Задать вопрос
  • Squid 4.13 прозрачный прокси без подмены сертификата, ssl_error_rx_record_too_long, что_я_делаю_не _так?

    @inve22
    Приветствую!
    Кальмар 5, заработал с таким конфигом в транспарент прокси:
    acl localnet src 10.0.0.0/8
    acl localnet src 100.64.0.0/10
    acl localnet src 169.254.0.0/16
    acl localnet src 172.16.0.0/12
    acl localnet src 192.168.0.0/16
    acl SSL_ports port 443
    acl Safe_ports port 80
    acl Safe_ports port 21
    acl Safe_ports port 443
    acl Safe_ports port 70
    acl Safe_ports port 210
    acl Safe_ports port 1025-65535
    acl Safe_ports port 280
    acl Safe_ports port 488
    acl Safe_ports port 591
    acl Safe_ports port 777
    http_access deny !Safe_ports
    http_access deny CONNECT !SSL_ports
    http_access allow localhost manager
    http_access deny manager
    http_access deny to_localhost
    http_access allow localnet
    http_access allow localhost
    http_access deny all
    http_port 3128 intercept
    visible_hostname 127.0.0.1:80
    https_port 3129 intercept ssl-bump options=ALL:NO_SSLv3:NO_SSLv2 connection-auth=off cert=/etc/squid/squidCA.pem
    sslproxy_cert_error allow all
    ssl_bump splice all
    sslcrtd_program /usr/lib/squid/security_file_certgen -s /var/lib/squid/ssl_db -M 10MB
    coredump_dir /var/cache/squid
    refresh_pattern ^ftp:		1440	20%	10080
    refresh_pattern ^gopher:	1440	0%	1440
    refresh_pattern -i (/cgi-bin/|\?) 0	0%	0
    refresh_pattern .		0	20%	4320
    Ответ написан