Re: [squid-users] Decrypting SSL Traffic after intercepting it with dynamic Certs.

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sat, 03 Mar 2012 14:12:31 +1300

On 1/03/2012 10:21 p.m., Jan Fischbach wrote:
> Hi,
>
> I set up SQUID for SSL interception. ( --enable-ssl --enable-certd).
> Intercepting works fine, but the ssl_cerd service doesnt draw back his
> dynamic generated certificates in the given directory. What do I have
> to do to encypt it? I dont get the priv key for the captured session.
> Wireshark also wont accept my self-signed cert witch acts as CA.

By "draw back" do you mean "save/write to"?

The generator saves things to the database as long-term storage and
operates out of a RAM copy for speed and security most of the time.

This feature is still experimental and being extended. For details and
troubleshooting you can contact the developers of it via squid-dev if
you dont get a useful reply here in the next few days (most of the dev
don't follow this mailing list regularly).

Amos
Received on Sat Mar 03 2012 - 01:12:43 MST

This archive was generated by hypermail 2.2.0 : Sat Mar 03 2012 - 12:00:02 MST