Re: [squid-users] HTTPS site access problem

From: Chris Robertson <crobertson_at_gci.net>
Date: Tue, 19 Aug 2008 12:19:04 -0800

Evren Demirkan wrote:
> Hello,
> I am using SQUID 2.7.STABLE2 on an Arch Linux server. Everything seems
> OK so far, except I am unable to connect a SSL site,
> https://evas.tcmb.gov.tr/
>
> Normally when i connect this site it should ask me my user certificate
> to select, but no.
>
> Here are my tails from acces.log
>
> 1219155728.992 10845 10.0.0.95 TCP_MISS/200 117 CONNECT
> evas.tcmb.gov.tr:443 - DIRECT/212.174.145.17 -
> 1219155747.294 18302 10.0.0.95 TCP_MISS/200 117 CONNECT
> evas.tcmb.gov.tr:443 - DIRECT/212.174.145.17 -
> 1219156647.386 900091 10.0.0.95 TCP_MISS/200 117 CONNECT
> evas.tcmb.gov.tr:443 - DIRECT/212.174.145.17 -
>
> and with mime_hdrs on
>
> 1219157421.509 10505 10.0.0.95 TCP_MISS/200 117 CONNECT
> evas.tcmb.gov.tr:443 - DIRECT/212.174.145.17 - [User-Agent:
> Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322;
> .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR
> 3.5.21022)\r\nProxy-Connection: Keep-Alive\r\nContent-Length:
> 0\r\nHost: evas.tcmb.gov.tr\r\nPragma: no-cache\r\n] []
>
> no answer is coming from the server.
>
>
>
> Also I can successfully connect directly or using SQUID 2.0
> maintained in Centos 4.X.
>

Heh... Squid 2.0? That would be something to see, as it's almost ten
years old (http://www.squid-cache.org/Versions/v2/2.0/).

> Using my archlinux setup mentioned above, I can successfully connected
> bank websites, Gmail ,etc.through SSL without a problem. I am using a
> basic squid.conf with http_port 8080 and some acl entires.
>
> Are there any more options /tweaks you may offer?
>

See the FAQ entry at
http://wiki.squid-cache.org/SquidFaq/SystemWeirdnesses#head-699d810035c099c8b4bff21e12bb365438a21027
for one possibility.

> Best Regards,
> Evren
>

Chris
Received on Tue Aug 19 2008 - 20:19:10 MDT

This archive was generated by hypermail 2.2.0 : Wed Aug 20 2008 - 12:00:04 MDT