Re: [squid-users] Transparent proxy with HTTPS on freebsd

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Wed, 29 Apr 2009 20:49:17 +1200

abdul sami wrote:
> Dear all,
>
> subject settings doesn't work when i set the transparent proxy though
> http traffic works. on analysis of traffic i have come to know that
> proxy doesn't add it's source address to https traffic rather simply
> forwards it with local net address to gateway/firewall device which
> ultimately drops the packets.
>
> any suggestion in shape of steps/article would be highly appreciated.
>
> Regards,

Pardon?
  HTTPS being transparently intercepted (miracle #1) and the users not
phoning you about being attacked? (miracle #2).

HTTPS == HTTP via _secure_ SSL.
transparent proxy == man-in-middle network attack on traffic.

HTTPS was created to prevent transparent interception amongst other
things. So yes I'm not surprised it won't work.

What are you trying to achieve with this?

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE6 or 3.0.STABLE14
   Current Beta Squid 3.1.0.7
Received on Wed Apr 29 2009 - 08:49:30 MDT

This archive was generated by hypermail 2.2.0 : Wed Apr 29 2009 - 12:00:03 MDT