[squid-users] https site access problem!!!

From: Shiva Raman <raman.shivag_at_gmail.com>
Date: Fri, 4 Jul 2008 09:56:20 +0530

Dear All

I got a squidIcap Installation running with following squid.conf

---------------------------------------------
http_port 80

hierarchy_stoplist cgi-bin ?

acl QUERY urlpath_regex cgi-bin \?

no_cache deny QUERY

cache_mem 8 MB

cache_dir ufs /usr/local/squidICAP/var/cache 500 16 256

cache_access_log /usr/local/squidICAP/var/logs/access.log

cache_log /usr/local/squidICAP/var/logs/cache.log

cache_store_log /usr/local/squidICAP/var/logs/store.log

redirect_program /opt/Websense/bin/WsRedtor

redirect_children 30

auth_param basic children 5

auth_param basic realm Squid proxy-caching web server

auth_param basic credentialsttl 2 hours

auth_param basic casesensitive off

refresh_pattern ^ftp: 1440 20% 10080

refresh_pattern ^gopher: 1440 0% 1440

refresh_pattern . 0 20% 4320

acl squidICAP dstdomain "/usr/local/squidICAP/bad_domains"

header_access Accept-Encoding deny squidICAP

acl all src 0.0.0.0/0.0.0.0

acl manager proto cache_object

acl localhost src 127.0.0.1/255.255.255.255

acl to_localhost dst 127.0.0.0/8

acl SSL_ports port 443 563

acl Safe_Ports port 81 # non stadard part

acl Safe_ports port 80 # http

acl Safe_ports port 21 # ftp

acl Safe_ports port 443 563 # https, snews

acl Safe_ports port 70 # gopher

acl Safe_ports port 210 # wais

acl Safe_ports port 1025-65535 # unregistered ports

acl Safe_ports port 280 # http-mgmt

acl Safe_ports port 488 # gss-http

acl Safe_ports port 591 # filemaker

acl Safe_ports port 777 # multiling http

acl CONNECT method CONNECT

acl GET method GET

http_access allow all

http_access allow manager localhost

http_access deny manager

http_access deny !Safe_ports

http_access deny CONNECT !SSL_ports

http_access deny all

http_reply_access allow all

icp_access allow all

cache_effective_user squid

visible_hostname squidproxy

coredump_dir /usr/local/squidICAP/var/cache

redirector_bypass off

----------------------------------------

i am not able to open all ssl websites through this squid ,but able to access
few ssl sites through it using lynx command line browser .

Following is one of the site tested https://secure.icicidirect.com

I am not sure whether its squid or linux ssl issue

When i try to access the above webserver through the squid proxy, it
is unable to open
the website. When i try the links its showing as only "SSL ERROR"

I tried to check the openssl connectivity through command prompt get
following error.

[root_at_squidproxy]# openssl s_client -connect
secure.icicidirect.com:443 -showcerts

CONNECTED(00000003)
write:errno=104

Any suggestions / workarounds for this problems, please let me know.

Regards

Shiva Raman
Received on Fri Jul 04 2008 - 04:26:25 MDT

This archive was generated by hypermail 2.2.0 : Fri Jul 04 2008 - 12:00:02 MDT