<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div>Ok i read the doc but I am afraid i do not know where yo start</div><div id="AppleMailSignature">I know that netflix traffic comes from these server domains</div><div id="AppleMailSignature">.<a href="http://netflix.com">netflix.com</a></div><div id="AppleMailSignature">.<a href="http://ntflx.com">ntflx.com</a></div><div id="AppleMailSignature">.<a href="http://ntflximg.com">ntflximg.com</a></div><div id="AppleMailSignature">.<a href="http://ntflxvideo.com">ntflxvideo.com</a></div><div id="AppleMailSignature">But how can I setup my config file to just tell squid do not bump netflix traffic and i am not interested in caching it or guarding against it</div><div id="AppleMailSignature">How can I use splice for that?</div><div id="AppleMailSignature"><br>Sent from my iPhone</div><div><br>On Mar 2, 2016, at 12:48 PM, Yuri Voinov <<a href="mailto:yvoinov@gmail.com">yvoinov@gmail.com</a>> wrote:<br><br></div><blockquote type="cite"><div>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<br>
-----BEGIN PGP SIGNED MESSAGE----- <br>
Hash: SHA256 <br>
<br>
With peek and splice feature.<br>
<br>
<a class="moz-txt-link-freetext" href="http://wiki.squid-cache.org/Features/SslPeekAndSplice">http://wiki.squid-cache.org/Features/SslPeekAndSplice</a><br>
<br>
03.03.16 2:45, Bmahak2005 пишет:<br>
<span style="white-space: pre;">> Thanks for the hint. How can I
do that ?<br>
><br>
><br>
> Sent from my iPhone<br>
><br>
>> On Mar 2, 2016, at 11:09 AM, Yuri Voinov
<a class="moz-txt-link-rfc2396E" href="mailto:yvoinov@gmail.com"><yvoinov@gmail.com></a> wrote:<br>
>><br>
>><br>
> Nobody can fight SSL pinning in proprietary apps.<br>
><br>
> The only way I see is to put Netflex under splice ACL and do
not do SSL<br>
> bump for all Netflex CDN.<br>
><br>
> 02.03.16 22:29, bma пишет:<br>
> >>> I have installed squid 3.15 on ubuntu 15.10
server. squid was setup with<br>
> >>> sslbump for https traffic. The functionality
work without any problem<br>
> i.e. :<br>
> >>> all traffic from both http and https goes
through squid and all<br>
> internet can<br>
> >>> be accessed on all devices where certificates
are installed. With one<br>
> >>> exception : 'Netflix APP' no longer works on IOS
devices (iPhone,<br>
> iPad). no<br>
> >>> matter what I do. All other internet services
(safari, and other apps)<br>
> work<br>
> >>> properly on those devices. And I was able to run
Netflix from browser on<br>
> >>> linux boxes and even OS X safari. The only thing
that is not working is<br>
> >>> Netflix APP on IOS.<br>
> >>><br>
> >>> Of course if I disable sslbump and only allow
http to go through squid<br>
> >>> netflix works. I tried both transparent mode and
proxy mode on the iPhone,<br>
> >>> still not working.<br>
> >>><br>
> >>> Did anyone manage to make Netflix APP on IOS
devices work with squid with<br>
> >>> sslbump enabled ?<br>
> >>><br>
> >>><br>
> >>><br>
> >>> --<br>
> >>> View this message in context:<br>
>
<a class="moz-txt-link-freetext" href="http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-with-sslbump-blocking-Netflix-tp4676381.html">http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-with-sslbump-blocking-Netflix-tp4676381.html</a><br>
> >>> Sent from the Squid - Users mailing list archive
at <a href="http://nabble.com">Nabble.com</a>.<br>
> >>> _______________________________________________<br>
> >>> squid-users mailing list<br>
> >>> <a class="moz-txt-link-abbreviated" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
> >>>
<a class="moz-txt-link-freetext" href="http://lists.squid-cache.org/listinfo/squid-users">http://lists.squid-cache.org/listinfo/squid-users</a><br>
><br>
>><br>
>> <0x613DEC46.asc><br>
>> _______________________________________________<br>
>> squid-users mailing list<br>
>> <a class="moz-txt-link-abbreviated" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
>> <a class="moz-txt-link-freetext" href="http://lists.squid-cache.org/listinfo/squid-users">http://lists.squid-cache.org/listinfo/squid-users</a></span><br>
<br>
-----BEGIN PGP SIGNATURE-----
<br>
Version: GnuPG v2
<br>
<br>
iQEcBAEBCAAGBQJW11GEAAoJENNXIZxhPexGsMIIAIJemE2gpPVJCo8Licrt6Hs6
<br>
vIxFb8KHUkq+sXRlRtJbqjwmHPU8m59wcHsVnsJfBFpDdOkd5sMDiBKs9xeTDKAQ
<br>
dFgtVW9LORvrienTKca3IhRoBlka/BdePA4vF00OosaGw47fQ20KjmjgPmgRihEs
<br>
I5RI1qxnB8RAmmQjMcS+vS6qtXYUkNBJlH6e6vDiuI2FlPDzuLWcGXD78PLJceGd
<br>
wWgIVWtQv6zjsBe4eMQzWC61xQ1ms+1ISTaihlyyBIztq1hIFtrOaoghXCJ1Ue6r
<br>
pdp+nqIuXbvbgC15fYC1gGJjaznenpPrJJ9gMszAKRuL9gfNGMHjCPZCbv4U/NE=
<br>
=TXwl
<br>
-----END PGP SIGNATURE-----
<br>
<br>
</div></blockquote><blockquote type="cite"><div><0x613DEC46.asc></div></blockquote></body></html>