N
N
Nikolai Kuznetsov2016-08-08 11:03:17
Squid
Nikolai Kuznetsov, 2016-08-08 11:03:17

conf: openSuse 13.2 squid transparent HTTPS. How to make it work?

Hi, Nikita!
I'm trying to start a transparent squid without changing certificates for HTTPS. Found your article, but I have openSuse 13.2.
It is not possible to install LibreSSL into the system, because this package crashes openSSL. A lot of things are tied to the last one. The same YaST.

I tried downloading the latest squid release from the stable ones: 3.5.20 I downloaded
openSSL: 1.0.2h and built squid with it.
Didn't collect any packages.
I just took the configuration options from the squid that was in the base package, added the --with-ssl=/path/to/sources/openssl_1.0.2h option there, configured and built it. After installation, Squid started up and worked in transparent mode for non-HTTPS traffic.
When trying to connect via HTTPS, an error appeared (after 2-5 seconds of waiting): ERROR: SSL_ERROR_RX_RECORD_TOO_LONG

Then I tried to rebuild also with LibreSSL. Same error.

At you in article patching of Squid is described. I understand that this is relevant only for the version of squid specified in the guide, and in my version everything that needs to be fixed is already there.

Did you have a similar error and in which direction to dig?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question