Re: [squid-users] dynamic ssl certificate generation - ip addresses

2013-11-01 Thread Lennert Rienau
Because you use client-first bumping on intercepted traffic. The only details Squid has at that point are the IP address and port the clients ws connecting to. You need server-first bumping to contact the server and find out what domain(s) its certificate indicate. Thank you for your

[squid-users] dynamic ssl certificate generation - ip addresses

2013-10-31 Thread Lennert Rienau
Hi, i want squid to create dynamic ssl certificates in intercept mode, which works, but squid uses ip-addresses for the certificates of the site, not the host name.   Does anybody know why this happens?   squid.conf: cache_effective_user squid cache_effective_group