[squid-users] Squid 3.2 - Dynamic SSL certs that aren't self-signed

From: Alex Ray <alexray_at_espsolution.net>
Date: Thu, 23 Dec 2010 11:52:29 -0800

I've written an ad-hoc bash script, ssl_srtd_ca, that acts like the
following, but doesn't work when dropped-in. Is there some sort of
spec on how ssl_crtd communicates?

squid01:/etc/ssl/ssl_crtd_tmp# ssl_crtd_ca -M 4MB -s
/usr/local/squid/var/lib/ssl_db
new_certificate 13 host=host.dom
ok 1502 -----BEGIN CERTIFICATE-----
MIIEWDCCA0CgAwIBAgIBFjANBgkqhkiG9w0BAQUFADCBpzELMAkGA1UEBhMCVVMx
EzARBgNVBAgTCldhc2hpbmd0b24xKDAmBgNVBAoTH0VuaGFuY2VkIFNvZnR3YXJl
IFByb2R1Y3RzLCBJbmMxFTATBgNVBAsTDFRlY2ggU3VwcG9ydDEdMBsGA1UEAxMU
RVNQU09MVVRJT04gUFJPWFkgQ0ExIzAhBgkqhkiG9w0BCQEWFHRlY2hAZXNwc29s
dXRpb24ubmV0MB4XDTEwMTIyMzE5NTAwM1oXDTIwMTIyMDE5NTAwM1owgbkxCzAJ
BgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRcwFQYDVQQHEw5TcG9rYW5l
IFZhbGxleTEoMCYGA1UEChMfRW5oYW5jZWQgU29mdHdhcmUgUHJvZHVjdHMsIElu
YzEaMBgGA1UECxMRVGVjaG5pY2FsIFN1cHBvcnQxETAPBgNVBAMTCGhvc3QuZG9t
MSMwIQYJKoZIhvcNAQkBFhR0ZWNoQGVzcHNvbHV0aW9uLm5ldDCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAL49fY/p+VVTqKrXAKm+uDiStVNebqGo9an8
JrG+AcKpp/GvOkVd4IDI7PR9T2/98x/89Vy8JZMdCrmue1IDf9T8RAcqcWiCOzNU
ZU+N8YnzkNME+O4P/3KGsJwnw8ornh50G0UbqQ7W9MxzSFFbalMSn/p2oOkWPU9U
S3CoeLYeG3TFDQnE42l9YUK72eG1CYqWiVuQA6y5LCrcWuM866QuLjjcwfQhy5b3
ceDoJrpt+tXe5j0mdJ3fGNABATijJ8rirX9VGQrvJAMt6KBW14tKpx2V6PWO/UVq
GwxJbGDRrZ11jo7N/z6hyHnIybExR87wvLMSpNtF4ZNsUzj8UxkCAwEAAaN7MHkw
CQYDVR0TBAIwADAsBglghkgBhvhCAQ0EHxYdT3BlblNTTCBHZW5lcmF0ZWQgQ2Vy
dGlmaWNhdGUwHQYDVR0OBBYEFG5gro1fZOnMidoGD3gfke30OGlJMB8GA1UdIwQY
MBaAFJxX0DITOt34sqbXAZdyn3s2HgBbMA0GCSqGSIb3DQEBBQUAA4IBAQABpYXr
nvAlsApWhDrs9lk1v0NlVYSaMHFZJGaQMsrk9DBcKq9hQehlUvetOMd98+BPaEZU
Wm2Rv41EUt6eB0jSRg6vR4MCs8Kq5XBBwEeXdLuKp95GPw74evhErB26jW5C+FWy
+WTjAiUhARp98nHs+9lLSiKYCHOujPdsb51n/MUo68oe3kVqLdwaHAmu3+8Z+Mqz
8knPCGr/EwonB0erZV7hSijURKBLepIREFnXRSAEhCUT8esgCsaOEnkQcIZz9R0i
TO+q/uI1dmiMNCuJHBbnCWuVhtN6rKwnUGtjMvJahFuq75uM7lpXiCdjPat1JfZE
PmAe90yjCCQSbmKc
-----END CERTIFICATE-----
-----BEGIN RSA PRIVATE KEY-----
MIIEogIBAAKCAQEAvj19j+n5VVOoqtcAqb64OJK1U15uoaj1qfwmsb4Bwqmn8a86
RV3ggMjs9H1Pb/3zH/z1XLwlkx0Kua57UgN/1PxEBypxaII7M1RlT43xifOQ0wT4
7g//coawnCfDyiueHnQbRRupDtb0zHNIUVtqUxKf+nag6RY9T1RLcKh4th4bdMUN
CcTjaX1hQrvZ4bUJipaJW5ADrLksKtxa4zzrpC4uONzB9CHLlvdx4Ogmum361d7m
PSZ0nd8Y0AEBOKMnyuKtf1UZCu8kAy3ooFbXi0qnHZXo9Y79RWobDElsYNGtnXWO
js3/PqHIecjJsTFHzvC8sxKk20Xhk2xTOPxTGQIDAQABAoIBAA8GXDxZhk+u48ta
X7sITRRqwddrxeEOrxhVydiP4SO2soTsCfYgi/Kf69cDbpqxu9ny6I4CbhVIXeh8
V1EK5bW0lsraF0rhvjs3lyjJVSJIElAYPHDQ4qPw71Hl8hitiTduhBjZLmj1oS/k
ivmh9qvI9MmbROojz4PMbIjhRWdcpn/Z4vuvJAroeEC+m/Nw+9oLsQ4SQ84jFW3I
9xTcY0D6WHK1Mc8/ZF0Y/JWleBe32zWtwYxLPNY6Ej6fldTFatKhkx8N59mvcxwQ
IxHCvWEnFGJFYLnIwcIUxl6Uz8TSzi3qce2Sb4fxsAlpblo8BGjcO1D0SuilS2iR
sKrk44ECgYEA4jFGGn6N6DxaJBWNFQ3YkK31mr3MQFnbleZeePCnahhkSUvHPuUN
wsB14ENJXTEBI9wrKiEc/RBKA+7nBuTkf762D5QWt/tk59Asrbp32qEunXzj9uXm
rxgGQlji6uHlfvSkI6pPrZGBriBN4HaKIXPcz03MYjfZDUa8BlTjbsUCgYEA109Y
0p1Phr9QMHR1wfTah1oUUKfjUu7Qv8UqJ7GFrGixSsJ3z5mBD7zrIU/3h5lBK8Vs
8pxkz7culEBeNXZnO6GFW89+7Ytrh/6dkETw1fIytng/1/z8zdbPcnOKMq0WxDAb
an78ST/cDFkDCLOciKMO+QJgLwGVx1kZF6TpGEUCgYAleLY9Y2PM6lqgibVynHWZ
GkiK1xCERJ6dCany7SM+70WF4vjiEX4jGlEs0tjPiHPA5hN8ijnMLqukVSqOuNKl
2wk8MXNGDW6c/J66NR7v6C3ZxzvYxiNeNGOtEB6ffMbRLmQWyHskrOtH1nAwVFLz
0cbtzNykFM5vZZ12iw+WZQKBgGYwmca0tScOLEAjNjTNQt7U6Sly1ZjqEhfCu4RF
ZF10/xitffIBOFlA4BRagPBR07WzqUbo5YwUtD3W4x/ax5psyf/OVr7l2i6csSnl
Hq1cm6cxIZQg1dfYaXM31VLCBjktYAXGqXUWoxkVMjRyEwxi39tdvkrxJKaN6jPn
qF5FAoGAdCrhZvdQeC4aDX8mHbIBXf2Wh4KDPuW9O3qMXI4uV14wF2FXtyRtyQXK
WGrk7Ap2TGN2pzN9tNP9DyuP862VVpAAHtcRy/1xVouv6KscRz90nrmiFk+FMG/T
/V7/1X04ebJVQqxj7x3+57KgePlp/77THZacKIGPpQhhzl4WL7I=
-----END RSA PRIVATE KEY-----
Received on Thu Dec 23 2010 - 19:52:37 MST

This archive was generated by hypermail 2.2.0 : Fri Dec 24 2010 - 12:00:03 MST