Re: [squid-users] sslbump - firefox sec_error_inadequate_key_usage

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sat, 12 Apr 2014 00:59:46 +1200

On 11/04/2014 11:55 p.m., Amm wrote:
> On Friday, 11 April 2014 5:19 PM
>
>
>> I also use this patch and would like if it is possible to somehow go on without it.
>>
>> May it be due to the fact squid caches the generated SSL certificates in the ssl_crtd store?
>> So we need to clear the store when root CA certificate for SSL bump is regenerated?

Yes to both of those questions.

They are not related to the warning in firefox though.

>
>> Raf
>
> I had cleared the ssl cert store but the issue still occured (without patch).
>
> So finally I gave up trying different things and used the patch.
>
> Here is exact same issue discussed earlier in mailing list:
> http://www.squid-cache.org/mail-archive/squid-users/201311/0310.html
>
> Amm
>

It seems to be something in firefox was buggy and they have a workaround
coming out in version 29.0, whether that will fix the warnign display or
just allow people to ignore/bypass it like other cert issues I'm not
certain.

Amos
Received on Fri Apr 11 2014 - 12:59:56 MDT

This archive was generated by hypermail 2.2.0 : Fri Apr 11 2014 - 12:00:04 MDT