Re: [squid-users] SSL gateway using chained certs?

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Wed, 17 Dec 2003 10:09:32 +0100 (CET)

On Tue, 16 Dec 2003, Paul wrote:

> Can squid (squid-2.5.STABLE1-2 running under RH9 Linux) be
> configured to handled *chained* SSL certificates (e.g. from
> FreeSSL.com) for SSL to HTTP gatewaying? Before I purchase
> chained cert (much cheaper than usual certs), I'd like to hear
> from anyone who has direct experience.

Squid-3 or Squid-2-5 + SSL update patch it should if you simply add the
chain to the certificate file.

Squid-2.5 without the SSL update patch does not support certificate chains
unless you modify the source to use SSL_CTX_use_certificate_chain_file
instead of SSL_CTX_use_certificate_file.

Regards
Henrik
Received on Wed Dec 17 2003 - 02:09:39 MST

This archive was generated by hypermail pre-2.1.9 : Thu Jan 01 2004 - 12:00:14 MST