Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-31 Thread Amos Jeffries
On 23/07/2015 2:41 a.m., Alex Wu wrote: We do not use cache-peer. I thought cache-peer is for connecting another squid-like proxy server. Historically yes. In Squid-3 it is for connecting to any specific upstream server. The correct way to send traffic over TLS/SSL to an intranet server is

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-22 Thread Alex Wu
we can intercept HTTP requests at squid, Alex To: squid-users@lists.squid-cache.org From: squ...@treenet.co.nz Date: Thu, 23 Jul 2015 00:21:31 +1200 Subject: Re: [squid-users] SSL connction failed due to SNI after content redirection On 22/07/2015 12:44 p.m., Alex Wu wrote: it depends

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-22 Thread Amos Jeffries
On 22/07/2015 12:44 p.m., Alex Wu wrote: it depends on how you set up squid, and where the connection is broken. The patch addessed the issue that occured using sslbump and content redirect together. I'd like some clarification what the exact problem symptoms are please. AFAIK, both

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-21 Thread Alex Wu
-users] SSL connction failed due to SNI after content redirection i have some thing like this issue ssl connection failed when using in mobile apps your patch dont solve the problem how i can tune what cause this problem ? thanks. -- View this message in context: http://squid

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-21 Thread HackXBack
i have some thing like this issue ssl connection failed when using in mobile apps your patch dont solve the problem how i can tune what cause this problem ? thanks. -- View this message in context:

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-21 Thread HackXBack
:~/squid-3.5.6-20150716-r13865# patch -p0 --verbose sni.patch Hmm... Looks like a unified diff to me... The text leading up to this was: -- |--- src/ssl/PeerConnector.cc |+++ src/ssl/PeerConnector.cc -- Patching file src/ssl/PeerConnector.cc using

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-21 Thread Alex Wu
To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] SSL connction failed due to SNI after content redirection :~/squid-3.5.6-20150716-r13865# patch -p0 --verbose sni.patch Hmm... Looks like a unified diff to me... The text leading up

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-21 Thread HackXBack
~/squid-3.5.6-20150716-r13865# patch -p0 --verbose sni.patch Hmm... Looks like a unified diff to me... The text leading up to this was: -- |diff --git src/ssl/PeerConnector.cc src/ssl/PeerConnector.cc |index b4dfd8f..d307665 100644 |--- src/ssl/PeerConnector.cc |+++

[squid-users] SSL connction failed due to SNI after content redirection

2015-07-20 Thread Alex Wu
With 3.5.6 code, we found one thing is broken. We used pyredir to rewrite request to a surrogated server enabled SSL connection. Also, we enable this in squid.conf: url_rewrite_host_header on We expect a request to www.foo.com is changed to www.foo-internal.com. squid sends the request

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-20 Thread Alex Rousskov
On 07/20/2015 11:28 AM, Alex Wu wrote: With 3.5.6 code, we found one thing is broken. We used pyredir to rewrite request to a surrogated server enabled SSL connection. Also, we enable this in squid.conf: url_rewrite_host_header on We expect a request to www.foo.com is changed to

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-20 Thread Alex Wu
if I can get squid-dev. Alex Date: Mon, 20 Jul 2015 13:10:26 -0600 From: rouss...@measurement-factory.com To: alex_wu2...@hotmail.com; squid-users@lists.squid-cache.org Subject: Re: [squid-users] SSL connction failed due to SNI after content redirection On 07/20/2015 11:28 AM, Alex Wu

Re: [squid-users] SSL connction failed due to SNI after content redirection

2015-07-20 Thread Alex Wu
); Ssl::setClientSNI(ssl, sniServer); Alex From: alex_wu2...@hotmail.com To: rouss...@measurement-factory.com; squid-users@lists.squid-cache.org Date: Mon, 20 Jul 2015 12:34:05 -0700 Subject: Re: [squid-users] SSL connction failed due to SNI after content redirection That's right, It should