Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Squid3 HTTPS and SNI

    Cache/Proxy
    2
    3
    1100
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deajan last edited by

      Hi,

      I've successfully setup a squid3 + clamav via icap transparent proxy on pfSense 2.2 x64.

      Now i try to use the MITM HTTPS functionnality, but it seems that Squid always uses the first SSL certificate of every server, without honoring SNI and selecting the right certificate for a given virtualhost.

      Is there anything that needs to be configured to HTTPS proxy uses SNI and fetches the right certificate ?

      Regards,
      Ozy.

      NetPOWER.fr - some opensource stuff for IT people

      1 Reply Last reply Reply Quote 0
      • W
        webstor last edited by

        Hi,

        please post your config or screenshoot.

        Thanx.

        1 Reply Last reply Reply Quote 0
        • D
          deajan last edited by

          Well i guess it was just too late for me to play with Squid.
          SNI is working indeed, the right client certificate is selected even on servers with multiple SSL certificates per vhost.

          Sorry for the post here :)

          NetPOWER.fr - some opensource stuff for IT people

          1 Reply Last reply Reply Quote 0
          • First post
            Last post