Re: ssl bump

Vacheslav <[email protected]> Thu, 30 Jul 2026 08:34:15 +0300
Newsgroups gmane.comp.web.squid.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2119058714267395019==
Content-Type: multipart/alternative;
 boundary="------------QzIr5Ua7zPjSu6ookJau0hFm"
Content-Language: en-US, ru-RU

This is a multi-part message in MIME format.
--------------QzIr5Ua7zPjSu6ookJau0hFm
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit



28.07.2026 15:44, Alex Rousskov пишет:
> On 2026-07-27 00:57, Vacheslav wrote:
>> 27.07.2026 07:54, Vacheslav пишет:
>>> 24.07.2026 16:08, Alex Rousskov пишет:
>>>> In a working setup, we expect:
>>>>
>>>> A) A browser receiving a site certificate generated by Squid.
>>>>    This site certificate (A) is signed by CA certificate (B).
>>>>
>>>> B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem
>>>>    Squid http_port configured to use certificate (B).
>>>>    Browser configured to trust certificate (B).
>>>>
>>>>
>>>> How does the above differ from what you observe?
>
>>> i'm getting in firefox Код ошибки: SEC_ERROR_UNKNOWN_ISSUER
>>> i had trusted squid-ca-cert.der in firefox and now i tried to trust 
>>> squid-ca-cert-key.pem but it complained that it is already trusted.
>>
>> some sites are opening while others complain of 
>> SEC_ERROR_UNKNOWN_ISSUER like linkedin and hotmail
>
>
> To answer my question, focus on the problematic cases but ignore the 
> fact that Firefox is showing SEC_ERROR_UNKNOWN_ISSUER error. What 
> certificate did Firefox received from Squid (that triggered that 
> error)? Did it get (A)?
>
> There is usually a way to examine the received certificate in Firefox 
> despite SEC_ERROR_UNKNOWN_ISSUER, but I do not have a step-by-step 
> instructions for that. When examining the certificate, look for 
> Subject and Issuer fields. Do they match those of certificate (A) used 
> for working (i.e. no browser error) transactions? If not, what are 
> they, and does the issuer match the Subject field in CA certificate (B)?
>
now hotmail and linkedin are opening, except yandex is not. in the 
certificate it shows:
subject: country:ru
organization yandex
issuer: the squid certificate that all for certificate *.yandex.tr on 
the the right there is a second certificate of squid: Subject is what i 
filled in when i generated the certificate and so is issuer and 
everything else.
> HTH,
>
> Alex.
>
>
>
>>>>> now the conf reconfigured is:
>>>>> http_port 8080 ssl-bump 
>>>>> cert=/etc/squid/certs/squid-ca-cert-key.pem 
>>>>> generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
>

--------------QzIr5Ua7zPjSu6ookJau0hFm
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#26a269" bgcolor="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">28.07.2026 15:44, Alex Rousskov пишет:<br>
    </div>
    <blockquote type="cite"
cite="mid:[email protected]">On
      2026-07-27 00:57, Vacheslav wrote:
      <br>
      <blockquote type="cite">27.07.2026 07:54, Vacheslav пишет:
        <br>
        <blockquote type="cite">24.07.2026 16:08, Alex Rousskov пишет:
          <br>
          <blockquote type="cite">In a working setup, we expect:
            <br>
            <br>
            A) A browser receiving a site certificate generated by
            Squid.
            <br>
               This site certificate (A) is signed by CA certificate
            (B).
            <br>
            <br>
            B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem
            <br>
               Squid http_port configured to use certificate (B).
            <br>
               Browser configured to trust certificate (B).
            <br>
            <br>
            <br>
            How does the above differ from what you observe?
            <br>
          </blockquote>
        </blockquote>
      </blockquote>
      <br>
      <blockquote type="cite">
        <blockquote type="cite">i'm getting in firefox Код ошибки:
          SEC_ERROR_UNKNOWN_ISSUER
          <br>
          i had trusted squid-ca-cert.der in firefox and now i tried to
          trust squid-ca-cert-key.pem but it complained that it is
          already trusted.
          <br>
        </blockquote>
        <br>
        some sites are opening while others complain of
        SEC_ERROR_UNKNOWN_ISSUER like linkedin and hotmail
        <br>
      </blockquote>
      <br>
      <br>
      To answer my question, focus on the problematic cases but ignore
      the fact that Firefox is showing SEC_ERROR_UNKNOWN_ISSUER error.
      What certificate did Firefox received from Squid (that triggered
      that error)? Did it get (A)?
      <br>
      <br>
      There is usually a way to examine the received certificate in
      Firefox despite SEC_ERROR_UNKNOWN_ISSUER, but I do not have a
      step-by-step instructions for that. When examining the
      certificate, look for Subject and Issuer fields. Do they match
      those of certificate (A) used for working (i.e. no browser error)
      transactions? If not, what are they, and does the issuer match the
      Subject field in CA certificate (B)? <br>
      <br>
    </blockquote>
    now hotmail and linkedin are opening, except yandex is not. in the
    certificate it shows:<br>
    subject: country:ru<br>
    organization yandex<br>
    issuer: the squid certificate that all for certificate *.yandex.tr
    on the the right there is a second certificate of squid: Subject is
    what i filled in when i generated the certificate and so is issuer
    and everything else.
    <blockquote type="cite"
cite="mid:[email protected]">HTH,
      <br>
      <br>
      Alex.
      <br>
      <br>
      <br>
      <br>
      <blockquote type="cite">
        <blockquote type="cite">
          <blockquote type="cite">
            <blockquote type="cite">now the conf reconfigured is:
              <br>
              http_port 8080 ssl-bump
              cert=/etc/squid/certs/squid-ca-cert-key.pem
              generate-host-certificates=on
              dynamic_cert_mem_cache_size=8MB
              <br>
            </blockquote>
          </blockquote>
        </blockquote>
      </blockquote>
      <br>
    </blockquote>
    <br>
  </body>
</html>

--------------QzIr5Ua7zPjSu6ookJau0hFm--

--===============2119058714267395019==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
squid-users mailing list
[email protected]
https://lists.squid-cache.org/listinfo/squid-users

--===============2119058714267395019==--