Re: [squid-users] Reverse DNS lookups from squid logging port

2022-01-24 Thread Alex Rousskov
On 1/24/22 7:24 PM, Praveen Ponakanti wrote: > Hi, > > I am running squid versionĀ 4.17 and have not been able to disable the > reverse DNS lookups it does on each client's IP address. Found the > thread below that discusses this; I have attempted adding the following > config knobs, but it still

Re: [squid-users] 4.17 and 5.3 SSL BUMP issue: SSL_ERROR_RX_RECORD_TOO_LONG

2022-01-24 Thread Alex Rousskov
On 1/24/22 1:06 PM, Eliezer Croitoru wrote: > I sat for a while thinking what is the best approach to the subject and the > next patch seems to be reasonable enough to me: > https://gist.github.com/elico/630fa57d161b0c0b59ef68786d801589 > Let me know if this patch violates anything that I might

Re: [squid-users] 4.17 and 5.3 SSL BUMP issue: SSL_ERROR_RX_RECORD_TOO_LONG

2022-01-24 Thread Eliezer Croitoru
I sat for a while thinking what is the best approach to the subject and the next patch seems to be reasonable enough to me: https://gist.github.com/elico/630fa57d161b0c0b59ef68786d801589 Let me know if this patch violates anything that I might not took into account. Thanks, Eliezer * Tested to

Re: [squid-users] 4.17 and 5.3 SSL BUMP issue: SSL_ERROR_RX_RECORD_TOO_LONG

2022-01-24 Thread Alex Rousskov
On 1/24/22 2:42 AM, Eliezer Croitoru wrote: > 2022/01/24 09:11:20 kid1| SECURITY ALERT: Host header forgery detected on > local=142.250.179.228:443 remote=10.200.191.171:51831 FD 16 flags=33 (local > IP does not match any domain IP) As you know, Squid improvements related to these messages have