem
>     generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
>
>
>
>
>     ##acl step1 at_step SslBump1
>     ##ssl_bump peek step1
>     ##ssl_bump bump all
>
>     ##sslcrtd_program /usr/libexec/squid/security_file_certgen -s
>     /var/lib/squid/ssl_db -M 4MB
>     ##sslcrtd_children 5
>
>     acl     tls_s1_connect            at_step SslBump1
>     acl     tls_s2_client_hello     at_step SslBump2
>     acl     tls_s3_server_hello     at_step SslBump3
>
>     # define acls for sites that must not be actively bumped
>
>     acl     tls_allowed_hsts        ssl::server_name    .akamaihd.net
>     <http://akamaihd.net>
>     acl     tls_allowed_hsts        ssl::server_name    .proxy.skko.by
>     <http://proxy.skko.by>
>     #acl     tls_server_is_bank         ssl::server_name      
>      .abnamro.nl <http://abnamro.nl>
>     #acl     tls_server_is_bank         ssl::server_name      
>      .abnamro.com <http://abnamro.com>
>     acl     tls_server_is_bank         ssl::server_name
>     "/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"
>     acl     tls_to_splice             any-of        tls_allowed_hsts 
>           tls_server_is_bank
>
>     # TLS/SSL bumping steps
>
>     ssl_bump         peek                tls_s1_connect  # peek at
>     TLS/SSL connect data
>     ssl_bump         splice                 tls_to_splice   # splice
>     some: no active bump
>     ssl_bump         stare                 all     # stare(peek) at server
>                                                             #
>     properties of the webserver
>     ssl_bump         bump                                    # bump if
>     we can (if the stare succeeded)
>
>     ssl_bump peek tls_s1_connect
>     ssl_bump splice all
>
>
>     #ssl_bump peek all
>     ############ssl_bump splice all
>
>
>     sslcrtd_program /usr/libexec/squid/security_file_certgen -s
>     /var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
>     sslcrtd_children 1 startup=1 idle=1
>
>     ssl_bump server-first all
>
>     sslproxy_cert_error allow all
>
>     #tls_outgoing_options
>     options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE
>     cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS
>
>     # Uncomment and adjust the following to add a disk cache directory.
>     # Updates: chrome and acrobat
>     #refresh_pattern -i gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)
>     <http://gvt1.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)>
>     43200 80% 129600 reload-into-ims
>     #refresh_pattern -i adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)
>     <http://adobe.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)>
>     43200 80% 129600 reload-into-ims
>
>
>
>     #range_offset_limit 200 MB
>     #maximum_object_size 200 MB
>     #quick_abort_min -1
>
>     # DONT MODIFY THESE LINES
>     #refresh_pattern \^ftp:           1440    20%     10080
>     #refresh_pattern \^gopher:        1440    0%      1440
>     #refresh_pattern -i (/cgi-bin/|\?) 0      0%      0
>     #refresh_pattern .                   0      20%     43200
>
>     cache_dir ufs /var/cache/squid 3000 16 256
>
>     # Leave coredumps in the first cache dir
>     coredump_dir /var/cache/squid
>
>     cache_mem 960 MB
>
>     netdb_filename none
>
>     logformat squidx %err_code/%err_detail
>     #access_log daemon:/var/log/squid/accessX.log squidx
>     #access_log squidx
>
>     #
>     # Add any of your own refresh_pattern entries above these.
>     #
>     refresh_pattern ^ftp:                1440    20%    10080
>     refresh_pattern ^gopher:            1440    0%    1440
>     refresh_pattern -i (/cgi-bin/|\?)     0        0%    0
>     refresh_pattern .                    0        20%    4320
>
>     url_rewrite_extras "%>a/%>A %un %>rm bump_mode=%ssl::bump_mode
>     sni=\"%ssl::>sni\" referer=\"%{Referer}>h\""
>     url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient -m 4 -l
>     /var/log/squid/
>     url_rewrite_children 16 startup=8 idle=2 concurrency=4 queue-size=64
>     #debug_options ALL,1 33,2 28,9
>
>>     HTH,
>>
>>     Alex. 
>
>     i finally noticed an empty sslcrtd.error.log file in /tmp created
>     on 20.07.2026, for some reason i was looking for a folder, stupid me.
>
>     i'm getting certificate errors when browsing sites in firefox.
>     some sites provide a warning to proceed to site (dangerous) other
>     sites just put 3 tab one of them is to see the certificate.
>
>     here is the cache.log:
>
>
>     2026/07/23 07:32:59 kid1| Processing Configuration File:
>     /etc/squid/squid.conf (depth 0)
>     2026/07/23 07:32:59 kid1| Set Current Directory to /var/cache/squid
>     2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6 for
>     x86_64-suse-linux-gnu...
>     2026/07/23 07:32:59 kid1| Service Name: squid
>     2026/07/23 07:32:59 kid1| Process ID 3183
>     2026/07/23 07:32:59 kid1| Process Roles: worker
>     2026/07/23 07:32:59 kid1| With 4096 file descriptors available
>     2026/07/23 07:32:59 kid1| Initializing IP Cache...
>     2026/07/23 07:32:59 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
>     2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46 from
>     /etc/resolv.conf
>     2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5 from
>     /etc/resolv.conf
>     2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1
>     'security_file_certgen' processes
>     2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16
>     'ufdbgclient' processes
>     2026/07/23 07:32:59 kid1| Logfile: opening log
>     daemon:/var/log/squid/access.log
>     2026/07/23 07:32:59 kid1| Logfile Daemon: opening log
>     /var/log/squid/access.log
>     2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31
>     2026/07/23 07:33:00 kid1| Local cache digest enabled;
>     rebuild/rewrite every 3600/3600 sec
>     2026/07/23 07:33:00 kid1| Store logging disabled
>     2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040 KB,
>     estimated 311926 objects
>     2026/07/23 07:33:00 kid1| Target number of buckets: 15596
>     2026/07/23 07:33:00 kid1| Using 16384 Store buckets
>     2026/07/23 07:33:00 kid1| Max Mem  size: 983040 KB
>     2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB
>     2026/07/23 07:33:00 kid1| Rebuilding storage in /var/cache/squid
>     (clean log)
>     2026/07/23 07:33:00 kid1| Using Least Load store dir selection
>     2026/07/23 07:33:00 kid1| Set Current Directory to /var/cache/squid
>     2026/07/23 07:33:00 kid1| Finished loading MIME types and icons.
>     2026/07/23 07:33:00 kid1| HTCP Disabled.
>     2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36
>     2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0
>     2026/07/23 07:33:00 kid1| Adaptation support is off.
>     2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket
>     connections at conn20 local=0.0.0.0:8080 <http://0.0.0.0:8080>
>     remote=[::] FD 34 flags=9
>         listening port: 8080
>     2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation. Detected
>     non-functional IPv6 loopback.
>     2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...
>     2026/07/23 07:33:00 pinger| ICMP socket opened.
>     2026/07/23 07:33:00 pinger| ICMPv6 socket opened
>     2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84% (4000 out
>     of 216863)
>     2026/07/23 07:33:03 kid1| Done reading /var/cache/squid swaplog
>     (216862 entries)
>     2026/07/23 07:33:03 kid1| Finished rebuilding storage from disk.
>          216862 Entries scanned
>               0 Invalid entries
>               0 With invalid flags
>          216862 Objects loaded
>               0 Objects expired
>               0 Objects canceled
>               0 Duplicate URLs purged
>               0 Swapfile clashes avoided
>         Took 3.16 seconds (68526.49 objects/sec).
>     2026/07/23 07:33:03 kid1| Beginning Validation Procedure
>     2026/07/23 07:33:03 kid1| Completed Validation Procedure
>         Validated 216848 Entries
>         store_swap_size = 2764352.00 KB
>     2026/07/23 07:33:03 kid1| storeLateRelease: released 0 objects
>     2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
>         problem: failure
>         error detail:
>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>         current master transaction: master58
>     2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
>         problem: failure
>         error detail:
>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>         current master transaction: master58
>     2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
>         problem: failure
>         error detail:
>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>         current master transaction: master58
>     .........
>
>
>>>>>     2026/07/17 08:17:35| Removing PID file (/run/squid.pid)
>>>>>     2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected
>>>>>     non-functional IPv6 loopback.
>>>>>     2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>>          acl name: to_localhost
>>>>>          configuration context: Default Configuration(15) acl
>>>>>     2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>>          acl name: to_localhost
>>>>>          configuration context: Default Configuration(15) acl
>>>>>     2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>>>          acl name: to_linklocal
>>>>>          configuration context: Default Configuration(16) acl
>>>>>     2026/07/17 08:18:54| Processing Configuration File:
>>>>>     /etc/squid/squid.conf (depth 0)
>>>>>     2026/07/17 08:18:55| Created PID file (/run/squid.pid)
>>>>>     2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation. Detected
>>>>>     non-functional IPv6 loopback.
>>>>>     2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been
>>>>>     enabled.
>>>>>          acl name: to_localhost
>>>>>          configuration context: Default Configuration(15) acl
>>>>>     2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been
>>>>>     enabled.
>>>>>          acl name: to_localhost
>>>>>          configuration context: Default Configuration(15) acl
>>>>>     2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been
>>>>>     enabled.
>>>>>          acl name: to_linklocal
>>>>>          configuration context: Default Configuration(16) acl
>>>>>     2026/07/17 08:18:55 kid1| Processing Configuration File:
>>>>>     /etc/squid/squid.conf (depth 0)
>>>>>     2026/07/17 08:18:55 kid1| Set Current Directory to
>>>>>     /var/cache/squid
>>>>>     2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6 for
>>>>>     x86_64-suse-linux-gnu...
>>>>>     2026/07/17 08:18:55 kid1| Service Name: squid
>>>>>     2026/07/17 08:18:55 kid1| Process ID 3685
>>>>>     2026/07/17 08:18:55 kid1| Process Roles: worker
>>>>>     2026/07/17 08:18:55 kid1| With 4096 file descriptors available
>>>>>     2026/07/17 08:18:55 kid1| Initializing IP Cache...
>>>>>     2026/07/17 08:18:55 kid1| DNS IPv4 socket created at 0.0.0.0,
>>>>>     FD 7
>>>>>     2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from
>>>>>     /etc/resolv.conf
>>>>>     2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from
>>>>>     /etc/resolv.conf
>>>>>     2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5
>>>>>     'security_file_certgen' processes
>>>>>     2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16
>>>>>     'ufdbgclient' processes
>>>>>     2026/07/17 08:18:55 kid1| Logfile: opening log
>>>>>     daemon:/var/log/squid/access.log
>>>>>     2026/07/17 08:18:55 kid1| Logfile Daemon: opening log
>>>>>     /var/log/squid/access.log
>>>>>     2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39
>>>>>     2026/07/17 08:18:56 kid1| Local cache digest enabled;
>>>>>     rebuild/rewrite every 3600/3600 sec
>>>>>     2026/07/17 08:18:56 kid1| Store logging disabled
>>>>>     2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB,
>>>>>     estimated 311926 objects
>>>>>     2026/07/17 08:18:56 kid1| Target number of buckets: 15596
>>>>>     2026/07/17 08:18:56 kid1| Using 16384 Store buckets
>>>>>     2026/07/17 08:18:56 kid1| Max Mem  size: 983040 KB
>>>>>     2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB
>>>>>     2026/07/17 08:18:56 kid1| Rebuilding storage in
>>>>>     /var/cache/squid (clean log)
>>>>>     2026/07/17 08:18:56 kid1| Using Least Load store dir selection
>>>>>     2026/07/17 08:18:56 kid1| Set Current Directory to
>>>>>     /var/cache/squid
>>>>>     2026/07/17 08:18:56 kid1| Finished loading MIME types and icons.
>>>>>     2026/07/17 08:18:56 kid1| HTCP Disabled.
>>>>>     2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44
>>>>>     2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0
>>>>>     2026/07/17 08:18:56 kid1| Adaptation support is off.
>>>>>     2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket
>>>>>     connections at conn28 local=0.0.0.0:8080 <http://0.0.0.0:8080>
>>>>>     remote=[::] FD 42 flags=9
>>>>>          listening port: 8080
>>>>>     2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation.
>>>>>     Detected non-functional IPv6 loopback.
>>>>>     2026/07/17 08:18:56 pinger| Initialising ICMP pinger ...
>>>>>     2026/07/17 08:18:56 pinger| ICMP socket opened.
>>>>>     2026/07/17 08:18:56 pinger| ICMPv6 socket opened
>>>>>     2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84% (4000
>>>>>     out of 217945)
>>>>>     2026/07/17 08:18:59 kid1| Done reading /var/cache/squid
>>>>>     swaplog (217944 entries)
>>>>>     2026/07/17 08:18:59 kid1| Finished rebuilding storage from disk.
>>>>>           217944 Entries scanned
>>>>>                0 Invalid entries
>>>>>                0 With invalid flags
>>>>>           217944 Objects loaded
>>>>>                0 Objects expired
>>>>>                0 Objects canceled
>>>>>                0 Duplicate URLs purged
>>>>>                0 Swapfile clashes avoided
>>>>>          Took 2.85 seconds (76435.29 objects/sec).
>>>>>     2026/07/17 08:18:59 kid1| Beginning Validation Procedure
>>>>>     2026/07/17 08:18:59 kid1| Completed Validation Procedure
>>>>>          Validated 217930 Entries
>>>>>          store_swap_size = 2764788.00 KB
>>>>>     2026/07/17 08:18:59 kid1| storeLateRelease: released 0 objects
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master55
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master55
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master55
>>>>>     2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>
>>>>>     ........
>>>>>
>>>>>     2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS connection
>>>>>          problem: failure
>>>>>          error detail:
>>>>>     SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes
>>>>>     are running (need 1/5)
>>>>>          active processes: 4
>>>>>          processes configured to start at (re)configuration: 5
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5
>>>>>     'security_file_certgen' processes
>>>>>          current master transaction: master57
>>>>>     2026/07/17 08:21:33 kid1| Preparing for shutdown after 761
>>>>>     requests
>>>>>     2026/07/17 08:21:33 kid1| Waiting 30 seconds for active
>>>>>     connections to finish
>>>>>     2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080
>>>>>     <http://0.0.0.0:8080>
>>>>>          listening port: 8080
>>>>>     2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44
>>>>>     2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite:
>>>>>     daemon:/var/log/squid/access.log: error writing ((32) Broken
>>>>>     pipe)
>>>>>          connection: conn2846 local=10.0.0.18:8080
>>>>>     <http://10.0.0.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs: Starting...
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1|     65536 entries written so far.
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1|    131072 entries written so far.
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1|    196608 entries written so far.
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1|   Finished.  Wrote 217944 entries.
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1|   Took 0.08 seconds (2736133.78
>>>>>     entries/sec).
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.16.0.7:53255
>>>>>     <http://10.16.0.7:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1| FATAL: I don't handle this error well!
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6):
>>>>>     Terminated abnormally.
>>>>>          connection: conn2846 local=10.10.10.18:8080
>>>>>     <http://10.10.10.18:8080> remote=10.1.0.17:53255
>>>>>     <http://10.1.0.17:53255> flags=1
>>>>>     CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
>>>>>     Maximum Resident Size: 314320 KB
>>>>>     Page faults with physical i/o: 0
>>>>>>
>>>>>>     To recreate a certificate database you should do:
>>>>>>
>>>>>>     sudo rm -rf /var/cache/squid/ssl_db
>>>>>>     sudo /usr/libexec/squid/security_file_certgen -c
>>>>>>     -s /var/cache/squid/ssl_db -M 4MB
>>>>>>     sudo chown -R squid:squid /var/cache/squid/ssl_db
>>>>>>
>>>>>>     чт, 16 июл. 2026 г. в 16:36, Alex Rousskov
>>>>>>     <[email protected]>
>>>>>>     <mailto:[email protected]>:
>>>>>>
>>>>>>         On 2026-07-16 01:57, Vacheslav wrote:
>>>>>>
>>>>>>         > 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program
>>>>>>     #Hlpr1 exited
>>>>>>
>>>>>>         We need to figure out why your security_file_certgen
>>>>>>     helpers are
>>>>>>         exiting. IIRC, those helpers have not been upgraded to
>>>>>>     report their
>>>>>>         fatal failures to cache.log. There are a few tricks you
>>>>>>     can use to
>>>>>>         see
>>>>>>         what the problem is, but I would probably start with
>>>>>>     these three:
>>>>>>
>>>>>>         1. Run security_file_certgen with sslcrtd_program
>>>>>>     parameters from the
>>>>>>         command line, as Squid user. If you are lucky, it will
>>>>>>     complain about
>>>>>>         something before it starts waiting for the helper request.
>>>>>>
>>>>>>         2. Redirect security_file_certgen stderr (but not
>>>>>>     stdout!) output
>>>>>>         into a
>>>>>>         dedicated log file. It may be possible to do that right
>>>>>>     on the
>>>>>>         sslcrtd_program line, without wrapping the helper into
>>>>>>     another script.
>>>>>>
>>>>>>         3. Enable full debugging, reproduce the problem with a
>>>>>>     single
>>>>>>         transaction, and send a link to the corresponding compressed
>>>>>>         cache.log
>>>>>>         file for analysis as detailed at
>>>>>>     https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction
>>>>>>
>>>>>>
>>>>>>
>>>>>>         Cheers,
>>>>>>
>>>>>>         Alex.
>>>>>>
>>>>>>     _______________________________________________
>>>>>>         squid-users mailing list
>>>>>>     [email protected]
>>>>>>     https://lists.squid-cache.org/listinfo/squid-users
>>>>>>
>>>>>
>>>>
>>>
>>
>
>     _______________________________________________
>     squid-users mailing list
>     [email protected]
>     https://lists.squid-cache.org/listinfo/squid-users
>

--------------MbtEixSrJshsMr0DldZG6dc7
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#26a269" bgcolor="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">23.07.2026 12:53, Andrey K пишет:<br>
    </div>
    <blockquote type="cite"
cite="mid:CADJd0Y0ww6v4o6Z2VTXiVxLvDgcXxzJztX-8cDkc9S=W=KddUA@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <div dir="ltr">Hello, Vacheslav,
          <div><br>
          </div>
          <div>It seems that the logs from 2026/07/23 no longer show any
            security_file_certgen crashes, but the browser errors are
            still there. Is it possible that the browsers are simply
            rejecting the new proxy certificate because it's not
            trusted?</div>
        </div>
      </div>
    </blockquote>
    even though i imported the new certificate, the browser was using
    the old certificate with the same certificate name, so i reissued
    the new der certificate and imported it into firefox and now it
    visible as the new certificate but the websites are not opening as
    they display a mixed certificate between the site and the squid
    certificate.<br>
    now the conf reconfigured is:<br>
    http_port 8080 ssl-bump  cert=/etc/squid/certs/squid-ca-cert-key.pem
    generate-host-certificates=on dynamic_cert_mem_cache_size=8MB<br>
    <br>
    <blockquote type="cite"
cite="mid:CADJd0Y0ww6v4o6Z2VTXiVxLvDgcXxzJztX-8cDkc9S=W=KddUA@mail.gmail.com">
      <div dir="ltr">
        <div dir="ltr">
          <div><br>
          </div>
        </div>
        <br>
        <div class="gmail_quote gmail_quote_container">
          <div dir="ltr" class="gmail_attr">On 23.07.2026 08:22,
            Vacheslav &lt;<a href="mailto:[email protected]"
              moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
            wrote:<br>
          </div>
          <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div bgcolor="#000000"> <br>
              <br>
              <div>20.07.2026 20:15, Alex Rousskov пишет:<br>
              </div>
              <blockquote type="cite">On 2026-07-20 01:27, Vacheslav
                wrote: <br>
                <blockquote type="cite">17.07.2026 15:44, Alex Rousskov
                  пишет: <br>
                  <blockquote type="cite">On 2026-07-17 01:31, Vacheslav
                    wrote: <br>
                    <br>
                    <blockquote type="cite">16.07.2026 18:19, Andrey K
                      пишет: <br>
                      <blockquote type="cite">@Vacheslav: <br>
                        &gt; sudo
                        /usr/libexec/squid/security_file_certgen -c -s <br>
                        &gt; /var/cache/squid/ssl_db/certs -M 4MB <br>
                        You specified the wrong path (the correct one is
                        /var/cache/squid/ssl_db ). <br>
                      </blockquote>
                      <br>
                      <br>
                      good catch: <br>
                      now running: <br>
                        sudo -u squid
                      /usr/libexec/squid/security_file_certgen -s
                      /var/cache/squid/ssl_db -M 4MB <br>
                      ^C <br>
                      produces nothing. <br>
                    </blockquote>
                    <br>
                    That lack of output is a good sign -- the helper
                    managed to start successfully. <br>
                    <br>
                    <br>
                    <blockquote type="cite">2026/07/17 08:21:33 kid1|
                      WARNING: sslcrtd_program #Hlpr1 exited <br>
                    </blockquote>
                    <br>
                    Helpers are still dying, but it looks like they do
                    it while handling traffic. <br>
                    <br>
                    <br>
                    <blockquote type="cite">
                      <blockquote type="cite">2. Redirect
                        security_file_certgen stderr (but not stdout!)
                        output <br>
                        into a dedicated log file. It may be possible to
                        do that right on <br>
                        the sslcrtd_program line, without wrapping the
                        helper into another <br>
                        script. <br>
                      </blockquote>
                    </blockquote>
                    <br>
                    <blockquote type="cite">how to do that? <br>
                    </blockquote>
                    <br>
                    Try using shell redirection when specifying how to
                    run the helper. Something along these lines may
                    work: <br>
                    <br>
                        sslcrtd_program /usr/local/... -M 4MB &gt;&gt;
                    /tmp/sslcrtd.error.log <br>
                  </blockquote>
                </blockquote>
                <br>
                <br>
                My bad. I missed "2" to redirect stderr rather than
                stdout. Fixed below. The missing file descriptor is
                _not_ the reason your test is not working though (as
                detailed below). <br>
                <br>
                <br>
                <blockquote type="cite">now the configuration looks like
                  this: <br>
                  <br>
                  sslcrtd_program
                  /usr/libexec/squid/security_file_certgen -s
                  /var/cache/squid/ssl_db -M 4MB &gt;&gt;
                  /tmp/sslcrtd.error.log <br>
                </blockquote>
                <br>
                <br>
                To capture stderr: <br>
                <br>
                sslcrtd_program /usr/libexec/squid/security_file_certgen
                -s <br>
                /var/cache/squid/ssl_db -M 4MB 2&gt;&gt;
                /tmp/sslcrtd.error.log <br>
                <br>
                <br>
                <blockquote type="cite">in tmp there is no
                  sslcrtd.error.log file. <br>
                </blockquote>
                <br>
                <br>
                AFAICT, your Squid does not start sslcrtd_program
                helper. What does "squid -v" say? If there is no
                '--enable-ssl-crtd' there, then you need to rebuild your
                Squid executable from scratch. Also, at least one
                http_port or https_port directive in your squid.conf
                should have both "generate-host-certificates" and
                "ssl-bump" options. <br>
              </blockquote>
              <br>
              sudo squid -v | grep "enable-ssl-crtd"<br>
              ........'--enable-arp-acl'
              '--enable-ssl-crtd'.............<br>
              <br>
              <blockquote type="cite">When done right, you should see
                the debugging file created in /tmp/ and, in cache log,
                Squid logging "Starting ..." lines mentioning your
                helper (similar to your existing lines for the
                ufdbgclient helper). <br>
              </blockquote>
              here is the configuration with the 8080 sslbump port open:<br>
              <br>
              <br>
              forwarded_for delete<br>
              <br>
              delay_pools 1<br>
              delay_class 1 3<br>
              delay_access 1 allow slower<br>
              delay_access 1 deny all<br>
              delay_parameters 1 128000/128000 -1/-1 128000/64000<br>
              <br>
              http_access allow localnet <br>
              http_access allow localhost<br>
              <br>
              <br>
              <br>
              # And finally deny all other access to this proxy<br>
              http_access deny all<br>
              <br>
              # Squid normally listens to port 3128<br>
              #http_port 8080<br>
              <br>
              <br>
              <br>
              http_port 8080 ssl-bump  cert=/etc/squid/certs/myCA.pem
              generate-host-certificates=on
              dynamic_cert_mem_cache_size=8MB<br>
              <br>
              <br>
              <br>
              <br>
              ##acl step1 at_step SslBump1                       <br>
              ##ssl_bump peek step1                       <br>
              ##ssl_bump bump all<br>
              <br>
              ##sslcrtd_program /usr/libexec/squid/security_file_certgen
              -s /var/lib/squid/ssl_db -M 4MB<br>
              ##sslcrtd_children 5<br>
              <br>
              acl     tls_s1_connect            at_step SslBump1<br>
              acl     tls_s2_client_hello     at_step SslBump2<br>
              acl     tls_s3_server_hello     at_step SslBump3<br>
              <br>
              # define acls for sites that must not be actively bumped<br>
              <br>
              acl     tls_allowed_hsts        ssl::server_name         
                 .<a href="http://akamaihd.net" target="_blank"
                moz-do-not-send="true">akamaihd.net</a><br>
              acl     tls_allowed_hsts        ssl::server_name         
                 .<a href="http://proxy.skko.by" target="_blank"
                moz-do-not-send="true">proxy.skko.by</a><br>
              #acl     tls_server_is_bank         ssl::server_name     
                     .<a href="http://abnamro.nl" target="_blank"
                moz-do-not-send="true">abnamro.nl</a><br>
              #acl     tls_server_is_bank         ssl::server_name     
                     .<a href="http://abnamro.com" target="_blank"
                moz-do-not-send="true">abnamro.com</a><br>
              acl     tls_server_is_bank         ssl::server_name       
                 
              "/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"<br>
              acl     tls_to_splice             any-of                 
                     tls_allowed_hsts        tls_server_is_bank<br>
              <br>
              # TLS/SSL bumping steps<br>
              <br>
              ssl_bump         peek                tls_s1_connect       
               # peek at TLS/SSL connect data<br>
              ssl_bump         splice                 tls_to_splice     
                # splice some: no active bump<br>
              ssl_bump         stare                 all               
                  # stare(peek) at server<br>
                                                                      #
              properties of the webserver<br>
              ssl_bump         bump                                    #
              bump if we can (if the stare succeeded)<br>
              <br>
              ssl_bump peek tls_s1_connect<br>
              ssl_bump splice all<br>
              <br>
              <br>
              #ssl_bump peek all<br>
              ############ssl_bump splice all<br>
              <br>
              <br>
              sslcrtd_program /usr/libexec/squid/security_file_certgen
              -s /var/cache/squid/ssl_db -M 4MB 2&gt;&gt;
              /tmp/sslcrtd.error.log<br>
              sslcrtd_children 1 startup=1 idle=1<br>
              <br>
              ssl_bump server-first all<br>
              <br>
              sslproxy_cert_error allow all<br>
              <br>
              #tls_outgoing_options
              options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE
cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS<br>
              <br>
              # Uncomment and adjust the following to add a disk cache
              directory.<br>
              # Updates: chrome and acrobat<br>
              #refresh_pattern -i <a
href="http://gvt1.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)"
                target="_blank" moz-do-not-send="true">gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)</a>
              43200 80% 129600 reload-into-ims<br>
              #refresh_pattern -i <a
href="http://adobe.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)"
                target="_blank" moz-do-not-send="true">adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)</a>
              43200 80% 129600 reload-into-ims<br>
              <br>
                            <br>
              <br>
              #range_offset_limit 200 MB <br>
              #maximum_object_size 200 MB<br>
              #quick_abort_min -1<br>
              <br>
              # DONT MODIFY THESE LINES<br>
              #refresh_pattern \^ftp:           1440    20%     10080<br>
              #refresh_pattern \^gopher:        1440    0%      1440<br>
              #refresh_pattern -i (/cgi-bin/|\?) 0      0%      0<br>
              #refresh_pattern .                   0      20%     43200<br>
              <br>
              cache_dir ufs /var/cache/squid 3000 16 256<br>
              <br>
              # Leave coredumps in the first cache dir<br>
              coredump_dir /var/cache/squid<br>
              <br>
              cache_mem 960 MB<br>
              <br>
              netdb_filename none<br>
              <br>
              logformat squidx %err_code/%err_detail<br>
              #access_log daemon:/var/log/squid/accessX.log squidx<br>
              #access_log squidx<br>
              <br>
              #<br>
              # Add any of your own refresh_pattern entries above these.<br>
              #<br>
              refresh_pattern ^ftp:                1440    20%    10080<br>
              refresh_pattern ^gopher:            1440    0%    1440<br>
              refresh_pattern -i (/cgi-bin/|\?)     0        0%    0<br>
              refresh_pattern .                    0        20%    4320<br>
              <br>
              url_rewrite_extras "%&gt;a/%&gt;A %un %&gt;rm
              bump_mode=%ssl::bump_mode sni=\"%ssl::&gt;sni\"
              referer=\"%{Referer}&gt;h\""<br>
              url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient
              -m 4 -l /var/log/squid/<br>
              url_rewrite_children 16 startup=8 idle=2 concurrency=4
              queue-size=64<br>
              #debug_options ALL,1 33,2 28,9<br>
              <br>
              <blockquote type="cite">HTH, <br>
                <br>
                Alex. </blockquote>
              <br>
              i finally noticed an empty sslcrtd.error.log file in /tmp
              created on 20.07.2026, for some reason i was looking for a
              folder, stupid me.<br>
              <br>
              i'm getting certificate errors when browsing sites in
              firefox. some sites provide a warning to proceed to site
              (dangerous) other sites just put 3 tab one of them is to
              see the certificate.<br>
              <br>
              here is the cache.log:<br>
              <br>
              <br>
              2026/07/23 07:32:59 kid1| Processing Configuration File:
              /etc/squid/squid.conf (depth 0)<br>
              2026/07/23 07:32:59 kid1| Set Current Directory to
              /var/cache/squid<br>
              2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6
              for x86_64-suse-linux-gnu...<br>
              2026/07/23 07:32:59 kid1| Service Name: squid<br>
              2026/07/23 07:32:59 kid1| Process ID 3183<br>
              2026/07/23 07:32:59 kid1| Process Roles: worker<br>
              2026/07/23 07:32:59 kid1| With 4096 file descriptors
              available<br>
              2026/07/23 07:32:59 kid1| Initializing IP Cache...<br>
              2026/07/23 07:32:59 kid1| DNS IPv4 socket created at
              0.0.0.0, FD 7<br>
              2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46
              from /etc/resolv.conf<br>
              2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5
              from /etc/resolv.conf<br>
              2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1
              'security_file_certgen' processes<br>
              2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16
              'ufdbgclient' processes<br>
              2026/07/23 07:32:59 kid1| Logfile: opening log
              daemon:/var/log/squid/access.log<br>
              2026/07/23 07:32:59 kid1| Logfile Daemon: opening log
              /var/log/squid/access.log<br>
              2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31<br>
              2026/07/23 07:33:00 kid1| Local cache digest enabled;
              rebuild/rewrite every 3600/3600 sec<br>
              2026/07/23 07:33:00 kid1| Store logging disabled<br>
              2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040
              KB, estimated 311926 objects<br>
              2026/07/23 07:33:00 kid1| Target number of buckets: 15596<br>
              2026/07/23 07:33:00 kid1| Using 16384 Store buckets<br>
              2026/07/23 07:33:00 kid1| Max Mem  size: 983040 KB<br>
              2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB<br>
              2026/07/23 07:33:00 kid1| Rebuilding storage in
              /var/cache/squid (clean log)<br>
              2026/07/23 07:33:00 kid1| Using Least Load store dir
              selection<br>
              2026/07/23 07:33:00 kid1| Set Current Directory to
              /var/cache/squid<br>
              2026/07/23 07:33:00 kid1| Finished loading MIME types and
              icons.<br>
              2026/07/23 07:33:00 kid1| HTCP Disabled.<br>
              2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36<br>
              2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0<br>
              2026/07/23 07:33:00 kid1| Adaptation support is off.<br>
              2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket
              connections at conn20 local=<a href="http://0.0.0.0:8080"
                target="_blank" moz-do-not-send="true">0.0.0.0:8080</a>
              remote=[::] FD 34 flags=9<br>
                  listening port: 8080<br>
              2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation.
              Detected non-functional IPv6 loopback.<br>
              2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...<br>
              2026/07/23 07:33:00 pinger| ICMP socket opened.<br>
              2026/07/23 07:33:00 pinger| ICMPv6 socket opened<br>
              2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84%
              (4000 out of 216863)<br>
              2026/07/23 07:33:03 kid1| Done reading /var/cache/squid
              swaplog (216862 entries)<br>
              2026/07/23 07:33:03 kid1| Finished rebuilding storage from
              disk.<br>
                   216862 Entries scanned<br>
                        0 Invalid entries<br>
                        0 With invalid flags<br>
                   216862 Objects loaded<br>
                        0 Objects expired<br>
                        0 Objects canceled<br>
                        0 Duplicate URLs purged<br>
                        0 Swapfile clashes avoided<br>
                  Took 3.16 seconds (68526.49 objects/sec).<br>
              2026/07/23 07:33:03 kid1| Beginning Validation Procedure<br>
              2026/07/23 07:33:03 kid1| Completed Validation Procedure<br>
                  Validated 216848 Entries<br>
                  store_swap_size = 2764352.00 KB<br>
              2026/07/23 07:33:03 kid1| storeLateRelease: released 0
              objects<br>
              2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
              connection<br>
                  problem: failure<br>
                  error detail:
              SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1<br>
                  current master transaction: master58<br>
              2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
              connection<br>
                  problem: failure<br>
                  error detail:
              SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
                  current master transaction: master58<br>
              2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
              connection<br>
                  problem: failure<br>
                  error detail:
              SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
                  current master transaction: master58<br>
              .........<br>
              <br>
              <br>
              <blockquote type="cite">
                <blockquote type="cite">
                  <blockquote type="cite">
                    <blockquote type="cite">2026/07/17 08:17:35|
                      Removing PID file (/run/squid.pid) <br>
                      2026/07/17 08:18:54| WARNING: BCP 177 violation.
                      Detected non-functional IPv6 loopback. <br>
                      2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
                      not been enabled. <br>
                           acl name: to_localhost <br>
                           configuration context: Default
                      Configuration(15) acl <br>
                      2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
                      not been enabled. <br>
                           acl name: to_localhost <br>
                           configuration context: Default
                      Configuration(15) acl <br>
                      2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
                      not been enabled. <br>
                           acl name: to_linklocal <br>
                           configuration context: Default
                      Configuration(16) acl <br>
                      2026/07/17 08:18:54| Processing Configuration
                      File: /etc/squid/squid.conf (depth 0) <br>
                      2026/07/17 08:18:55| Created PID file
                      (/run/squid.pid) <br>
                      2026/07/17 08:18:55 kid1| WARNING: BCP 177
                      violation. Detected non-functional IPv6 loopback.
                      <br>
                      2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
                      has not been enabled. <br>
                           acl name: to_localhost <br>
                           configuration context: Default
                      Configuration(15) acl <br>
                      2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
                      has not been enabled. <br>
                           acl name: to_localhost <br>
                           configuration context: Default
                      Configuration(15) acl <br>
                      2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
                      has not been enabled. <br>
                           acl name: to_linklocal <br>
                           configuration context: Default
                      Configuration(16) acl <br>
                      2026/07/17 08:18:55 kid1| Processing Configuration
                      File: /etc/squid/squid.conf (depth 0) <br>
                      2026/07/17 08:18:55 kid1| Set Current Directory to
                      /var/cache/squid <br>
                      2026/07/17 08:18:55 kid1| Starting Squid Cache
                      version 7.6 for x86_64-suse-linux-gnu... <br>
                      2026/07/17 08:18:55 kid1| Service Name: squid <br>
                      2026/07/17 08:18:55 kid1| Process ID 3685 <br>
                      2026/07/17 08:18:55 kid1| Process Roles: worker <br>
                      2026/07/17 08:18:55 kid1| With 4096 file
                      descriptors available <br>
                      2026/07/17 08:18:55 kid1| Initializing IP Cache...
                      <br>
                      2026/07/17 08:18:55 kid1| DNS IPv4 socket created
                      at 0.0.0.0, FD 7 <br>
                      2026/07/17 08:18:55 kid1| Adding nameserver
                      10.6.30.40 from /etc/resolv.conf <br>
                      2026/07/17 08:18:55 kid1| Adding nameserver
                      10.10.10.5 from /etc/resolv.conf <br>
                      2026/07/17 08:18:55 kid1| helperOpenServers:
                      Starting 5/5 'security_file_certgen' processes <br>
                      2026/07/17 08:18:55 kid1| helperOpenServers:
                      Starting 8/16 'ufdbgclient' processes <br>
                      2026/07/17 08:18:55 kid1| Logfile: opening log
                      daemon:/var/log/squid/access.log <br>
                      2026/07/17 08:18:55 kid1| Logfile Daemon: opening
                      log /var/log/squid/access.log <br>
                      2026/07/17 08:18:56 kid1| Unlinkd pipe opened on
                      FD 39 <br>
                      2026/07/17 08:18:56 kid1| Local cache digest
                      enabled; rebuild/rewrite every 3600/3600 sec <br>
                      2026/07/17 08:18:56 kid1| Store logging disabled <br>
                      2026/07/17 08:18:56 kid1| Swap maxSize 3072000 +
                      983040 KB, estimated 311926 objects <br>
                      2026/07/17 08:18:56 kid1| Target number of
                      buckets: 15596 <br>
                      2026/07/17 08:18:56 kid1| Using 16384 Store
                      buckets <br>
                      2026/07/17 08:18:56 kid1| Max Mem  size: 983040 KB
                      <br>
                      2026/07/17 08:18:56 kid1| Max Swap size: 3072000
                      KB <br>
                      2026/07/17 08:18:56 kid1| Rebuilding storage in
                      /var/cache/squid (clean log) <br>
                      2026/07/17 08:18:56 kid1| Using Least Load store
                      dir selection <br>
                      2026/07/17 08:18:56 kid1| Set Current Directory to
                      /var/cache/squid <br>
                      2026/07/17 08:18:56 kid1| Finished loading MIME
                      types and icons. <br>
                      2026/07/17 08:18:56 kid1| HTCP Disabled. <br>
                      2026/07/17 08:18:56 kid1| Pinger socket opened on
                      FD 44 <br>
                      2026/07/17 08:18:56 kid1| Squid plugin modules
                      loaded: 0 <br>
                      2026/07/17 08:18:56 kid1| Adaptation support is
                      off. <br>
                      2026/07/17 08:18:56 kid1| Accepting SSL bumped
                      HTTP Socket connections at conn28 local=<a
                        href="http://0.0.0.0:8080" target="_blank"
                        moz-do-not-send="true">0.0.0.0:8080</a>
                      remote=[::] FD 42 flags=9 <br>
                           listening port: 8080 <br>
                      2026/07/17 08:18:56 pinger| WARNING: BCP 177
                      violation. Detected non-functional IPv6 loopback.
                      <br>
                      2026/07/17 08:18:56 pinger| Initialising ICMP
                      pinger ... <br>
                      2026/07/17 08:18:56 pinger| ICMP socket opened. <br>
                      2026/07/17 08:18:56 pinger| ICMPv6 socket opened <br>
                      2026/07/17 08:18:56 kid1| Indexing cache entries:
                      1.84% (4000 out of 217945) <br>
                      2026/07/17 08:18:59 kid1| Done reading
                      /var/cache/squid swaplog (217944 entries) <br>
                      2026/07/17 08:18:59 kid1| Finished rebuilding
                      storage from disk. <br>
                            217944 Entries scanned <br>
                                 0 Invalid entries <br>
                                 0 With invalid flags <br>
                            217944 Objects loaded <br>
                                 0 Objects expired <br>
                                 0 Objects canceled <br>
                                 0 Duplicate URLs purged <br>
                                 0 Swapfile clashes avoided <br>
                           Took 2.85 seconds (76435.29 objects/sec). <br>
                      2026/07/17 08:18:59 kid1| Beginning Validation
                      Procedure <br>
                      2026/07/17 08:18:59 kid1| Completed Validation
                      Procedure <br>
                           Validated 217930 Entries <br>
                           store_swap_size = 2764788.00 KB <br>
                      2026/07/17 08:18:59 kid1| storeLateRelease:
                      released 0 objects <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master55 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master55 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master55 <br>
                      2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      <br>
                      ........ <br>
                      <br>
                      2026/07/17 08:21:32 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:32 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:33 kid1| ERROR: Cannot accept a
                      TLS connection <br>
                           problem: failure <br>
                           error detail:
                      SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
                      <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program
                      #Hlpr1 exited <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:33 kid1| Too few sslcrtd_program
                      processes are running (need 1/5) <br>
                           active processes: 4 <br>
                           processes configured to start at
                      (re)configuration: 5 <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:33 kid1| helperOpenServers:
                      Starting 1/5 'security_file_certgen' processes <br>
                           current master transaction: master57 <br>
                      2026/07/17 08:21:33 kid1| Preparing for shutdown
                      after 761 requests <br>
                      2026/07/17 08:21:33 kid1| Waiting 30 seconds for
                      active connections to finish <br>
                      2026/07/17 08:21:33 kid1| Closing HTTP(S) port <a
                        href="http://0.0.0.0:8080" target="_blank"
                        moz-do-not-send="true">0.0.0.0:8080</a> <br>
                           listening port: 8080 <br>
                      2026/07/17 08:21:33 kid1| Closing Pinger socket on
                      FD 44 <br>
                      2026/07/17 08:21:33 kid1| ERROR:
                      logfileHandleWrite:
                      daemon:/var/log/squid/access.log: error writing
                      ((32) Broken pipe) <br>
                           connection: conn2846 local=<a
                        href="http://10.0.0.18:8080" target="_blank"
                        moz-do-not-send="true">10.0.0.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs:
                      Starting... <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1|     65536 entries
                      written so far. <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1|    131072 entries
                      written so far. <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1|    196608 entries
                      written so far. <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1|   Finished.  Wrote
                      217944 entries. <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1|   Took 0.08 seconds
                      (2736133.78 entries/sec). <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.16.0.7:53255"
                        target="_blank" moz-do-not-send="true">10.16.0.7:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1| FATAL: I don't handle
                      this error well! <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      2026/07/17 08:21:33 kid1| Squid Cache (Version
                      7.6): Terminated abnormally. <br>
                           connection: conn2846 local=<a
                        href="http://10.10.10.18:8080" target="_blank"
                        moz-do-not-send="true">10.10.10.18:8080</a>
                      remote=<a href="http://10.1.0.17:53255"
                        target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
                      flags=1 <br>
                      CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
                      <br>
                      Maximum Resident Size: 314320 KB <br>
                      Page faults with physical i/o: 0 <br>
                      <blockquote type="cite"> <br>
                        To recreate a certificate database you should
                        do: <br>
                        <br>
                        sudo rm -rf /var/cache/squid/ssl_db <br>
                        sudo /usr/libexec/squid/security_file_certgen -c
                        -s /var/cache/squid/ssl_db -M 4MB <br>
                        sudo chown -R squid:squid
                        /var/cache/squid/ssl_db <br>
                        <br>
                        чт, 16 июл. 2026 г. в 16:36, Alex Rousskov <a
                          href="mailto:[email protected]"
                          target="_blank" moz-do-not-send="true">&lt;[email protected]&gt;</a>:
                        <br>
                        <br>
                            On 2026-07-16 01:57, Vacheslav wrote: <br>
                        <br>
                            &gt; 2026/07/16 08:34:24 kid1| WARNING:
                        sslcrtd_program #Hlpr1 exited <br>
                        <br>
                            We need to figure out why your
                        security_file_certgen helpers are <br>
                            exiting. IIRC, those helpers have not been
                        upgraded to report their <br>
                            fatal failures to cache.log. There are a few
                        tricks you can use to <br>
                            see <br>
                            what the problem is, but I would probably
                        start with these three: <br>
                        <br>
                            1. Run security_file_certgen with
                        sslcrtd_program parameters from the <br>
                            command line, as Squid user. If you are
                        lucky, it will complain about <br>
                            something before it starts waiting for the
                        helper request. <br>
                        <br>
                            2. Redirect security_file_certgen stderr
                        (but not stdout!) output <br>
                            into a <br>
                            dedicated log file. It may be possible to do
                        that right on the <br>
                            sslcrtd_program line, without wrapping the
                        helper into another script. <br>
                        <br>
                            3. Enable full debugging, reproduce the
                        problem with a single <br>
                            transaction, and send a link to the
                        corresponding compressed <br>
                            cache.log <br>
                            file for analysis as detailed at <br>
                        <a
href="https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction"
                          target="_blank" moz-do-not-send="true"
                          class="moz-txt-link-freetext">https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction</a>
                        <br>
                        <br>
                        <br>
                            Cheers, <br>
                        <br>
                            Alex. <br>
                        <br>
                           
                        _______________________________________________
                        <br>
                            squid-users mailing list <br>
                        <a
href="mailto:[email protected]" target="_blank"
                          moz-do-not-send="true"
                          class="moz-txt-link-freetext">[email protected]</a>
                        <br>
                        <a
href="https://lists.squid-cache.org/listinfo/squid-users"
                          target="_blank" moz-do-not-send="true"
                          class="moz-txt-link-freetext">https://lists.squid-cache.org/listinfo/squid-users</a>
                        <br>
                        <br>
                      </blockquote>
                      <br>
                    </blockquote>
                    <br>
                  </blockquote>
                  <br>
                </blockquote>
                <br>
              </blockquote>
              <br>
            </div>
            _______________________________________________<br>
            squid-users mailing list<br>
            <a href="mailto:[email protected]"
              target="_blank" moz-do-not-send="true"
              class="moz-txt-link-freetext">[email protected]</a><br>
            <a href="https://lists.squid-cache.org/listinfo/squid-users"
              rel="noreferrer" target="_blank" moz-do-not-send="true"
              class="moz-txt-link-freetext">https://lists.squid-cache.org/listinfo/squid-users</a><br>
          </blockquote>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>

--------------MbtEixSrJshsMr0DldZG6dc7--

--===============2770530707340702711==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============2770530707340702711==--