Re: [squid-users] ssl reverse proxy self signed cert

From: Henrik Nordstrom <henrik@dont-contact.us>
Date: Tue, 20 Mar 2007 12:53:07 +0100

fre 2007-03-09 klockan 15:59 +0100 skrev Peter Meier:
> Hi
>
> maybe i understood something wrong but I'm trying to do the following
> setup with squid 2.6.STABLE7 and couldn't find anything related to my
> errors and problems:
>
> wished setup:
> client --ssl (cacert signed)--> squid (reverse) --ssl (selfsigned)--> apache

When using self-signed certificates you need to either add the
certificate as a ca for the cache_peer, or tell Squid to not verify the
certificate of the peer at all.

> well for me it is clear that squid cannot verify the cert as it is
> self signed. however i'd like to tell squid that it should accept this
> cert, not try to verify it or whatever to be possible to use it. But I
> couldn't find such an option for the https_port option.

It's the cache_peer option you need to look at..

Regards
Henrik

Received on Tue Mar 20 2007 - 05:53:13 MDT

This archive was generated by hypermail pre-2.1.9 : Sat Mar 31 2007 - 13:00:02 MDT