[squid-users] Question about squid 3.5.x and SSL

Mike mcsnv96 at afo.net
Tue Oct 21 16:40:51 UTC 2014


I was reading through the release notes for squid 3.5, and in section 
2.4 regarding HTTPS, it mentions "When Squid is built with the GnuTLS 
encryption library the tool is able to open TLS (or SSL/3.0) connections 
to servers", and the wording makes me think that when openssl is in use, 
squid cannot open TLS/SSL connections to servers...

So my question is if it will still properly able to open TLS/SSL 
connections to server when openssl is in use (like we currently are 
using with 3.4.6 and ssl_bump)? Or is gnutls recommended for use with 
squid 3.5.x (despite its massive bugs and vulnerabilities compared to 
openssl)?

and my last question, regarding squid usage by people on HTTPS websites, 
what are some primary differences of using gnutls versus openssl?

Thanks!
Mike


More information about the squid-users mailing list