Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid3 HTTPS and SNI

    Scheduled Pinned Locked Moved Cache/Proxy
    3 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deajan
      last edited by

      Hi,

      I've successfully setup a squid3 + clamav via icap transparent proxy on pfSense 2.2 x64.

      Now i try to use the MITM HTTPS functionnality, but it seems that Squid always uses the first SSL certificate of every server, without honoring SNI and selecting the right certificate for a given virtualhost.

      Is there anything that needs to be configured to HTTPS proxy uses SNI and fetches the right certificate ?

      Regards,
      Ozy.

      NetPOWER.fr - some opensource stuff for IT people

      1 Reply Last reply Reply Quote 0
      • W
        webstor
        last edited by

        Hi,

        please post your config or screenshoot.

        Thanx.

        1 Reply Last reply Reply Quote 0
        • D
          deajan
          last edited by

          Well i guess it was just too late for me to play with Squid.
          SNI is working indeed, the right client certificate is selected even on servers with multiple SSL certificates per vhost.

          Sorry for the post here :)

          NetPOWER.fr - some opensource stuff for IT people

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.