Re: [squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-12 Thread nipun_mlist Assam
Thanks Eliezer/Amos for the hints. But I have some concerns here with SSLBUMP. Without proxy forwarding, SSL from client is terminated on squid and then squid does SSL with the orgin server. But when squid (with SSLBUMP enabled) connects internet via upstream proxy, it behaves different way.

Re: [squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-12 Thread Amos Jeffries
On 12/06/2012 7:33 p.m., nipun_mlist Assam wrote: Thanks Eliezer/Amos for the hints. But I have some concerns here with SSLBUMP. Without proxy forwarding, SSL from client is terminated on squid and then squid does SSL with the orgin server. But when squid (with SSLBUMP enabled) connects

[squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-11 Thread nipun_mlist Assam
Hi All, I have a configuration as given below: client -- downstream-proxy -- upstream-proxy --- cloud downstream proxy is always squid, while upstream proxy is either squid or bluecoat. When SSL termination enabled on downstream proxy, I noticed traffic between down-stream and

Re: [squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-11 Thread bnichols
On Mon, 11 Jun 2012 18:30:14 +0530 nipun_mlist Assam nipunml...@gmail.com wrote: Hi All, I have a configuration as given below: client -- downstream-proxy -- upstream-proxy --- cloud Im not sure what a cloud is, I think its called the internet. downstream proxy is always

Re: [squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-11 Thread Eliezer Croitoru
you can use two cache_peers fot he same host then name them differently with a name= and using a CONNECT method acl to allow access to the ssl encrypted upstream connection. Eliezer On 11/06/2012 16:00, nipun_mlist Assam wrote: Hi All, I have a configuration as given below: client--

Re: [squid-users] https traffic via cache peer with SSL termination enabled on downstream proxy

2012-06-11 Thread Amos Jeffries
On 12.06.2012 11:17, Eliezer Croitoru wrote: you can use two cache_peers fot he same host then name them differently with a name= and using a CONNECT method acl to allow access to the ssl encrypted upstream connection. Not quite. The downstream has terminated the TLS and Squid does not wrap