Re: [squid-users] squid-3.4.8 sslbump breaks facebook

2014-10-17 Thread Jason Haar
I applied the patch to 3.4.8, built it and reset the cache, and now facebook.com and youtube.com work when they caused the error before Well done - all sorted by the looks of it :-) Jason On 17/10/14 05:59, Christos Tsantilas wrote: > > A patch for this bug attached to 4102 bug report. > Please

Re: [squid-users] squid-3.4.8 sslbump breaks facebook

2014-10-16 Thread Christos Tsantilas
A patch for this bug attached to 4102 bug report. Please test it and report any problem. Regards, Christos On 10/16/2014 12:14 PM, Amm wrote: On 10/16/2014 02:35 PM, Jason Haar wrote: On 16/10/14 20:54, Jason Haar wrote: I also checked the ssl_db/certs dir and removed the facebook certs

Re: [squid-users] squid-3.4.8 sslbump breaks facebook

2014-10-16 Thread Amm
On 10/16/2014 02:35 PM, Jason Haar wrote: On 16/10/14 20:54, Jason Haar wrote: I also checked the ssl_db/certs dir and removed the facebook certs and restarted - didn't help let me rephrase that. I deleted the dirtree and re-ran "ssl_crtd -s /usr/local/squid/var/lib/ssl_db -c" - ie restarted w

Re: [squid-users] squid-3.4.8 sslbump breaks facebook

2014-10-16 Thread Jason Haar
On 16/10/14 20:54, Jason Haar wrote: > I also checked the ssl_db/certs dir and > removed the facebook certs and restarted - didn't help let me rephrase that. I deleted the dirtree and re-ran "ssl_crtd -s /usr/local/squid/var/lib/ssl_db -c" - ie restarted with an empty cache. It didn't help. It crea

[squid-users] squid-3.4.8 sslbump breaks facebook

2014-10-16 Thread Jason Haar
Hi there Weird. sslbump seems to be working well, even intercepts twitter.com fine under FF-33 (with it's pinning support, due to security.cert_pinning.enforcement_level=1) However, facebook.com generates a "sec_error_inadequate_key_usage" error. I cranked up debugging and see this. As you can se