Re: [squid-users] dh key too small

2021-02-16 Thread Alex Rousskov
On 2/15/21 4:42 PM, Marek Greško wrote: > Hello, > > most probably the problem is on the server side: > > openssl s_client -connect www.p-mat.sk:443 -tls1 > CONNECTED(0003) > depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3 > verify return:1 > depth=1 C = US, O = Let's Encrypt, CN

Re: [squid-users] dh key too small

2021-02-15 Thread Marek Greško
Hello, most probably the problem is on the server side: openssl s_client -connect www.p-mat.sk:443 -tls1 CONNECTED(0003) depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = p-mat.sk verify return:

[squid-users] dh key too small

2021-02-15 Thread Marek Greško
Hello, I am struggling with "ERROR: negotiating TLS on FD 53: error:141A318A:SSL routines:tls_process_ske_dhe:dh key too small (1/-1/0)" error when ssl bumping. I cannot find out where the problem liesand why is the key too small. I regenerated my dhparams with openssl dhparam -outform PEM -out d