Re: [squid-users] SslBump and bad cert

From: Alex Crow <alex_at_nanogherkin.com>
Date: Tue, 24 May 2011 17:25:25 +0100

E.g. if the server cert has expired, sign an expired squid cert to the
browser. At least this will reproduce the same behavior as if the
sslbump is not turned on. The browser will warn the certificate problem
and the user can proceed at his own risk. The squid administrator can be
kept out of the loop in dealing with not so well maintained server
certificate.
> Regards,
> Ming
>

Sounds like it could work, but I don't know with openssl if it's even
possible to generate a cert that has already expired!

Alex
Received on Tue May 24 2011 - 16:25:33 MDT

This archive was generated by hypermail 2.2.0 : Tue May 24 2011 - 12:00:03 MDT