• Why is a certificate needed for squid reverse https?

    4
    0 Votes
    4 Posts
    2k Views
    K
    A slightly longer answer is that any SSL/TLS endpoint that is going to decrypt and authenticate incoming HTTPS connections MUST have a certificate because it's the cryptographic identification and authentication of a peer. If an SSL/TLS server you're connecting to claims to be 'www.example.tld' it must present a certificate (preferably signed by a trusted third party so it verifies correctly) with a CN (common name) 'www.example.tld', otherwise the SSL/TLS handshake will be aborted if the server can not present such certificate.
  • Group acl on squidguard not working please help

    2
    0 Votes
    2 Posts
    1k Views
    G
    try this ldapusersearch ldap://dc1.domain.com.uy:3268/dc=domain,dc=com,dc=uy?sAMAccountName?sub?(&(sAMAccountName=%s)(memberOf=CN=Internet,OU=Grupos,dc=domain,dc=com,dc=uy)) "Internet" is my AD group located at "OU=Grupos"
  • SquidGuard - can't download/extract blacklist

    3
    0 Votes
    3 Posts
    4k Views
    D
    All I can suggest here is starting a bounty for a complete package rewrite. Apparently noone will touch the current buggy code, since it's completely unreadable mess. Unfixable. Alternatively, get some blocklists in Squid's ACL format and use those.
  • "Bypass Proxy for These Source IPs" Bug

    3
    0 Votes
    3 Posts
    1k Views
    D
    (And, FWIW, about 99% sure this has completely nothing to do with "Bypass Proxy for These Source IPs" or any other Squid configuration. If you cleared whatever other fields, or simple re-saved the Squid config without doing any changes whatsoever, it'd have the same effect (restarting services, reloading firewall, working again until it breaks for god knows what reason…)
  • Squid/transparent proxy improperly intercepting SSL?

    3
    0 Votes
    3 Posts
    2k Views
    T
    @doktornotor: It is intercepting just fine. Recently discussed in the proper forum. If things break, use the manual config, or don't MITM. apologies if I wasn't clear in my post - I am not implementing MITM and have never enabled it.  It would appear that while all other SSL traffic bypasses the proxy just fine (as intended), this one API call with the :443 appended may indeed be SSL but is attempting to go through the proxy.
  • Modify SSL User Agent Header

    6
    0 Votes
    6 Posts
    2k Views
    ?
    that's correct.
  • How to remove Request denied by pfsense proxy

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    That block of text is configurable in squidGuard's options.
  • How Personalize reports on lightsquid

    1
    0 Votes
    1 Posts
    520 Views
    No one has replied
  • How do I change Blacklists settings in squid + squidguard?

    6
    0 Votes
    6 Posts
    4k Views
    S
    @doktornotor: @sprinteroz: I found the setting in pfblockerBg that you where talking about but i could not work out what you meant by Force Reload all. Click the Update tab. Ok thanks done… Just a quick question before i install squidguard again how do i change the lists in squadguard once its installed encase I would like to add or remover rules on the lists.
  • Besides lightsquid, any other better reporting tool for pfsense

    2
    0 Votes
    2 Posts
    901 Views
    D
    Not ATM, no. Offload it to a logserver and do whatever you want with that, perhaps. (ELK, …)
  • LightSquid, Captive Portal Codes as User

    1
    0 Votes
    1 Posts
    594 Views
    No one has replied
  • Help with HAProxy URL rewrite

    2
    0 Votes
    2 Posts
    1k Views
    N
    would you mind telling me the model of Sophos UTM that you have before?
  • FTP Client Proxy Restrictions

    1
    0 Votes
    1 Posts
    589 Views
    No one has replied
  • Mixed content warning when using SSL offloading in HAProxy

    5
    0 Votes
    5 Posts
    2k Views
    W
    Inspecting the blocked content it all seems local to me, can't see any other domain names in it than just the domain name the site is running.
  • LightSquid service not running

    5
    0 Votes
    5 Posts
    2k Views
    T
    Awesome. I can confirm that the lightsquid_web is now running after the update.
  • HAProxy randomly "failing", need to restart service to fix

    3
    0 Votes
    3 Posts
    677 Views
    P
    I would move webgui to a non-standard port like 1443 or something, and disable the webgui-redirect.. Then at least you wont unintentionally end up on the webgui when trying to visit the wan-ip.
  • Filtering HTTPS

    5
    0 Votes
    5 Posts
    1k Views
    D
    Content filtering == you can see the real content. Terminology mixup I guess. You cannot filter the content you do not see. http://wiki.squid-cache.org/Features/SslPeekAndSplice
  • MITM error with C-ICAP

    2
    0 Votes
    2 Posts
    662 Views
    D
    Sorry, there is no support for packages on pfSense on 2.2.x. Also, the Squid version plus related packages there are extremely outdated and not really offering any of the recent features.
  • Lightsquid not working on New update

    11
    0 Votes
    11 Posts
    4k Views
    D
    Well, at least things work now. (I certainly won't be able to debug any SIGSEGV issues there, my experience is that it was a HW issue ~95% of time. If not RAM, then CPU overheating, or bad PSU with unstable voltage.) If it's a bug with Squid, you'd need to move this to Squid mailing list or generally upstream, nothing pfSene specific there.
  • HAProxy - cannot load balance https - please can someone answer ?

    3
    0 Votes
    3 Posts
    530 Views
    P
    ok finaly I had to remove my domain name in the apache virtual host tag, replacing it by *.80 dont know why it was there in the tutorial
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.