[squid-users] ssl bump
Vacheslav
m_zouhairy at ckta.by
Thu Jul 23 05:22:48 UTC 2026
20.07.2026 20:15, Alex Rousskov пишет:
> On 2026-07-20 01:27, Vacheslav wrote:
>> 17.07.2026 15:44, Alex Rousskov пишет:
>>> On 2026-07-17 01:31, Vacheslav wrote:
>>>
>>>> 16.07.2026 18:19, Andrey K пишет:
>>>>> @Vacheslav:
>>>>> > sudo /usr/libexec/squid/security_file_certgen -c -s
>>>>> > /var/cache/squid/ssl_db/certs -M 4MB
>>>>> You specified the wrong path (the correct one is
>>>>> /var/cache/squid/ssl_db ).
>>>>
>>>>
>>>> good catch:
>>>> now running:
>>>> sudo -u squid /usr/libexec/squid/security_file_certgen -s
>>>> /var/cache/squid/ssl_db -M 4MB
>>>> ^C
>>>> produces nothing.
>>>
>>> That lack of output is a good sign -- the helper managed to start
>>> successfully.
>>>
>>>
>>>> 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>
>>> Helpers are still dying, but it looks like they do it while handling
>>> traffic.
>>>
>>>
>>>>> 2. Redirect security_file_certgen stderr (but not stdout!) output
>>>>> into a dedicated log file. It may be possible to do that right on
>>>>> the sslcrtd_program line, without wrapping the helper into another
>>>>> script.
>>>
>>>> how to do that?
>>>
>>> Try using shell redirection when specifying how to run the helper.
>>> Something along these lines may work:
>>>
>>> sslcrtd_program /usr/local/... -M 4MB >> /tmp/sslcrtd.error.log
>
>
> My bad. I missed "2" to redirect stderr rather than stdout. Fixed
> below. The missing file descriptor is _not_ the reason your test is
> not working though (as detailed below).
>
>
>> now the configuration looks like this:
>>
>> sslcrtd_program /usr/libexec/squid/security_file_certgen -s
>> /var/cache/squid/ssl_db -M 4MB >> /tmp/sslcrtd.error.log
>
>
> To capture stderr:
>
> sslcrtd_program /usr/libexec/squid/security_file_certgen -s
> /var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
>
>
>> in tmp there is no sslcrtd.error.log file.
>
>
> AFAICT, your Squid does not start sslcrtd_program helper. What does
> "squid -v" say? If there is no '--enable-ssl-crtd' there, then you
> need to rebuild your Squid executable from scratch. Also, at least one
> http_port or https_port directive in your squid.conf should have both
> "generate-host-certificates" and "ssl-bump" options.
sudo squid -v | grep "enable-ssl-crtd"
........'--enable-arp-acl' '--enable-ssl-crtd'.............
> When done right, you should see the debugging file created in /tmp/
> and, in cache log, Squid logging "Starting ..." lines mentioning your
> helper (similar to your existing lines for the ufdbgclient helper).
here is the configuration with the 8080 sslbump port open:
forwarded_for delete
delay_pools 1
delay_class 1 3
delay_access 1 allow slower
delay_access 1 deny all
delay_parameters 1 128000/128000 -1/-1 128000/64000
http_access allow localnet
http_access allow localhost
# And finally deny all other access to this proxy
http_access deny all
# Squid normally listens to port 3128
#http_port 8080
http_port 8080 ssl-bump cert=/etc/squid/certs/myCA.pem
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
##acl step1 at_step SslBump1
##ssl_bump peek step1
##ssl_bump bump all
##sslcrtd_program /usr/libexec/squid/security_file_certgen -s
/var/lib/squid/ssl_db -M 4MB
##sslcrtd_children 5
acl tls_s1_connect at_step SslBump1
acl tls_s2_client_hello at_step SslBump2
acl tls_s3_server_hello at_step SslBump3
# define acls for sites that must not be actively bumped
acl tls_allowed_hsts ssl::server_name .akamaihd.net
acl tls_allowed_hsts ssl::server_name .proxy.skko.by
#acl tls_server_is_bank ssl::server_name .abnamro.nl
#acl tls_server_is_bank ssl::server_name .abnamro.com
acl tls_server_is_bank ssl::server_name
"/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"
acl tls_to_splice any-of tls_allowed_hsts
tls_server_is_bank
# TLS/SSL bumping steps
ssl_bump peek tls_s1_connect # peek at
TLS/SSL connect data
ssl_bump splice tls_to_splice # splice
some: no active bump
ssl_bump stare all #
stare(peek) at server
# properties of
the webserver
ssl_bump bump # bump if we
can (if the stare succeeded)
ssl_bump peek tls_s1_connect
ssl_bump splice all
#ssl_bump peek all
############ssl_bump splice all
sslcrtd_program /usr/libexec/squid/security_file_certgen -s
/var/cache/squid/ssl_db -M 4MB 2>> /tmp/sslcrtd.error.log
sslcrtd_children 1 startup=1 idle=1
ssl_bump server-first all
sslproxy_cert_error allow all
#tls_outgoing_options options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE
cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS
# Uncomment and adjust the following to add a disk cache directory.
# Updates: chrome and acrobat
#refresh_pattern -i gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf) 43200 80%
129600 reload-into-ims
#refresh_pattern -i adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf) 43200
80% 129600 reload-into-ims
#range_offset_limit 200 MB
#maximum_object_size 200 MB
#quick_abort_min -1
# DONT MODIFY THESE LINES
#refresh_pattern \^ftp: 1440 20% 10080
#refresh_pattern \^gopher: 1440 0% 1440
#refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
#refresh_pattern . 0 20% 43200
cache_dir ufs /var/cache/squid 3000 16 256
# Leave coredumps in the first cache dir
coredump_dir /var/cache/squid
cache_mem 960 MB
netdb_filename none
logformat squidx %err_code/%err_detail
#access_log daemon:/var/log/squid/accessX.log squidx
#access_log squidx
#
# Add any of your own refresh_pattern entries above these.
#
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
url_rewrite_extras "%>a/%>A %un %>rm bump_mode=%ssl::bump_mode
sni=\"%ssl::>sni\" referer=\"%{Referer}>h\""
url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient -m 4 -l
/var/log/squid/
url_rewrite_children 16 startup=8 idle=2 concurrency=4 queue-size=64
#debug_options ALL,1 33,2 28,9
> HTH,
>
> Alex.
i finally noticed an empty sslcrtd.error.log file in /tmp created on
20.07.2026, for some reason i was looking for a folder, stupid me.
i'm getting certificate errors when browsing sites in firefox. some
sites provide a warning to proceed to site (dangerous) other sites just
put 3 tab one of them is to see the certificate.
here is the cache.log:
2026/07/23 07:32:59 kid1| Processing Configuration File:
/etc/squid/squid.conf (depth 0)
2026/07/23 07:32:59 kid1| Set Current Directory to /var/cache/squid
2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6 for
x86_64-suse-linux-gnu...
2026/07/23 07:32:59 kid1| Service Name: squid
2026/07/23 07:32:59 kid1| Process ID 3183
2026/07/23 07:32:59 kid1| Process Roles: worker
2026/07/23 07:32:59 kid1| With 4096 file descriptors available
2026/07/23 07:32:59 kid1| Initializing IP Cache...
2026/07/23 07:32:59 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46 from
/etc/resolv.conf
2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5 from /etc/resolv.conf
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1
'security_file_certgen' processes
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16 'ufdbgclient'
processes
2026/07/23 07:32:59 kid1| Logfile: opening log
daemon:/var/log/squid/access.log
2026/07/23 07:32:59 kid1| Logfile Daemon: opening log
/var/log/squid/access.log
2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31
2026/07/23 07:33:00 kid1| Local cache digest enabled; rebuild/rewrite
every 3600/3600 sec
2026/07/23 07:33:00 kid1| Store logging disabled
2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040 KB, estimated
311926 objects
2026/07/23 07:33:00 kid1| Target number of buckets: 15596
2026/07/23 07:33:00 kid1| Using 16384 Store buckets
2026/07/23 07:33:00 kid1| Max Mem size: 983040 KB
2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB
2026/07/23 07:33:00 kid1| Rebuilding storage in /var/cache/squid (clean log)
2026/07/23 07:33:00 kid1| Using Least Load store dir selection
2026/07/23 07:33:00 kid1| Set Current Directory to /var/cache/squid
2026/07/23 07:33:00 kid1| Finished loading MIME types and icons.
2026/07/23 07:33:00 kid1| HTCP Disabled.
2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36
2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0
2026/07/23 07:33:00 kid1| Adaptation support is off.
2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket connections
at conn20 local=0.0.0.0:8080 remote=[::] FD 34 flags=9
listening port: 8080
2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation. Detected
non-functional IPv6 loopback.
2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...
2026/07/23 07:33:00 pinger| ICMP socket opened.
2026/07/23 07:33:00 pinger| ICMPv6 socket opened
2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84% (4000 out of 216863)
2026/07/23 07:33:03 kid1| Done reading /var/cache/squid swaplog (216862
entries)
2026/07/23 07:33:03 kid1| Finished rebuilding storage from disk.
216862 Entries scanned
0 Invalid entries
0 With invalid flags
216862 Objects loaded
0 Objects expired
0 Objects canceled
0 Duplicate URLs purged
0 Swapfile clashes avoided
Took 3.16 seconds (68526.49 objects/sec).
2026/07/23 07:33:03 kid1| Beginning Validation Procedure
2026/07/23 07:33:03 kid1| Completed Validation Procedure
Validated 216848 Entries
store_swap_size = 2764352.00 KB
2026/07/23 07:33:03 kid1| storeLateRelease: released 0 objects
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
problem: failure
error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
current master transaction: master58
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
problem: failure
error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
current master transaction: master58
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS connection
problem: failure
error detail: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
current master transaction: master58
.........
>>>> 2026/07/17 08:17:35| Removing PID file (/run/squid.pid)
>>>> 2026/07/17 08:18:54| WARNING: BCP 177 violation. Detected
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_localhost
>>>> configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_localhost
>>>> configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:54| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_linklocal
>>>> configuration context: Default Configuration(16) acl
>>>> 2026/07/17 08:18:54| Processing Configuration File:
>>>> /etc/squid/squid.conf (depth 0)
>>>> 2026/07/17 08:18:55| Created PID file (/run/squid.pid)
>>>> 2026/07/17 08:18:55 kid1| WARNING: BCP 177 violation. Detected
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_localhost
>>>> configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_localhost
>>>> configuration context: Default Configuration(15) acl
>>>> 2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6 has not been enabled.
>>>> acl name: to_linklocal
>>>> configuration context: Default Configuration(16) acl
>>>> 2026/07/17 08:18:55 kid1| Processing Configuration File:
>>>> /etc/squid/squid.conf (depth 0)
>>>> 2026/07/17 08:18:55 kid1| Set Current Directory to /var/cache/squid
>>>> 2026/07/17 08:18:55 kid1| Starting Squid Cache version 7.6 for
>>>> x86_64-suse-linux-gnu...
>>>> 2026/07/17 08:18:55 kid1| Service Name: squid
>>>> 2026/07/17 08:18:55 kid1| Process ID 3685
>>>> 2026/07/17 08:18:55 kid1| Process Roles: worker
>>>> 2026/07/17 08:18:55 kid1| With 4096 file descriptors available
>>>> 2026/07/17 08:18:55 kid1| Initializing IP Cache...
>>>> 2026/07/17 08:18:55 kid1| DNS IPv4 socket created at 0.0.0.0, FD 7
>>>> 2026/07/17 08:18:55 kid1| Adding nameserver 10.6.30.40 from
>>>> /etc/resolv.conf
>>>> 2026/07/17 08:18:55 kid1| Adding nameserver 10.10.10.5 from
>>>> /etc/resolv.conf
>>>> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 5/5
>>>> 'security_file_certgen' processes
>>>> 2026/07/17 08:18:55 kid1| helperOpenServers: Starting 8/16
>>>> 'ufdbgclient' processes
>>>> 2026/07/17 08:18:55 kid1| Logfile: opening log
>>>> daemon:/var/log/squid/access.log
>>>> 2026/07/17 08:18:55 kid1| Logfile Daemon: opening log
>>>> /var/log/squid/access.log
>>>> 2026/07/17 08:18:56 kid1| Unlinkd pipe opened on FD 39
>>>> 2026/07/17 08:18:56 kid1| Local cache digest enabled;
>>>> rebuild/rewrite every 3600/3600 sec
>>>> 2026/07/17 08:18:56 kid1| Store logging disabled
>>>> 2026/07/17 08:18:56 kid1| Swap maxSize 3072000 + 983040 KB,
>>>> estimated 311926 objects
>>>> 2026/07/17 08:18:56 kid1| Target number of buckets: 15596
>>>> 2026/07/17 08:18:56 kid1| Using 16384 Store buckets
>>>> 2026/07/17 08:18:56 kid1| Max Mem size: 983040 KB
>>>> 2026/07/17 08:18:56 kid1| Max Swap size: 3072000 KB
>>>> 2026/07/17 08:18:56 kid1| Rebuilding storage in /var/cache/squid
>>>> (clean log)
>>>> 2026/07/17 08:18:56 kid1| Using Least Load store dir selection
>>>> 2026/07/17 08:18:56 kid1| Set Current Directory to /var/cache/squid
>>>> 2026/07/17 08:18:56 kid1| Finished loading MIME types and icons.
>>>> 2026/07/17 08:18:56 kid1| HTCP Disabled.
>>>> 2026/07/17 08:18:56 kid1| Pinger socket opened on FD 44
>>>> 2026/07/17 08:18:56 kid1| Squid plugin modules loaded: 0
>>>> 2026/07/17 08:18:56 kid1| Adaptation support is off.
>>>> 2026/07/17 08:18:56 kid1| Accepting SSL bumped HTTP Socket
>>>> connections at conn28 local=0.0.0.0:8080 remote=[::] FD 42 flags=9
>>>> listening port: 8080
>>>> 2026/07/17 08:18:56 pinger| WARNING: BCP 177 violation. Detected
>>>> non-functional IPv6 loopback.
>>>> 2026/07/17 08:18:56 pinger| Initialising ICMP pinger ...
>>>> 2026/07/17 08:18:56 pinger| ICMP socket opened.
>>>> 2026/07/17 08:18:56 pinger| ICMPv6 socket opened
>>>> 2026/07/17 08:18:56 kid1| Indexing cache entries: 1.84% (4000 out
>>>> of 217945)
>>>> 2026/07/17 08:18:59 kid1| Done reading /var/cache/squid swaplog
>>>> (217944 entries)
>>>> 2026/07/17 08:18:59 kid1| Finished rebuilding storage from disk.
>>>> 217944 Entries scanned
>>>> 0 Invalid entries
>>>> 0 With invalid flags
>>>> 217944 Objects loaded
>>>> 0 Objects expired
>>>> 0 Objects canceled
>>>> 0 Duplicate URLs purged
>>>> 0 Swapfile clashes avoided
>>>> Took 2.85 seconds (76435.29 objects/sec).
>>>> 2026/07/17 08:18:59 kid1| Beginning Validation Procedure
>>>> 2026/07/17 08:18:59 kid1| Completed Validation Procedure
>>>> Validated 217930 Entries
>>>> store_swap_size = 2764788.00 KB
>>>> 2026/07/17 08:18:59 kid1| storeLateRelease: released 0 objects
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master55
>>>> 2026/07/17 08:18:59 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>>
>>>> ........
>>>>
>>>> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:32 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| ERROR: Cannot accept a TLS connection
>>>> problem: failure
>>>> error detail:
>>>> SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program #Hlpr1 exited
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| Too few sslcrtd_program processes are
>>>> running (need 1/5)
>>>> active processes: 4
>>>> processes configured to start at (re)configuration: 5
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| helperOpenServers: Starting 1/5
>>>> 'security_file_certgen' processes
>>>> current master transaction: master57
>>>> 2026/07/17 08:21:33 kid1| Preparing for shutdown after 761 requests
>>>> 2026/07/17 08:21:33 kid1| Waiting 30 seconds for active connections
>>>> to finish
>>>> 2026/07/17 08:21:33 kid1| Closing HTTP(S) port 0.0.0.0:8080
>>>> listening port: 8080
>>>> 2026/07/17 08:21:33 kid1| Closing Pinger socket on FD 44
>>>> 2026/07/17 08:21:33 kid1| ERROR: logfileHandleWrite:
>>>> daemon:/var/log/squid/access.log: error writing ((32) Broken pipe)
>>>> connection: conn2846 local=10.0.0.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs: Starting...
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| 65536 entries written so far.
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| 131072 entries written so far.
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| 196608 entries written so far.
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| Finished. Wrote 217944 entries.
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| Took 0.08 seconds (2736133.78
>>>> entries/sec).
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.16.0.7:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| FATAL: I don't handle this error well!
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> 2026/07/17 08:21:33 kid1| Squid Cache (Version 7.6): Terminated
>>>> abnormally.
>>>> connection: conn2846 local=10.10.10.18:8080
>>>> remote=10.1.0.17:53255 flags=1
>>>> CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
>>>> Maximum Resident Size: 314320 KB
>>>> Page faults with physical i/o: 0
>>>>>
>>>>> To recreate a certificate database you should do:
>>>>>
>>>>> sudo rm -rf /var/cache/squid/ssl_db
>>>>> sudo /usr/libexec/squid/security_file_certgen -c
>>>>> -s /var/cache/squid/ssl_db -M 4MB
>>>>> sudo chown -R squid:squid /var/cache/squid/ssl_db
>>>>>
>>>>> чт, 16 июл. 2026 г. в 16:36, Alex Rousskov
>>>>> <rousskov at measurement-factory.com>:
>>>>>
>>>>> On 2026-07-16 01:57, Vacheslav wrote:
>>>>>
>>>>> > 2026/07/16 08:34:24 kid1| WARNING: sslcrtd_program #Hlpr1
>>>>> exited
>>>>>
>>>>> We need to figure out why your security_file_certgen helpers are
>>>>> exiting. IIRC, those helpers have not been upgraded to report
>>>>> their
>>>>> fatal failures to cache.log. There are a few tricks you can
>>>>> use to
>>>>> see
>>>>> what the problem is, but I would probably start with these three:
>>>>>
>>>>> 1. Run security_file_certgen with sslcrtd_program parameters
>>>>> from the
>>>>> command line, as Squid user. If you are lucky, it will
>>>>> complain about
>>>>> something before it starts waiting for the helper request.
>>>>>
>>>>> 2. Redirect security_file_certgen stderr (but not stdout!) output
>>>>> into a
>>>>> dedicated log file. It may be possible to do that right on the
>>>>> sslcrtd_program line, without wrapping the helper into another
>>>>> script.
>>>>>
>>>>> 3. Enable full debugging, reproduce the problem with a single
>>>>> transaction, and send a link to the corresponding compressed
>>>>> cache.log
>>>>> file for analysis as detailed at
>>>>> https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction
>>>>>
>>>>>
>>>>>
>>>>> Cheers,
>>>>>
>>>>> Alex.
>>>>>
>>>>> _______________________________________________
>>>>> squid-users mailing list
>>>>> squid-users at lists.squid-cache.org
>>>>> https://lists.squid-cache.org/listinfo/squid-users
>>>>>
>>>>
>>>
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20260723/6c903d16/attachment-0001.htm>
More information about the squid-users
mailing list