Re: [squid-users] Rewriting HTTP to HTTPS for generic package proxy

2024-07-14 Thread Fiehe, Christoph
The only solution I was currently able to get working, was to make use of an Apache server installed locally beside Squid. It acts as a reverse proxy and gets queried by Squid when the client requests an external resource via HTTP, but that resource must be accessed transparently for the client

Re: [squid-users] Rewriting HTTP to HTTPS for generic package proxy

2024-07-14 Thread Fiehe, Christoph
Hi Alex, sorry, I have not seen your message, yet. Thank you very much for your helping support. (A) I will try to find a way to test, how a new Squid build based on OpenSSL behaves under those circumstances. It will take some time. (B) Yes, Squid does nothing wrong, it is a very specific use

Re: [squid-users] Rewriting HTTP to HTTPS for generic package proxy

2024-07-14 Thread Fiehe, Christoph
I did some more debugging and I think that I have found the cause why the issue occurs in case (A). As Alex already explained, in case (A) the child proxy forwards the rewritten request e.g. a GET request containing a HTTPS URL, to the parent proxy. Now the parent proxy is in charge to establish

Re: [squid-users] Tproxy or intercept

2024-07-14 Thread Andrea Venturoli
On 7/13/24 20:48, Jonathan Lee wrote: It works 6.6 it just have a different requirement to enable it. I am using a Netgate 2100 with pfSense. The difference is that it spoofs the IP of the client so the host doesn’t see the IP of the firewall when using intercept I am told. So transparent with

Re: [squid-users] Tproxy or intercept

2024-07-14 Thread Jonathan Lee
IPv4 only ips, I have a BE with tunnel broker that I test out but my IPS IDS can’t inspect the tunnel Sent from my iPhone > On Jul 14, 2024, at 22:49, Andrea Venturoli wrote: > > On 7/13/24 20:48, Jonathan Lee wrote: >> It works 6.6 it just have a different requirement to enable it. I am usin