Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid + https

    Scheduled Pinned Locked Moved Cache/Proxy
    52 Posts 5 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DaddyGoD
      DaddyGo @Gertjan
      last edited by

      @Gertjan said in Squid + https:

      Never used squid before, but I guess a CA should be created first.
      Here :

      exactly,
      use the pfSense certificate builder and then it will appear in Squid settings

      then you can also export it for installation on external devices

      like:
      b0e976f7-948a-4515-bedb-311e848e43c7-image.png

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      V 1 Reply Last reply Reply Quote 0
      • V
        viberua @DaddyGo
        last edited by

        @DaddyGo so if i don't want create new CA because i already have one, then i can't use this external CA cert in MITM?

        DaddyGoD T 2 Replies Last reply Reply Quote 0
        • DaddyGoD
          DaddyGo @viberua
          last edited by

          @viberua

          Squid works with an internal intermediate certificate
          you can't use example Lets' E or other

          because of what is described above in this thread......

          like:
          e6d85e91-20c0-4c72-994d-63130e5c6ab0-image.png

          d885c2db-48b4-4c2b-9e0c-6b930da4372b-image.png

          50fd8d7b-58eb-4c5c-ac9f-46ffaaa060e6-image.png

          Cats bury it so they can't see it!
          (You know what I mean if you have a cat)

          V 1 Reply Last reply Reply Quote 0
          • T
            techtester-m @viberua
            last edited by

            @viberua You need to "become" a CA (a local one of course) and have your own Public Key & Private Key in order for Squid to encrypt-decrypt.

            1 Reply Last reply Reply Quote 0
            • V
              viberua @DaddyGo
              last edited by

              @DaddyGo when i try to create an intermediate CA, the list of signing CA is empty
              171ae991-dfe2-4980-8db2-c2a85ef36382-image.png but as i said i have our domain CA server and added his CA cert to CA settings
              ff98755a-9058-42da-bc51-7c14b4c4d448-image.png

              T DaddyGoD 2 Replies Last reply Reply Quote 0
              • T
                techtester-m @viberua
                last edited by techtester-m

                @viberua said in Squid + https:

                but as i said i have our domain CA server and added his CA

                Won't work.

                Do this from scratch:
                Screen Shot 2020-07-17 at 16.44.04.png

                And this is what you should see:
                Screen Shot 2020-07-17 at 16.43.38.png

                DaddyGoD 1 Reply Last reply Reply Quote 0
                • DaddyGoD
                  DaddyGo @viberua
                  last edited by

                  @viberua

                  you are doing something wrong... 😉
                  because it works very well in pfSense

                  just watch squidSSL2 I just created for the sake of the test...

                  30181433-5b3d-43d3-9b81-6da6f43a1408-image.png

                  d8d8b847-ff3e-4824-878f-53a96e8f0017-image.png

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • DaddyGoD
                    DaddyGo @techtester-m
                    last edited by

                    @techtester-m

                    😒
                    I like you bro, but it is not appropriate to speak into an ongoing conversation...

                    forum etiquette

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      techtester-m @DaddyGo
                      last edited by techtester-m

                      @DaddyGo
                      Ok...I just saw notifications of his questions jump in my email so it caught my attention and just wanted to help.
                      But I accept your point. Have a great one :), I'm out. No expert anyway lol

                      DaddyGoD 1 Reply Last reply Reply Quote 0
                      • DaddyGoD
                        DaddyGo @techtester-m
                        last edited by

                        @techtester-m

                        nothing happened...
                        we taught you about these a few days ago
                        I'm glad, you learned 🖐

                        Cats bury it so they can't see it!
                        (You know what I mean if you have a cat)

                        1 Reply Last reply Reply Quote 1
                        • GertjanG
                          Gertjan
                          last edited by Gertjan

                          @viberua

                          Your image :

                          50323089-19ad-45f3-ad02-7df622380ee3-image.png

                          This is mine :

                          f55f3978-8c03-401a-b616-9fa142b31276-image.png

                          More in detail :
                          You :

                          b8584d75-a4ee-465a-a725-0404f69e458a-image.png

                          Me :

                          a6d744be-bde0-4f14-bd53-02ec2c917072-image.png

                          What is your pfSense version or what ?

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          DaddyGoD 1 Reply Last reply Reply Quote 0
                          • DaddyGoD
                            DaddyGo @Gertjan
                            last edited by

                            @Gertjan said in Squid + https:

                            What is your pfSense version or what ?

                            legitimate question anyway ✋

                            Cats bury it so they can't see it!
                            (You know what I mean if you have a cat)

                            1 Reply Last reply Reply Quote 0
                            • A
                              Abdou Ahmed
                              last edited by

                              @DaddyGo
                              Hi
                              how are you . i just want to ask if i can use pfsense proxy with mikrotik server
                              clearly . i wannot to add a certificat in users phone . just add it in mikrotik
                              to Enable SSL filtering in my network
                              i tray to that alot and have no result

                              DaddyGoD 1 Reply Last reply Reply Quote 0
                              • DaddyGoD
                                DaddyGo @Abdou Ahmed
                                last edited by

                                @Abdou-Ahmed said in Squid + https:

                                just add it in mikrotik

                                well, please specify this, please what kind of Mikrotik???
                                I'm pretty prepared in the "picture" - Mikrotik...
                                (all our CATV traffic is provided by Mikrotik devices)

                                Cats bury it so they can't see it!
                                (You know what I mean if you have a cat)

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.