Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Stefan Reible
Zitat von Amos Jeffries : Leonardo Carneiro - Veltrac wrote: Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines all have a CA cert

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Amos Jeffries
Leonardo Carneiro - Veltrac wrote: Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines all have a CA certificate installed to make th

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Leonardo Carneiro - Veltrac
Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines all have a CA certificate installed to make them trust the proxy for decryption.

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-23 Thread Amos Jeffries
Stefan Reible wrote: Hi, I want to use https with the viralator (http ist working). I'm prerouting Port 80 to Port 3128 for http. Is there an option like https_port in my version? Now I want to set following option in squid.conf: http_port 3128 sslBump cert=/etc/squid/ssl_cert/proxy.testdoma

[squid-users] squid 3.0.19 + transparent + sslbump

2010-03-23 Thread Stefan Reible
Hi, I want to use https with the viralator (http ist working). I'm prerouting Port 80 to Port 3128 for http. Is there an option like https_port in my version? Now I want to set following option in squid.conf: http_port 3128 sslBump cert=/etc/squid/ssl_cert/proxy.testdomain.deCert.pem key=/