Re: [squid-users] Re: SSLBump, help to configure for 3.1.0.16

From: Matus UHLAR - fantomas <uhlar_at_fantomas.sk>
Date: Thu, 18 Feb 2010 09:21:01 +0100

> On 02/16/2010 12:54 PM, Andres Salazar wrote:
> > Iam still having issues with SSLBump .. apparently iam now getting
> > this error when I visit an https site with my browser explicity
> > configured to use the https_port .
> >
> > 2010/02/16 14:31:14| clientNegotiateSSL: Error negotiating SSL
> > connection on FD 8: error:1407609B:SSL
> > routines:SSL23_GET_CLIENT_HELLO:https proxy request (1/-1)

On 17.02.10 22:40, Alex Rousskov wrote:
> IIRC, SSL bumping at http_port is for dealing with HTTP CONNECT
> requests sent by the browser directly to the proxy while https_port is
> for bumping transparently intercepted SSL sessions that the browser
> tries to establish with the origin server. Your "browser explicitly
> configured to use the https_port" description does not fit either of
> these use cases.

I think it's more case of browsers not supporting proxying via https.

-- 
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Honk if you love peace and quiet. 
Received on Thu Feb 18 2010 - 08:21:37 MST

This archive was generated by hypermail 2.2.0 : Thu Feb 18 2010 - 12:00:06 MST