Re: ssl bump
Vacheslav <[email protected]> Mon, 27 Jul 2026 07:57:34 +0300
| Newsgroups | gmane.comp.web.squid.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============1737385847172722559== Content-Type: multipart/alternative; boundary="------------5M9SUeZpKeuukNsoJei50lEE" Content-Language: en-US, ru-RU This is a multi-part message in MIME format. --------------5M9SUeZpKeuukNsoJei50lEE Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit 27.07.2026 07:54, Vacheslav пишет: > > > 24.07.2026 16:08, Alex Rousskov пишет: >> On 2026-07-23 07:38, Vacheslav wrote: >>> >>> >>> 23.07.2026 12:53, Andrey K пишет: >>>> It seems that the logs from 2026/07/23 no longer show any >>>> security_file_certgen crashes, >> >> I also assume that sslcrtd_program helpers no longer exit. >> >> >>>> but the browser errors are still there. Is it possible that the >>>> browsers are simply rejecting the new proxy certificate because >>>> it's not trusted? >> >>> even though i imported the new certificate, the browser was using >>> the old certificate with the same certificate name, so i reissued >>> the new der certificate and imported it into firefox and now it >>> visible as the new certificate but the websites are not opening as >>> they display a mixed certificate between the site and the squid >>> certificate. >> >> In a working setup, we expect: >> >> A) A browser receiving a site certificate generated by Squid. >> This site certificate (A) is signed by CA certificate (B). >> >> B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem >> Squid http_port configured to use certificate (B). >> Browser configured to trust certificate (B). >> >> >> How does the above differ from what you observe? >> >> Alex. > > i'm getting in firefox Код ошибки: SEC_ERROR_UNKNOWN_ISSUER > i had trusted squid-ca-cert.der in firefox and now i tried to trust > squid-ca-cert-key.pem but it complained that it is already trusted. some sites are opening while others complain of SEC_ERROR_UNKNOWN_ISSUER like linkedin and hotmail >> >> >>> now the conf reconfigured is: >>> http_port 8080 ssl-bump cert=/etc/squid/certs/squid-ca-cert-key.pem >>> generate-host-certificates=on dynamic_cert_mem_cache_size=8MB >> >> >> > > > _______________________________________________ > squid-users mailing list > [email protected] > https://lists.squid-cache.org/listinfo/squid-users --------------5M9SUeZpKeuukNsoJei50lEE Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body text="#26a269" bgcolor="#000000"> <br> <br> <div class="moz-cite-prefix">27.07.2026 07:54, Vacheslav пишет:<br> </div> <blockquote type="cite" cite="mid:[email protected]"> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <br> <br> <div class="moz-cite-prefix">24.07.2026 16:08, Alex Rousskov пишет:<br> </div> <blockquote type="cite" cite="mid:[email protected]">On 2026-07-23 07:38, Vacheslav wrote: <br> <blockquote type="cite"> <br> <br> 23.07.2026 12:53, Andrey K пишет: <br> <blockquote type="cite">It seems that the logs from 2026/07/23 no longer show any security_file_certgen crashes, <br> </blockquote> </blockquote> <br> I also assume that sslcrtd_program helpers no longer exit. <br> <br> <br> <blockquote type="cite"> <blockquote type="cite">but the browser errors are still there. Is it possible that the browsers are simply rejecting the new proxy certificate because it's not trusted? <br> </blockquote> </blockquote> <br> <blockquote type="cite">even though i imported the new certificate, the browser was using the old certificate with the same certificate name, so i reissued the new der certificate and imported it into firefox and now it visible as the new certificate but the websites are not opening as they display a mixed certificate between the site and the squid certificate. <br> </blockquote> <br> In a working setup, we expect: <br> <br> A) A browser receiving a site certificate generated by Squid. <br> This site certificate (A) is signed by CA certificate (B). <br> <br> B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem <br> Squid http_port configured to use certificate (B). <br> Browser configured to trust certificate (B). <br> <br> <br> How does the above differ from what you observe? <br> <br> Alex. <br> </blockquote> <br> i'm getting in firefox <a id="errorCode" data-l10n-id="fp-cert-error-code" data-l10n-name="error-code-link" data-telemetry-id="error_code_link" data-l10n-args="{"error": "SEC_ERROR_UNKNOWN_ISSUER"}" moz-do-not-send="true">Код ошибки: SEC_ERROR_UNKNOWN_ISSUER<br> i had trusted squid-ca-cert.der in firefox and now i tried to trust squid-ca-cert-key.pem but it complained that it is already trusted.</a></blockquote> <br> some sites are opening while others complain of <a id="errorCode" data-l10n-id="fp-cert-error-code" data-l10n-name="error-code-link" data-telemetry-id="error_code_link" data-l10n-args="{"error": "SEC_ERROR_UNKNOWN_ISSUER"}">SEC_ERROR_UNKNOWN_ISSUER like linkedin and hotmail</a> <blockquote type="cite" cite="mid:[email protected]"> <blockquote type="cite" cite="mid:[email protected]"><br> <br> <blockquote type="cite">now the conf reconfigured is: <br> http_port 8080 ssl-bump cert=/etc/squid/certs/squid-ca-cert-key.pem generate-host-certificates=on dynamic_cert_mem_cache_size=8MB <br> </blockquote> <br> <br> <br> </blockquote> <br> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <pre wrap="" class="moz-quote-pre">_______________________________________________ squid-users mailing list <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <a class="moz-txt-link-freetext" href="https://lists.squid-cache.org/listinfo/squid-users">https://lists.squid-cache.org/listinfo/squid-users</a> </pre> </blockquote> <br> </body> </html> --------------5M9SUeZpKeuukNsoJei50lEE-- --===============1737385847172722559== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ squid-users mailing list [email protected] https://lists.squid-cache.org/listinfo/squid-users --===============1737385847172722559==--