LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 06-12-2014, 05:26 PM   #1
!! hack-back !!
Member
 
Registered: Nov 2009
Posts: 183

Rep: Reputation: 2
squid 3.4.5 and decrypt ssl


i want to decrypt ssl connection with ssl bump but am still getting
CONNECT gp4.googleusercontent.com:443
CONNECT s.youtube.com:443
CONNECT nps.noproblemppc.com:443
....etc

i used:
./configure --prefix=/usr --exec_prefix=/usr --bindir=/usr/sbin --sbindir=/usr/sbin --libexecdir=/usr/lib/squid --sysconfdir=/etc/squid --localstatedir=/var/spool/squid --datadir=/usr/share/squid --enable-async-io --with-pthreads --enable-storeio=aufs --enable-icap-client --enable-kill-parent-hack --enable-ssl --enable-linux-netfilter --disable-ident-lookups --enable-ssl-crtd --enable-zph-qos --enable-arp-acl --enable-epoll --enable-removal-policies=lru,heap --enable-snmp --enable-referer-log --disable-unlinkd --enable-x-accelerator-vary --enable-dlmalloc --enable-truncate --enable-useragent-log --enable-follow-x-forwarded-for --enable-poll --enable-large-cache-files --with-large-files --with-maxfd=65536 CFLAGS="-Wall -g -O3 -march=native -mtune=native -pipe -DNUMTHREADS=60 -fomit-frame-pointer -fno-strict-aliasing -funroll-loops -ffast-math -fno-exceptions" LDFLAGS="-Wl,-Bsymbolic-functions"


my squid.conf
#PORT HTTP / HTTPS
http_port 8080
http_port 3128 intercept
#ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/myCA.pem
https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/myCA.pem

always_direct allow all
ssl_bump server-first all
sslproxy_cert_error allow all


what i got in access.log is
http://aacable.files.wordpress.com/2...g?w=1024&h=197

but i want it to be like this
http://aacable.files.wordpress.com/2...g?w=1024&h=368

what i mess ?
 
Old 06-13-2014, 12:01 PM   #2
!! hack-back !!
Member
 
Registered: Nov 2009
Posts: 183

Original Poster
Rep: Reputation: 2
no solution ?
 
Old 06-13-2014, 03:33 PM   #3
DJ Shaji
Member
 
Registered: Dec 2004
Location: Yo Momma's house
Distribution: Fedora Rawhide, ArchLinux
Posts: 518
Blog Entries: 15

Rep: Reputation: 106Reputation: 106
Quote:
Originally Posted by !! hack-back !! View Post
i want to decrypt ssl connection
Someone's so gonna be on the naughty list this year.

Quote:
what, i mess ?
Probably.
 
Old 06-13-2014, 05:08 PM   #4
!! hack-back !!
Member
 
Registered: Nov 2009
Posts: 183

Original Poster
Rep: Reputation: 2
Quote:
Originally Posted by DJ Shaji View Post
Someone's so gonna be on the naughty list this year.



Probably.
why naughty !!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sniffing From Squid SSL cyb33r Linux - General 1 09-07-2013 09:22 PM
Squid+ SSL FTP possible? rocka Linux - Server 3 03-18-2010 10:20 AM
SSL Bad Decrypt uiuiui172 Linux - Server 14 08-27-2009 09:52 AM
Decrypt SSL ajaye1971 Linux - Security 1 08-30-2006 04:06 PM
squid ssl gabsik Linux - Networking 6 05-15-2006 03:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 01:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration