[squid-users] ssl bump

Vacheslav m_zouhairy at ckta.by
Thu Jul 30 05:34:15 UTC 2026



28.07.2026 15:44, Alex Rousskov пишет:
> On 2026-07-27 00:57, Vacheslav wrote:
>> 27.07.2026 07:54, Vacheslav пишет:
>>> 24.07.2026 16:08, Alex Rousskov пишет:
>>>> In a working setup, we expect:
>>>>
>>>> A) A browser receiving a site certificate generated by Squid.
>>>>    This site certificate (A) is signed by CA certificate (B).
>>>>
>>>> B) CA certificate in /etc/squid/certs/squid-ca-cert-key.pem
>>>>    Squid http_port configured to use certificate (B).
>>>>    Browser configured to trust certificate (B).
>>>>
>>>>
>>>> How does the above differ from what you observe?
>
>>> i'm getting in firefox Код ошибки: SEC_ERROR_UNKNOWN_ISSUER
>>> i had trusted squid-ca-cert.der in firefox and now i tried to trust 
>>> squid-ca-cert-key.pem but it complained that it is already trusted.
>>
>> some sites are opening while others complain of 
>> SEC_ERROR_UNKNOWN_ISSUER like linkedin and hotmail
>
>
> To answer my question, focus on the problematic cases but ignore the 
> fact that Firefox is showing SEC_ERROR_UNKNOWN_ISSUER error. What 
> certificate did Firefox received from Squid (that triggered that 
> error)? Did it get (A)?
>
> There is usually a way to examine the received certificate in Firefox 
> despite SEC_ERROR_UNKNOWN_ISSUER, but I do not have a step-by-step 
> instructions for that. When examining the certificate, look for 
> Subject and Issuer fields. Do they match those of certificate (A) used 
> for working (i.e. no browser error) transactions? If not, what are 
> they, and does the issuer match the Subject field in CA certificate (B)?
>
now hotmail and linkedin are opening, except yandex is not. in the 
certificate it shows:
subject: country:ru
organization yandex
issuer: the squid certificate that all for certificate *.yandex.tr on 
the the right there is a second certificate of squid: Subject is what i 
filled in when i generated the certificate and so is issuer and 
everything else.
> HTH,
>
> Alex.
>
>
>
>>>>> now the conf reconfigured is:
>>>>> http_port 8080 ssl-bump 
>>>>> cert=/etc/squid/certs/squid-ca-cert-key.pem 
>>>>> generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20260730/86ee1c8a/attachment.htm>


More information about the squid-users mailing list