[squid-users] SSL mitm while properly reflecting bad upstream certs?

Amos Jeffries squid3 at treenet.co.nz
Fri Mar 11 09:39:53 UTC 2016


On 11/03/2016 7:52 p.m., Will Rouesnel wrote:
> Can squid mitm SSL connections, but deliberately generate invalid certs for upstream connections which are self signed or invalid so my browser will flag them?
> 

The current Squid do that provided you do the SSL-Bump "bump" action at
step3 when the server details are known.

<http://wiki.squid-cache.org/Features/SslPeekAndSplice>

Amos


More information about the squid-users mailing list