Re: [squid-users] Certificate server validation

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sun, 20 Jan 2013 14:24:02 +1300

On 19/01/2013 3:37 a.m., vincent viard wrote:
> Hello,
>
> I ask you about the feasibility of achieving an validation server
> certificates used during session establishment SSL/TLS in HTTPS at the
> level of SQUID proxy ?
> The idea is not to break the SSL session with a man-in-the-middle (ex.
> SSLBump), but to authenticate (and to authorize) the target with a
> white or black list of CAs. In other words, realize with Squid, the
> first validation of the SSL handshake logically made by the client
> browser on the certificate of server.
>
> In advance, thank you and good day.
>
> Vince

Please see http://wiki.squid-cache.org/Features/SslServerCertValidator

This feature is merged and will be in 3.4 series when it is released. To
use it now you need to build the 3.HEAD Squid sources.

Amos
Received on Sun Jan 20 2013 - 01:24:07 MST

This archive was generated by hypermail 2.2.0 : Sun Jan 20 2013 - 12:00:06 MST