Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid + https

    Scheduled Pinned Locked Moved Cache/Proxy
    52 Posts 5 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan
      last edited by

      Never used squid before, but I guess a CA should be created first.
      Here :

      74a3d27e-e644-474a-83cd-fb9855bbc874-image.png

      Then, based on the CA, you create your certs :

      9c04ee32-e19e-48b3-b689-f694aded4dc5-image.png

      These certs can be used in OpenVPN, FreeRadius, the pfSense GUI, etc.
      CA's can't be use directly, except for signing (your own) certs.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      DaddyGoD 1 Reply Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo @Gertjan
        last edited by

        @Gertjan said in Squid + https:

        Never used squid before, but I guess a CA should be created first.
        Here :

        exactly,
        use the pfSense certificate builder and then it will appear in Squid settings

        then you can also export it for installation on external devices

        like:
        b0e976f7-948a-4515-bedb-311e848e43c7-image.png

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        V 1 Reply Last reply Reply Quote 0
        • V
          viberua @DaddyGo
          last edited by

          @DaddyGo so if i don't want create new CA because i already have one, then i can't use this external CA cert in MITM?

          DaddyGoD T 2 Replies Last reply Reply Quote 0
          • DaddyGoD
            DaddyGo @viberua
            last edited by

            @viberua

            Squid works with an internal intermediate certificate
            you can't use example Lets' E or other

            because of what is described above in this thread......

            like:
            e6d85e91-20c0-4c72-994d-63130e5c6ab0-image.png

            d885c2db-48b4-4c2b-9e0c-6b930da4372b-image.png

            50fd8d7b-58eb-4c5c-ac9f-46ffaaa060e6-image.png

            Cats bury it so they can't see it!
            (You know what I mean if you have a cat)

            V 1 Reply Last reply Reply Quote 0
            • T
              techtester-m @viberua
              last edited by

              @viberua You need to "become" a CA (a local one of course) and have your own Public Key & Private Key in order for Squid to encrypt-decrypt.

              1 Reply Last reply Reply Quote 0
              • V
                viberua @DaddyGo
                last edited by

                @DaddyGo when i try to create an intermediate CA, the list of signing CA is empty
                171ae991-dfe2-4980-8db2-c2a85ef36382-image.png but as i said i have our domain CA server and added his CA cert to CA settings
                ff98755a-9058-42da-bc51-7c14b4c4d448-image.png

                T DaddyGoD 2 Replies Last reply Reply Quote 0
                • T
                  techtester-m @viberua
                  last edited by techtester-m

                  @viberua said in Squid + https:

                  but as i said i have our domain CA server and added his CA

                  Won't work.

                  Do this from scratch:
                  Screen Shot 2020-07-17 at 16.44.04.png

                  And this is what you should see:
                  Screen Shot 2020-07-17 at 16.43.38.png

                  DaddyGoD 1 Reply Last reply Reply Quote 0
                  • DaddyGoD
                    DaddyGo @viberua
                    last edited by

                    @viberua

                    you are doing something wrong... 😉
                    because it works very well in pfSense

                    just watch squidSSL2 I just created for the sake of the test...

                    30181433-5b3d-43d3-9b81-6da6f43a1408-image.png

                    d8d8b847-ff3e-4824-878f-53a96e8f0017-image.png

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    1 Reply Last reply Reply Quote 0
                    • DaddyGoD
                      DaddyGo @techtester-m
                      last edited by

                      @techtester-m

                      😒
                      I like you bro, but it is not appropriate to speak into an ongoing conversation...

                      forum etiquette

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        techtester-m @DaddyGo
                        last edited by techtester-m

                        @DaddyGo
                        Ok...I just saw notifications of his questions jump in my email so it caught my attention and just wanted to help.
                        But I accept your point. Have a great one :), I'm out. No expert anyway lol

                        DaddyGoD 1 Reply Last reply Reply Quote 0
                        • DaddyGoD
                          DaddyGo @techtester-m
                          last edited by

                          @techtester-m

                          nothing happened...
                          we taught you about these a few days ago
                          I'm glad, you learned 🖐

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 1
                          • GertjanG
                            Gertjan
                            last edited by Gertjan

                            @viberua

                            Your image :

                            50323089-19ad-45f3-ad02-7df622380ee3-image.png

                            This is mine :

                            f55f3978-8c03-401a-b616-9fa142b31276-image.png

                            More in detail :
                            You :

                            b8584d75-a4ee-465a-a725-0404f69e458a-image.png

                            Me :

                            a6d744be-bde0-4f14-bd53-02ec2c917072-image.png

                            What is your pfSense version or what ?

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            DaddyGoD 1 Reply Last reply Reply Quote 0
                            • DaddyGoD
                              DaddyGo @Gertjan
                              last edited by

                              @Gertjan said in Squid + https:

                              What is your pfSense version or what ?

                              legitimate question anyway ✋

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              1 Reply Last reply Reply Quote 0
                              • A
                                Abdou Ahmed
                                last edited by

                                @DaddyGo
                                Hi
                                how are you . i just want to ask if i can use pfsense proxy with mikrotik server
                                clearly . i wannot to add a certificat in users phone . just add it in mikrotik
                                to Enable SSL filtering in my network
                                i tray to that alot and have no result

                                DaddyGoD 1 Reply Last reply Reply Quote 0
                                • DaddyGoD
                                  DaddyGo @Abdou Ahmed
                                  last edited by

                                  @Abdou-Ahmed said in Squid + https:

                                  just add it in mikrotik

                                  well, please specify this, please what kind of Mikrotik???
                                  I'm pretty prepared in the "picture" - Mikrotik...
                                  (all our CATV traffic is provided by Mikrotik devices)

                                  Cats bury it so they can't see it!
                                  (You know what I mean if you have a cat)

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.