Re: ssl bump

Vacheslav <[email protected]> Mon, 27 Jul 2026 07:54:22 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============1629463494313426844==
Content-Type: multipart/alternative;
 boundary="------------MRWoZxqSUrY5A6zpsjHrvZT0"
Content-Language: en-US, ru-RU

This is a multi-part message in MIME format.
--------------MRWoZxqSUrY5A6zpsjHrvZT0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit



24.07.2026 16:08, Alex Rousskov пишет:
> On 2026-07-23 07:38, Vacheslav wrote:
>>
>>
>> 23.07.2026 12:53, Andrey K пишет:
>>> It seems that the logs from 2026/07/23 no longer show any 
>>> security_file_certgen crashes,
>
> I also assume that sslcrtd_program helpers no longer exit.
>
>
>>> but the browser errors are still there. Is it possible that the 
>>> browsers are simply rejecting the new proxy certificate because it's 
>>> not trusted?
>
>> even though i imported the new certificate, the browser was using the 
>> old certificate with the same certificate name, so i reissued the new 
>> der certificate and imported it into firefox and now it visible as 
>> the new certificate but the websites are not opening as they display 
>> a mixed certificate between the site and the squid certificate.
>
> In a working setup, we expect:
>
> A) A browser receiving a site certificate generated by Squid.
>    This site certificate (A) is signed by CA certificate (B).
>
> B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem
>    Squid http_port configured to use certificate (B).
>    Browser configured to trust certificate (B).
>
>
> How does the above differ from what you observe?
>
> Alex.

i'm getting in firefox Код ошибки: SEC_ERROR_UNKNOWN_ISSUER
i had trusted squid-ca-cert.der in firefox and now i tried to trust 
squid-ca-cert-key.pem but it complained that it is already trusted.
>
>
>> now the conf reconfigured is:
>> http_port 8080 ssl-bump cert=/etc/squid/certs/squid-ca-cert-key.pem 
>> generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
>
>
>

--------------MRWoZxqSUrY5A6zpsjHrvZT0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#26a269" bgcolor="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">24.07.2026 16:08, Alex Rousskov пишет:<br>
    </div>
    <blockquote type="cite"
cite="mid:[email protected]">On
      2026-07-23 07:38, Vacheslav wrote:
      <br>
      <blockquote type="cite">
        <br>
        <br>
        23.07.2026 12:53, Andrey K пишет:
        <br>
        <blockquote type="cite">It seems that the logs from 2026/07/23
          no longer show any security_file_certgen crashes,
          <br>
        </blockquote>
      </blockquote>
      <br>
      I also assume that sslcrtd_program helpers no longer exit.
      <br>
      <br>
      <br>
      <blockquote type="cite">
        <blockquote type="cite">but the browser errors are still there.
          Is it possible that the browsers are simply rejecting the new
          proxy certificate because it's not trusted?
          <br>
        </blockquote>
      </blockquote>
      <br>
      <blockquote type="cite">even though i imported the new
        certificate, the browser was using the old certificate with the
        same certificate name, so i reissued the new der certificate and
        imported it into firefox and now it visible as the new
        certificate but the websites are not opening as they display a
        mixed certificate between the site and the squid certificate.
        <br>
      </blockquote>
      <br>
      In a working setup, we expect:
      <br>
      <br>
      A) A browser receiving a site certificate generated by Squid.
      <br>
         This site certificate (A) is signed by CA certificate (B).
      <br>
      <br>
      B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem
      <br>
         Squid http_port configured to use certificate (B).
      <br>
         Browser configured to trust certificate (B).
      <br>
      <br>
      <br>
      How does the above differ from what you observe?
      <br>
      <br>
      Alex. <br>
    </blockquote>
    <br>
    i'm getting in firefox <a id="errorCode"
      data-l10n-id="fp-cert-error-code" data-l10n-name="error-code-link"
      data-telemetry-id="error_code_link"
data-l10n-args="{&quot;error&quot;: &quot;SEC_ERROR_UNKNOWN_ISSUER&quot;}">Код
      ошибки: SEC_ERROR_UNKNOWN_ISSUER<br>
      i had trusted squid-ca-cert.der in firefox and now i tried to
      trust squid-ca-cert-key.pem but it complained that it is already
      trusted.</a>
    <blockquote type="cite"
cite="mid:[email protected]"><br>
      <br>
      <blockquote type="cite">now the conf reconfigured is:
        <br>
        http_port 8080 ssl-bump 
        cert=/etc/squid/certs/squid-ca-cert-key.pem
        generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
        <br>
      </blockquote>
      <br>
      <br>
      <br>
    </blockquote>
    <br>
  </body>
</html>

--------------MRWoZxqSUrY5A6zpsjHrvZT0--

--===============1629463494313426844==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============1629463494313426844==--