<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body text="#26a269" bgcolor="#000000">
<br>
<br>
<div class="moz-cite-prefix">23.07.2026 12:53, Andrey K пишет:<br>
</div>
<blockquote type="cite"
cite="mid:CADJd0Y0ww6v4o6Z2VTXiVxLvDgcXxzJztX-8cDkc9S=W=KddUA@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<div dir="ltr">Hello, Vacheslav,
<div><br>
</div>
<div>It seems that the logs from 2026/07/23 no longer show any
security_file_certgen crashes, but the browser errors are
still there. Is it possible that the browsers are simply
rejecting the new proxy certificate because it's not
trusted?</div>
</div>
</div>
</blockquote>
even though i imported the new certificate, the browser was using
the old certificate with the same certificate name, so i reissued
the new der certificate and imported it into firefox and now it
visible as the new certificate but the websites are not opening as
they display a mixed certificate between the site and the squid
certificate.<br>
now the conf reconfigured is:<br>
http_port 8080 ssl-bump cert=/etc/squid/certs/squid-ca-cert-key.pem
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB<br>
<br>
<blockquote type="cite"
cite="mid:CADJd0Y0ww6v4o6Z2VTXiVxLvDgcXxzJztX-8cDkc9S=W=KddUA@mail.gmail.com">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
</div>
<br>
<div class="gmail_quote gmail_quote_container">
<div dir="ltr" class="gmail_attr">On 23.07.2026 08:22,
Vacheslav <<a href="mailto:m_zouhairy@ckta.by"
moz-do-not-send="true" class="moz-txt-link-freetext">m_zouhairy@ckta.by</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div bgcolor="#000000"> <br>
<br>
<div>20.07.2026 20:15, Alex Rousskov пишет:<br>
</div>
<blockquote type="cite">On 2026-07-20 01:27, Vacheslav
wrote: <br>
<blockquote type="cite">17.07.2026 15:44, Alex Rousskov
пишет: <br>
<blockquote type="cite">On 2026-07-17 01:31, Vacheslav
wrote: <br>
<br>
<blockquote type="cite">16.07.2026 18:19, Andrey K
пишет: <br>
<blockquote type="cite">@Vacheslav: <br>
> sudo
/usr/libexec/squid/security_file_certgen -c -s <br>
> /var/cache/squid/ssl_db/certs -M 4MB <br>
You specified the wrong path (the correct one is
/var/cache/squid/ssl_db ). <br>
</blockquote>
<br>
<br>
good catch: <br>
now running: <br>
sudo -u squid
/usr/libexec/squid/security_file_certgen -s
/var/cache/squid/ssl_db -M 4MB <br>
^C <br>
produces nothing. <br>
</blockquote>
<br>
That lack of output is a good sign -- the helper
managed to start successfully. <br>
<br>
<br>
<blockquote type="cite">2026/07/17 08:21:33 kid1|
WARNING: sslcrtd_program #Hlpr1 exited <br>
</blockquote>
<br>
Helpers are still dying, but it looks like they do
it while handling traffic. <br>
<br>
<br>
<blockquote type="cite">
<blockquote type="cite">2. Redirect
security_file_certgen stderr (but not stdout!)
output <br>
into a dedicated log file. It may be possible to
do that right on <br>
the sslcrtd_program line, without wrapping the
helper into another <br>
script. <br>
</blockquote>
</blockquote>
<br>
<blockquote type="cite">how to do that? <br>
</blockquote>
<br>
Try using shell redirection when specifying how to
run the helper. Something along these lines may
work: <br>
<br>
sslcrtd_program /usr/local/... -M 4MB >>
/tmp/sslcrtd.error.log <br>
</blockquote>
</blockquote>
<br>
<br>
My bad. I missed "2" to redirect stderr rather than
stdout. Fixed below. The missing file descriptor is
_not_ the reason your test is not working though (as
detailed below). <br>
<br>
<br>
<blockquote type="cite">now the configuration looks like
this: <br>
<br>
sslcrtd_program
/usr/libexec/squid/security_file_certgen -s
/var/cache/squid/ssl_db -M 4MB >>
/tmp/sslcrtd.error.log <br>
</blockquote>
<br>
<br>
To capture stderr: <br>
<br>
sslcrtd_program /usr/libexec/squid/security_file_certgen
-s <br>
/var/cache/squid/ssl_db -M 4MB 2>>
/tmp/sslcrtd.error.log <br>
<br>
<br>
<blockquote type="cite">in tmp there is no
sslcrtd.error.log file. <br>
</blockquote>
<br>
<br>
AFAICT, your Squid does not start sslcrtd_program
helper. What does "squid -v" say? If there is no
'--enable-ssl-crtd' there, then you need to rebuild your
Squid executable from scratch. Also, at least one
http_port or https_port directive in your squid.conf
should have both "generate-host-certificates" and
"ssl-bump" options. <br>
</blockquote>
<br>
sudo squid -v | grep "enable-ssl-crtd"<br>
........'--enable-arp-acl'
'--enable-ssl-crtd'.............<br>
<br>
<blockquote type="cite">When done right, you should see
the debugging file created in /tmp/ and, in cache log,
Squid logging "Starting ..." lines mentioning your
helper (similar to your existing lines for the
ufdbgclient helper). <br>
</blockquote>
here is the configuration with the 8080 sslbump port open:<br>
<br>
<br>
forwarded_for delete<br>
<br>
delay_pools 1<br>
delay_class 1 3<br>
delay_access 1 allow slower<br>
delay_access 1 deny all<br>
delay_parameters 1 128000/128000 -1/-1 128000/64000<br>
<br>
http_access allow localnet <br>
http_access allow localhost<br>
<br>
<br>
<br>
# And finally deny all other access to this proxy<br>
http_access deny all<br>
<br>
# Squid normally listens to port 3128<br>
#http_port 8080<br>
<br>
<br>
<br>
http_port 8080 ssl-bump cert=/etc/squid/certs/myCA.pem
generate-host-certificates=on
dynamic_cert_mem_cache_size=8MB<br>
<br>
<br>
<br>
<br>
##acl step1 at_step SslBump1 <br>
##ssl_bump peek step1 <br>
##ssl_bump bump all<br>
<br>
##sslcrtd_program /usr/libexec/squid/security_file_certgen
-s /var/lib/squid/ssl_db -M 4MB<br>
##sslcrtd_children 5<br>
<br>
acl tls_s1_connect at_step SslBump1<br>
acl tls_s2_client_hello at_step SslBump2<br>
acl tls_s3_server_hello at_step SslBump3<br>
<br>
# define acls for sites that must not be actively bumped<br>
<br>
acl tls_allowed_hsts ssl::server_name
.<a href="http://akamaihd.net" target="_blank"
moz-do-not-send="true">akamaihd.net</a><br>
acl tls_allowed_hsts ssl::server_name
.<a href="http://proxy.skko.by" target="_blank"
moz-do-not-send="true">proxy.skko.by</a><br>
#acl tls_server_is_bank ssl::server_name
.<a href="http://abnamro.nl" target="_blank"
moz-do-not-send="true">abnamro.nl</a><br>
#acl tls_server_is_bank ssl::server_name
.<a href="http://abnamro.com" target="_blank"
moz-do-not-send="true">abnamro.com</a><br>
acl tls_server_is_bank ssl::server_name
"/usr/local/ufdbguard/blacklists/finance/domains.squidsplice"<br>
acl tls_to_splice any-of
tls_allowed_hsts tls_server_is_bank<br>
<br>
# TLS/SSL bumping steps<br>
<br>
ssl_bump peek tls_s1_connect
# peek at TLS/SSL connect data<br>
ssl_bump splice tls_to_splice
# splice some: no active bump<br>
ssl_bump stare all
# stare(peek) at server<br>
#
properties of the webserver<br>
ssl_bump bump #
bump if we can (if the stare succeeded)<br>
<br>
ssl_bump peek tls_s1_connect<br>
ssl_bump splice all<br>
<br>
<br>
#ssl_bump peek all<br>
############ssl_bump splice all<br>
<br>
<br>
sslcrtd_program /usr/libexec/squid/security_file_certgen
-s /var/cache/squid/ssl_db -M 4MB 2>>
/tmp/sslcrtd.error.log<br>
sslcrtd_children 1 startup=1 idle=1<br>
<br>
ssl_bump server-first all<br>
<br>
sslproxy_cert_error allow all<br>
<br>
#tls_outgoing_options
options=NO_SSLv3,SINGLE_DH_USE,SINGLE_ECDH_USE
cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS<br>
<br>
# Uncomment and adjust the following to add a disk cache
directory.<br>
# Updates: chrome and acrobat<br>
#refresh_pattern -i <a
href="http://gvt1.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)"
target="_blank" moz-do-not-send="true">gvt1.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)</a>
43200 80% 129600 reload-into-ims<br>
#refresh_pattern -i <a
href="http://adobe.com/.*%5C.(exe%7Cms%5Bi%7Cu%7Cf%7Cp%5D%7Cdat%7Czip%7Cpsf)"
target="_blank" moz-do-not-send="true">adobe.com/.*\.(exe|ms[i|u|f|p]|dat|zip|psf)</a>
43200 80% 129600 reload-into-ims<br>
<br>
<br>
<br>
#range_offset_limit 200 MB <br>
#maximum_object_size 200 MB<br>
#quick_abort_min -1<br>
<br>
# DONT MODIFY THESE LINES<br>
#refresh_pattern \^ftp: 1440 20% 10080<br>
#refresh_pattern \^gopher: 1440 0% 1440<br>
#refresh_pattern -i (/cgi-bin/|\?) 0 0% 0<br>
#refresh_pattern . 0 20% 43200<br>
<br>
cache_dir ufs /var/cache/squid 3000 16 256<br>
<br>
# Leave coredumps in the first cache dir<br>
coredump_dir /var/cache/squid<br>
<br>
cache_mem 960 MB<br>
<br>
netdb_filename none<br>
<br>
logformat squidx %err_code/%err_detail<br>
#access_log daemon:/var/log/squid/accessX.log squidx<br>
#access_log squidx<br>
<br>
#<br>
# Add any of your own refresh_pattern entries above these.<br>
#<br>
refresh_pattern ^ftp: 1440 20% 10080<br>
refresh_pattern ^gopher: 1440 0% 1440<br>
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0<br>
refresh_pattern . 0 20% 4320<br>
<br>
url_rewrite_extras "%>a/%>A %un %>rm
bump_mode=%ssl::bump_mode sni=\"%ssl::>sni\"
referer=\"%{Referer}>h\""<br>
url_rewrite_program /usr/local/ufdbguard/bin/ufdbgclient
-m 4 -l /var/log/squid/<br>
url_rewrite_children 16 startup=8 idle=2 concurrency=4
queue-size=64<br>
#debug_options ALL,1 33,2 28,9<br>
<br>
<blockquote type="cite">HTH, <br>
<br>
Alex. </blockquote>
<br>
i finally noticed an empty sslcrtd.error.log file in /tmp
created on 20.07.2026, for some reason i was looking for a
folder, stupid me.<br>
<br>
i'm getting certificate errors when browsing sites in
firefox. some sites provide a warning to proceed to site
(dangerous) other sites just put 3 tab one of them is to
see the certificate.<br>
<br>
here is the cache.log:<br>
<br>
<br>
2026/07/23 07:32:59 kid1| Processing Configuration File:
/etc/squid/squid.conf (depth 0)<br>
2026/07/23 07:32:59 kid1| Set Current Directory to
/var/cache/squid<br>
2026/07/23 07:32:59 kid1| Starting Squid Cache version 7.6
for x86_64-suse-linux-gnu...<br>
2026/07/23 07:32:59 kid1| Service Name: squid<br>
2026/07/23 07:32:59 kid1| Process ID 3183<br>
2026/07/23 07:32:59 kid1| Process Roles: worker<br>
2026/07/23 07:32:59 kid1| With 4096 file descriptors
available<br>
2026/07/23 07:32:59 kid1| Initializing IP Cache...<br>
2026/07/23 07:32:59 kid1| DNS IPv4 socket created at
0.0.0.0, FD 7<br>
2026/07/23 07:32:59 kid1| Adding nameserver 10.16.30.46
from /etc/resolv.conf<br>
2026/07/23 07:32:59 kid1| Adding nameserver 10.10.10.5
from /etc/resolv.conf<br>
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 1/1
'security_file_certgen' processes<br>
2026/07/23 07:32:59 kid1| helperOpenServers: Starting 8/16
'ufdbgclient' processes<br>
2026/07/23 07:32:59 kid1| Logfile: opening log
daemon:/var/log/squid/access.log<br>
2026/07/23 07:32:59 kid1| Logfile Daemon: opening log
/var/log/squid/access.log<br>
2026/07/23 07:33:00 kid1| Unlinkd pipe opened on FD 31<br>
2026/07/23 07:33:00 kid1| Local cache digest enabled;
rebuild/rewrite every 3600/3600 sec<br>
2026/07/23 07:33:00 kid1| Store logging disabled<br>
2026/07/23 07:33:00 kid1| Swap maxSize 3072000 + 983040
KB, estimated 311926 objects<br>
2026/07/23 07:33:00 kid1| Target number of buckets: 15596<br>
2026/07/23 07:33:00 kid1| Using 16384 Store buckets<br>
2026/07/23 07:33:00 kid1| Max Mem size: 983040 KB<br>
2026/07/23 07:33:00 kid1| Max Swap size: 3072000 KB<br>
2026/07/23 07:33:00 kid1| Rebuilding storage in
/var/cache/squid (clean log)<br>
2026/07/23 07:33:00 kid1| Using Least Load store dir
selection<br>
2026/07/23 07:33:00 kid1| Set Current Directory to
/var/cache/squid<br>
2026/07/23 07:33:00 kid1| Finished loading MIME types and
icons.<br>
2026/07/23 07:33:00 kid1| HTCP Disabled.<br>
2026/07/23 07:33:00 kid1| Pinger socket opened on FD 36<br>
2026/07/23 07:33:00 kid1| Squid plugin modules loaded: 0<br>
2026/07/23 07:33:00 kid1| Adaptation support is off.<br>
2026/07/23 07:33:00 kid1| Accepting SSL bumped HTTP Socket
connections at conn20 local=<a href="http://0.0.0.0:8080"
target="_blank" moz-do-not-send="true">0.0.0.0:8080</a>
remote=[::] FD 34 flags=9<br>
listening port: 8080<br>
2026/07/23 07:33:00 pinger| WARNING: BCP 177 violation.
Detected non-functional IPv6 loopback.<br>
2026/07/23 07:33:00 pinger| Initialising ICMP pinger ...<br>
2026/07/23 07:33:00 pinger| ICMP socket opened.<br>
2026/07/23 07:33:00 pinger| ICMPv6 socket opened<br>
2026/07/23 07:33:00 kid1| Indexing cache entries: 1.84%
(4000 out of 216863)<br>
2026/07/23 07:33:03 kid1| Done reading /var/cache/squid
swaplog (216862 entries)<br>
2026/07/23 07:33:03 kid1| Finished rebuilding storage from
disk.<br>
216862 Entries scanned<br>
0 Invalid entries<br>
0 With invalid flags<br>
216862 Objects loaded<br>
0 Objects expired<br>
0 Objects canceled<br>
0 Duplicate URLs purged<br>
0 Swapfile clashes avoided<br>
Took 3.16 seconds (68526.49 objects/sec).<br>
2026/07/23 07:33:03 kid1| Beginning Validation Procedure<br>
2026/07/23 07:33:03 kid1| Completed Validation Procedure<br>
Validated 216848 Entries<br>
store_swap_size = 2764352.00 KB<br>
2026/07/23 07:33:03 kid1| storeLateRelease: released 0
objects<br>
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
connection<br>
problem: failure<br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1<br>
current master transaction: master58<br>
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
connection<br>
problem: failure<br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
current master transaction: master58<br>
2026/07/23 07:33:03 kid1| ERROR: Cannot accept a TLS
connection<br>
problem: failure<br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1<br>
current master transaction: master58<br>
.........<br>
<br>
<br>
<blockquote type="cite">
<blockquote type="cite">
<blockquote type="cite">
<blockquote type="cite">2026/07/17 08:17:35|
Removing PID file (/run/squid.pid) <br>
2026/07/17 08:18:54| WARNING: BCP 177 violation.
Detected non-functional IPv6 loopback. <br>
2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
not been enabled. <br>
acl name: to_localhost <br>
configuration context: Default
Configuration(15) acl <br>
2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
not been enabled. <br>
acl name: to_localhost <br>
configuration context: Default
Configuration(15) acl <br>
2026/07/17 08:18:54| aclIpParseIpData: IPv6 has
not been enabled. <br>
acl name: to_linklocal <br>
configuration context: Default
Configuration(16) acl <br>
2026/07/17 08:18:54| Processing Configuration
File: /etc/squid/squid.conf (depth 0) <br>
2026/07/17 08:18:55| Created PID file
(/run/squid.pid) <br>
2026/07/17 08:18:55 kid1| WARNING: BCP 177
violation. Detected non-functional IPv6 loopback.
<br>
2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
has not been enabled. <br>
acl name: to_localhost <br>
configuration context: Default
Configuration(15) acl <br>
2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
has not been enabled. <br>
acl name: to_localhost <br>
configuration context: Default
Configuration(15) acl <br>
2026/07/17 08:18:55 kid1| aclIpParseIpData: IPv6
has not been enabled. <br>
acl name: to_linklocal <br>
configuration context: Default
Configuration(16) acl <br>
2026/07/17 08:18:55 kid1| Processing Configuration
File: /etc/squid/squid.conf (depth 0) <br>
2026/07/17 08:18:55 kid1| Set Current Directory to
/var/cache/squid <br>
2026/07/17 08:18:55 kid1| Starting Squid Cache
version 7.6 for x86_64-suse-linux-gnu... <br>
2026/07/17 08:18:55 kid1| Service Name: squid <br>
2026/07/17 08:18:55 kid1| Process ID 3685 <br>
2026/07/17 08:18:55 kid1| Process Roles: worker <br>
2026/07/17 08:18:55 kid1| With 4096 file
descriptors available <br>
2026/07/17 08:18:55 kid1| Initializing IP Cache...
<br>
2026/07/17 08:18:55 kid1| DNS IPv4 socket created
at 0.0.0.0, FD 7 <br>
2026/07/17 08:18:55 kid1| Adding nameserver
10.6.30.40 from /etc/resolv.conf <br>
2026/07/17 08:18:55 kid1| Adding nameserver
10.10.10.5 from /etc/resolv.conf <br>
2026/07/17 08:18:55 kid1| helperOpenServers:
Starting 5/5 'security_file_certgen' processes <br>
2026/07/17 08:18:55 kid1| helperOpenServers:
Starting 8/16 'ufdbgclient' processes <br>
2026/07/17 08:18:55 kid1| Logfile: opening log
daemon:/var/log/squid/access.log <br>
2026/07/17 08:18:55 kid1| Logfile Daemon: opening
log /var/log/squid/access.log <br>
2026/07/17 08:18:56 kid1| Unlinkd pipe opened on
FD 39 <br>
2026/07/17 08:18:56 kid1| Local cache digest
enabled; rebuild/rewrite every 3600/3600 sec <br>
2026/07/17 08:18:56 kid1| Store logging disabled <br>
2026/07/17 08:18:56 kid1| Swap maxSize 3072000 +
983040 KB, estimated 311926 objects <br>
2026/07/17 08:18:56 kid1| Target number of
buckets: 15596 <br>
2026/07/17 08:18:56 kid1| Using 16384 Store
buckets <br>
2026/07/17 08:18:56 kid1| Max Mem size: 983040 KB
<br>
2026/07/17 08:18:56 kid1| Max Swap size: 3072000
KB <br>
2026/07/17 08:18:56 kid1| Rebuilding storage in
/var/cache/squid (clean log) <br>
2026/07/17 08:18:56 kid1| Using Least Load store
dir selection <br>
2026/07/17 08:18:56 kid1| Set Current Directory to
/var/cache/squid <br>
2026/07/17 08:18:56 kid1| Finished loading MIME
types and icons. <br>
2026/07/17 08:18:56 kid1| HTCP Disabled. <br>
2026/07/17 08:18:56 kid1| Pinger socket opened on
FD 44 <br>
2026/07/17 08:18:56 kid1| Squid plugin modules
loaded: 0 <br>
2026/07/17 08:18:56 kid1| Adaptation support is
off. <br>
2026/07/17 08:18:56 kid1| Accepting SSL bumped
HTTP Socket connections at conn28 local=<a
href="http://0.0.0.0:8080" target="_blank"
moz-do-not-send="true">0.0.0.0:8080</a>
remote=[::] FD 42 flags=9 <br>
listening port: 8080 <br>
2026/07/17 08:18:56 pinger| WARNING: BCP 177
violation. Detected non-functional IPv6 loopback.
<br>
2026/07/17 08:18:56 pinger| Initialising ICMP
pinger ... <br>
2026/07/17 08:18:56 pinger| ICMP socket opened. <br>
2026/07/17 08:18:56 pinger| ICMPv6 socket opened <br>
2026/07/17 08:18:56 kid1| Indexing cache entries:
1.84% (4000 out of 217945) <br>
2026/07/17 08:18:59 kid1| Done reading
/var/cache/squid swaplog (217944 entries) <br>
2026/07/17 08:18:59 kid1| Finished rebuilding
storage from disk. <br>
217944 Entries scanned <br>
0 Invalid entries <br>
0 With invalid flags <br>
217944 Objects loaded <br>
0 Objects expired <br>
0 Objects canceled <br>
0 Duplicate URLs purged <br>
0 Swapfile clashes avoided <br>
Took 2.85 seconds (76435.29 objects/sec). <br>
2026/07/17 08:18:59 kid1| Beginning Validation
Procedure <br>
2026/07/17 08:18:59 kid1| Completed Validation
Procedure <br>
Validated 217930 Entries <br>
store_swap_size = 2764788.00 KB <br>
2026/07/17 08:18:59 kid1| storeLateRelease:
released 0 objects <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master55 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master55 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master55 <br>
2026/07/17 08:18:59 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
<br>
........ <br>
<br>
2026/07/17 08:21:32 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:21:32 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000416+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:21:33 kid1| ERROR: Cannot accept a
TLS connection <br>
problem: failure <br>
error detail:
SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=A000418+TLS_IO_ERR=1
<br>
current master transaction: master57 <br>
2026/07/17 08:21:33 kid1| WARNING: sslcrtd_program
#Hlpr1 exited <br>
current master transaction: master57 <br>
2026/07/17 08:21:33 kid1| Too few sslcrtd_program
processes are running (need 1/5) <br>
active processes: 4 <br>
processes configured to start at
(re)configuration: 5 <br>
current master transaction: master57 <br>
2026/07/17 08:21:33 kid1| helperOpenServers:
Starting 1/5 'security_file_certgen' processes <br>
current master transaction: master57 <br>
2026/07/17 08:21:33 kid1| Preparing for shutdown
after 761 requests <br>
2026/07/17 08:21:33 kid1| Waiting 30 seconds for
active connections to finish <br>
2026/07/17 08:21:33 kid1| Closing HTTP(S) port <a
href="http://0.0.0.0:8080" target="_blank"
moz-do-not-send="true">0.0.0.0:8080</a> <br>
listening port: 8080 <br>
2026/07/17 08:21:33 kid1| Closing Pinger socket on
FD 44 <br>
2026/07/17 08:21:33 kid1| ERROR:
logfileHandleWrite:
daemon:/var/log/squid/access.log: error writing
((32) Broken pipe) <br>
connection: conn2846 local=<a
href="http://10.0.0.18:8080" target="_blank"
moz-do-not-send="true">10.0.0.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| storeDirWriteCleanLogs:
Starting... <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| 65536 entries
written so far. <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| 131072 entries
written so far. <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| 196608 entries
written so far. <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| Finished. Wrote
217944 entries. <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| Took 0.08 seconds
(2736133.78 entries/sec). <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.16.0.7:53255"
target="_blank" moz-do-not-send="true">10.16.0.7:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| FATAL: I don't handle
this error well! <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
2026/07/17 08:21:33 kid1| Squid Cache (Version
7.6): Terminated abnormally. <br>
connection: conn2846 local=<a
href="http://10.10.10.18:8080" target="_blank"
moz-do-not-send="true">10.10.10.18:8080</a>
remote=<a href="http://10.1.0.17:53255"
target="_blank" moz-do-not-send="true">10.1.0.17:53255</a>
flags=1 <br>
CPU Usage: 10.098 seconds = 7.758 user + 2.340 sys
<br>
Maximum Resident Size: 314320 KB <br>
Page faults with physical i/o: 0 <br>
<blockquote type="cite"> <br>
To recreate a certificate database you should
do: <br>
<br>
sudo rm -rf /var/cache/squid/ssl_db <br>
sudo /usr/libexec/squid/security_file_certgen -c
-s /var/cache/squid/ssl_db -M 4MB <br>
sudo chown -R squid:squid
/var/cache/squid/ssl_db <br>
<br>
чт, 16 июл. 2026 г. в 16:36, Alex Rousskov <a
href="mailto:rousskov@measurement-factory.com"
target="_blank" moz-do-not-send="true"><rousskov@measurement-factory.com></a>:
<br>
<br>
On 2026-07-16 01:57, Vacheslav wrote: <br>
<br>
> 2026/07/16 08:34:24 kid1| WARNING:
sslcrtd_program #Hlpr1 exited <br>
<br>
We need to figure out why your
security_file_certgen helpers are <br>
exiting. IIRC, those helpers have not been
upgraded to report their <br>
fatal failures to cache.log. There are a few
tricks you can use to <br>
see <br>
what the problem is, but I would probably
start with these three: <br>
<br>
1. Run security_file_certgen with
sslcrtd_program parameters from the <br>
command line, as Squid user. If you are
lucky, it will complain about <br>
something before it starts waiting for the
helper request. <br>
<br>
2. Redirect security_file_certgen stderr
(but not stdout!) output <br>
into a <br>
dedicated log file. It may be possible to do
that right on the <br>
sslcrtd_program line, without wrapping the
helper into another script. <br>
<br>
3. Enable full debugging, reproduce the
problem with a single <br>
transaction, and send a link to the
corresponding compressed <br>
cache.log <br>
file for analysis as detailed at <br>
<a
href="https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction"
target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">https://wiki.squid-cache.org/SquidFaq/BugReporting#debugging-a-single-transaction</a>
<br>
<br>
<br>
Cheers, <br>
<br>
Alex. <br>
<br>
_______________________________________________
<br>
squid-users mailing list <br>
<a
href="mailto:squid-users@lists.squid-cache.org" target="_blank"
moz-do-not-send="true"
class="moz-txt-link-freetext">squid-users@lists.squid-cache.org</a>
<br>
<a
href="https://lists.squid-cache.org/listinfo/squid-users"
target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">https://lists.squid-cache.org/listinfo/squid-users</a>
<br>
<br>
</blockquote>
<br>
</blockquote>
<br>
</blockquote>
<br>
</blockquote>
<br>
</blockquote>
<br>
</div>
_______________________________________________<br>
squid-users mailing list<br>
<a href="mailto:squid-users@lists.squid-cache.org"
target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">squid-users@lists.squid-cache.org</a><br>
<a href="https://lists.squid-cache.org/listinfo/squid-users"
rel="noreferrer" target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">https://lists.squid-cache.org/listinfo/squid-users</a><br>
</blockquote>
</div>
</div>
</blockquote>
<br>
</body>
</html>