Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    squid versao nova recente mais captive portal pfsense 2.4.5 nao funciona em modo transparente

    Scheduled Pinned Locked Moved Portuguese
    1 Posts 1 Posters 675 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      serginho
      last edited by serginho

      squid versão nova mais captive portal Pfsense 2.4.5 não funciona em modo transparente e fica dando erro de certificado, alguém, alguém aqui tem esse cenário montado, fiz teste em laboratório e não validou, e teve uma correção do squid que atualizou pensei que eles iriam corrigir esse erro,mesmo assim permanece o erro com captive portal.
      quando eu douo comando aparece alguns erros no tls

      2020/03/30 21:21:39| Startup: Initializing Authentication Schemes ...
      2020/03/30 21:21:39| Startup: Initialized Authentication Scheme 'basic'
      2020/03/30 21:21:39| Startup: Initialized Authentication Scheme 'digest'
      2020/03/30 21:21:39| Startup: Initialized Authentication Scheme 'negotiate'
      2020/03/30 21:21:39| Startup: Initialized Authentication Scheme 'ntlm'
      2020/03/30 21:21:39| Startup: Initialized Authentication.
      2020/03/30 21:21:39| Processing Configuration File: /usr/local/etc/squid/squid.conf (depth 0)
      2020/03/30 21:21:39| Processing: http_port 192.168.50.1:3128 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=400MB cert=/usr/local/etc/squid/serverkey.pem capath=/usr/local/share/certs/ cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:!RC4:!aNULL:!eNULL:!LOW:!3DES:!SHA1:!MD5:!EXP:!PSK:!SRP:!DSS tls-dh=prime256v1:/etc/dh-parameters.2048 options=NO_SSLv2,NO_SSLv3,NO_TLSv1,SINGLE_DH_USE,SINGLE_ECDH_USE
      2020/03/30 21:21:39| ERROR: Unknown TLS option NO_SSLv2
      2020/03/30 21:21:39| Processing: http_port 127.0.0.1:3128 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=400MB cert=/usr/local/etc/squid/serverkey.pem capath=/usr/local/share/certs/ cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:!RC4:!aNULL:!eNULL:!LOW:!3DES:!SHA1:!MD5:!EXP:!PSK:!SRP:!DSS tls-dh=prime256v1:/etc/dh-parameters.2048 options=NO_SSLv2,NO_SSLv3,NO_TLSv1,SINGLE_DH_USE,SINGLE_ECDH_USE
      2020/03/30 21:21:39| Starting Authentication on port 127.0.0.1:3128
      2020/03/30 21:21:39| Disabling Authentication on port 127.0.0.1:3128 (interception enabled)
      2020/03/30 21:21:39| ERROR: Unknown TLS option NO_SSLv2
      2020/03/30 21:21:39| Processing: https_port 127.0.0.1:3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=400MB cert=/usr/local/etc/squid/serverkey.pem capath=/usr/local/share/certs/ cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:!RC4:!aNULL:!eNULL:!LOW:!3DES:!SHA1:!MD5:!EXP:!PSK:!SRP:!DSS tls-dh=prime256v1:/etc/dh-parameters.2048 options=NO_SSLv2,NO_SSLv3,NO_TLSv1,SINGLE_DH_USE,SINGLE_ECDH_USE
      2020/03/30 21:21:39| Starting Authentication on port 127.0.0.1:3129
      2020/03/30 21:21:39| Disabling Authentication on port 127.0.0.1:3129 (interception enabled)
      2020/03/30 21:21:39| ERROR: Unknown TLS option NO_SSLv2
      2020/03/30 21:21:39| Processing: icp_port 0
      2020/03/30 21:21:39| Processing: digest_generation off
      2020/03/30 21:21:39| Processing: dns_v4_first on
      2020/03/30 21:21:39| Processing: pid_filename /var/run/squid/squid.pid
      2020/03/30 21:21:39| Processing: cache_effective_user squid
      2020/03/30 21:21:39| Processing: cache_effective_group proxy
      2020/03/30 21:21:39| Processing: error_default_language pt-br
      2020/03/30 21:21:39| Processing: icon_directory /usr/local/etc/squid/icons
      2020/03/30 21:21:39| Processing: visible_hostname Casamax
      2020/03/30 21:21:39| Processing: cache_mgr ti@acasamax.com.br
      2020/03/30 21:21:39| Processing: access_log /var/squid/logs/access.log
      2020/03/30 21:21:39| Processing: cache_log /var/squid/logs/cache.log
      2020/03/30 21:21:39| Processing: cache_store_log none
      2020/03/30 21:21:39| Processing: netdb_filename /var/squid/logs/netdb.state
      2020/03/30 21:21:39| Processing: pinger_enable on
      2020/03/30 21:21:39| Processing: pinger_program /usr/local/libexec/squid/pinger
      2020/03/30 21:21:39| Processing: sslcrtd_program /usr/local/libexec/squid/security_file_certgen -s /var/squid/lib/ssl_db -M 4MB -b 2048
      2020/03/30 21:21:39| Processing: tls_outgoing_options capath=/usr/local/share/certs/
      2020/03/30 21:21:39| Processing: tls_outgoing_options options=NO_SSLv2,NO_SSLv3,NO_TLSv1,SINGLE_DH_USE,SINGLE_ECDH_USE
      2020/03/30 21:21:39| ERROR: Unknown TLS option NO_SSLv2
      2020/03/30 21:21:39| Processing: tls_outgoing_options cipher=EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH+aRSA+RC4:EECDH:EDH+aRSA:!RC4:!aNULL:!eNULL:!LOW:!3DES:!SHA1:!MD5:!EXP:!PSK:!SRP:!DSS
      2020/03/30 21:21:39| Processing: tls_outgoing_options flags=DONT_VERIFY_PEER
      2020/03/30 21:21:39| Processing: sslcrtd_children 200
      2020/03/30 21:21:39| Processing: sslproxy_cert_error allow all
      2020/03/30 21:21:39| Processing: sslproxy_cert_adapt setValidAfter all
      2020/03/30 21:21:39| Processing: sslproxy_cert_adapt setValidBefore all
      2020/03/30 21:21:39| Processing: sslproxy_cert_adapt setCommonName all
      2020/03/30 21:21:39| Processing: logfile_rotate 60
      2020/03/30 21:21:39| Processing: debug_options rotate=60
      2020/03/30 21:21:39| Processing: shutdown_lifetime 3 seconds
      2020/03/30 21:21:39| Processing: acl localnet src 192.168.50.0/23
      2020/03/30 21:21:39| Processing: forwarded_for on
      2020/03/30 21:21:39| Processing: via off
      2020/03/30 21:21:39| Processing: httpd_suppress_version_string on
      2020/03/30 21:21:39| Processing: uri_whitespace allow
      2020/03/30 21:21:39| Processing: acl dynamic urlpath_regex cgi-bin ?
      2020/03/30 21:21:39| Processing: cache deny dynamic
      2020/03/30 21:21:39| Processing: cache_mem 4000 MB
      2020/03/30 21:21:39| Processing: maximum_object_size_in_memory 256 KB
      2020/03/30 21:21:39| Processing: memory_replacement_policy heap GDSF
      2020/03/30 21:21:39| Processing: cache_replacement_policy heap LFUDA
      2020/03/30 21:21:39| Processing: minimum_object_size 0 KB
      2020/03/30 21:21:39| Processing: maximum_object_size 3000 MB
      2020/03/30 21:21:39| Processing: cache_dir ufs /var/squid/cache 4000 16 256
      2020/03/30 21:21:39| Processing: offline_mode off
      2020/03/30 21:21:39| Processing: cache_swap_low 90
      2020/03/30 21:21:39| Processing: cache_swap_high 95
      2020/03/30 21:21:39| Processing: acl donotcache dstdomain "/var/squid/acl/donotcache.acl"
      2020/03/30 21:21:39| Processing: cache deny donotcache
      2020/03/30 21:21:39| Processing: cache allow all
      2020/03/30 21:21:39| Processing: refresh_pattern ^ftp: 1440 20% 10080
      2020/03/30 21:21:39| Processing: refresh_pattern ^gopher: 1440 0% 1440
      2020/03/30 21:21:39| Processing: refresh_pattern -i (/cgi-bin/|?) 0 0% 0
      2020/03/30 21:21:39| Processing: refresh_pattern . 0 20% 4320
      2020/03/30 21:21:39| Processing: acl allsrc src all
      2020/03/30 21:21:39| Processing: acl safeports port 21 70 80 210 280 443 488 563 591 631 777 901 3128 3129 1025-65535
      2020/03/30 21:21:39| Processing: acl sslports port 443 563
      2020/03/30 21:21:39| Processing: acl purge method PURGE
      2020/03/30 21:21:39| Processing: acl connect method CONNECT
      2020/03/30 21:21:39| Processing: acl HTTP proto HTTP
      2020/03/30 21:21:39| Processing: acl HTTPS proto HTTPS
      2020/03/30 21:21:39| Processing: acl step1 at_step SslBump1
      2020/03/30 21:21:39| Processing: acl step2 at_step SslBump2
      2020/03/30 21:21:39| Processing: acl step3 at_step SslBump3
      2020/03/30 21:21:39| Processing: acl whitelist dstdom_regex -i "/var/squid/acl/whitelist.acl"
      2020/03/30 21:21:39| /usr/local/etc/squid/squid.conf line 103: acl whitelist dstdom_regex -i "/var/squid/acl/whitelist.acl"
      2020/03/30 21:21:39| ERROR: invalid regular expression: '(https://lista.mercadolivre.com.br/cabo-de-rede-cat5e-furukawa#D[A:cabo-de-rede-cat5e-furukawa,B:2])|(mercadolivre)|(https://informatica.mercadolivre.com.br/cabos-conectores/sao-paulo/ licitacoes1.caixa.gov.br http://www.prefeitura.sp.gov.br/cidade/secretarias/fazenda/servicos/empenhospagamentos/)|(https://buyingflow.mercadolivre.com.br/bid/confirm?item_id=MLB715965183&parent_url=https%3A%2F%2Fproduto.mercadolivre.com.br%2FMLB-715965183-cabo-de-rede-furukawa-cat5e-soho-plus-caixa-305-metros-azul-_JM&mode=page&zip_code=08664645&ship_option_id=27565905&ship_method_id=182&pm=visa&cc_issuer=25&inst=12&quantity=1&token=a112f5bf16d53c1e3e3f4eef1643e91138c89fb84a4fa8f18c2e6bb6d2a946e3510869195134d07d46404db792d72d792c010c1f64ff8240cda4c9774efca575)': bad range inside [] at offset 72
      2020/03/30 21:21:39| WARNING: optimisation of regular expressions failed; using fallback method without optimisation
      2020/03/30 21:21:39| /usr/local/etc/squid/squid.conf line 103: acl whitelist dstdom_regex -i "/var/squid/acl/whitelist.acl"
      2020/03/30 21:21:39| ERROR: invalid regular expression: 'https://lista.mercadolivre.com.br/cabo-de-rede-cat5e-furukawa#D[A:cabo-de-rede-cat5e-furukawa,B:2]': bad range inside [] at offset 71
      2020/03/30 21:21:39| ERROR: Skipping regular expression. Compile failed: 'https://lista.mercadolivre.com.br/cabo-de-rede-cat5e-furukawa#D[A:cabo-de-rede-cat5e-furukawa,B:2]'
      2020/03/30 21:21:39| Processing: http_access allow manager localhost
      2020/03/30 21:21:39| Processing: http_access deny manager
      2020/03/30 21:21:39| Processing: http_access allow purge localhost
      2020/03/30 21:21:39| Processing: http_access deny purge
      2020/03/30 21:21:39| Processing: http_access deny !safeports
      2020/03/30 21:21:39| Processing: http_access deny CONNECT !sslports
      2020/03/30 21:21:39| Processing: http_access allow localhost
      2020/03/30 21:21:39| Processing: request_body_max_size 0 KB
      2020/03/30 21:21:39| Processing: delay_pools 1
      2020/03/30 21:21:39| Processing: delay_class 1 2
      2020/03/30 21:21:39| Processing: delay_parameters 1 -1/-1 -1/-1
      2020/03/30 21:21:39| Processing: delay_initial_bucket_level 100
      2020/03/30 21:21:39| Processing: delay_access 1 allow allsrc
      2020/03/30 21:21:39| Processing: deny_info TCP_RESET allsrc
      2020/03/30 21:21:39| Processing: url_rewrite_program /usr/local/bin/squidGuard -c /usr/local/etc/squidGuard/squidGuard.conf
      2020/03/30 21:21:39| Processing: url_rewrite_bypass off
      2020/03/30 21:21:39| Processing: url_rewrite_children 200 startup=8 idle=4 concurrency=0
      2020/03/30 21:21:39| Processing: http_access allow whitelist
      2020/03/30 21:21:39| Processing: acl sglog url_regex -i sgr=ACCESSDENIED
      2020/03/30 21:21:39| Processing: http_access deny sglog
      2020/03/30 21:21:39| Processing: ssl_bump peek step1
      2020/03/30 21:21:39| Processing: ssl_bump splice all
      2020/03/30 21:21:39| Processing: http_access allow localnet
      2020/03/30 21:21:39| Processing: http_access deny allsrc
      2020/03/30 21:21:39| WARNING: HTTP requires the use of Via
      2020/03/30 21:21:39| Initializing https:// proxy context
      2020/03/30 21:21:39| Initializing http_port 192.168.50.1:3128 TLS contexts
      2020/03/30 21:21:39| Using certificate in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Using certificate chain in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Adding issuer CA: /C=BR/ST=SAO PAULO/L=SUZANO/O=CASAMAX/emailAddress=ti@acasamax.com.br/CN=casamaxinternal-ca/OU=CASAMAX COMERCIAL
      2020/03/30 21:21:39| Using key in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Initializing http_port 127.0.0.1:3128 TLS contexts
      2020/03/30 21:21:39| Using certificate in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Using certificate chain in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Adding issuer CA: /C=BR/ST=SAO PAULO/L=SUZANO/O=CASAMAX/emailAddress=ti@acasamax.com.br/CN=casamaxinternal-ca/OU=CASAMAX COMERCIAL
      2020/03/30 21:21:39| Using key in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Initializing https_port 127.0.0.1:3129 TLS contexts
      2020/03/30 21:21:39| Using certificate in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Using certificate chain in /usr/local/etc/squid/serverkey.pem
      2020/03/30 21:21:39| Adding issuer CA: /C=BR/ST=SAO PAULO/L=SUZANO/O=CASAMAX/emailAddress=ti@acasamax.com.br/CN=casamaxinternal-ca/OU=CASAMAX COMERCIAL
      2020/03/30 21:21:39| Using key in /usr/local/etc/squid/serverkey.pem

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.