Re: [squid-users] The status of AIA ie: TLS code: X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY ?

2022-02-05 Thread Marcus Kool
I would have expected that the remote host ip:port and sni would be logged as well in the above mentioned line. SNI is one of the details TLS/1.3 encrypts now  :( To prevent misunderstandings, TLS 1.3 does not encrypt the SNI. See https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni

Re: [squid-users] The status of AIA ie: TLS code: X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY ?

2022-02-04 Thread Amos Jeffries
On 26/01/22 06:12, Eliezer Croitoru wrote: Hey, I have recently seen more then one site that doesn't provide the full CA bundle chain. An example: https://www.ssllabs.com/ssltest/analyze.html?d=www.cloudschool.org https://www.ssllabs.com/ssltest/analyze.html?d= certificatechain.io I wanted to

[squid-users] The status of AIA ie: TLS code: X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY ?

2022-01-25 Thread Eliezer Croitoru
Hey, I have recently seen more then one site that doesn't provide the full CA bundle chain. An example: https://www.ssllabs.com/ssltest/analyze.html?d=www.cloudschool.org https://www.ssllabs.com/ssltest/analyze.html?d= certificatechain.io I wanted to somehow get this issue logged properly.