[squid-users] SQUID_ERR_SSL_HANDSHAKE

L.P.H. van Belle belle at bazuin.nl
Fri Jun 28 14:34:43 UTC 2019


the SSL3_GET_MESSAGE ? 
 
Maybe because the only support TLSv1.2 ? 
Its long ago i seen a site good configured for ones with its TLS settings. 
 
So most probely, your downgrading the connection within the proxy settings to sslv3 
 
And sharing you config might help to see that. 
 
Greetz, 
 
Louis
 

Van: squid-users [mailto:squid-users-bounces at lists.squid-cache.org] Namens Walter H.
Verzonden: vrijdag 28 juni 2019 16:21
Aan: squid-users at lists.squid-cache.org
Onderwerp: [squid-users] SQUID_ERR_SSL_HANDSHAKE



Hello,

at some specific hosts
this is shown in cache.log
2019/06/28 16:11:12 kid1| Error negotiating SSL on FD 17: error:1408E0F4:SSL routines:SSL3_GET_MESSAGE:unexpected message (1/-1/0)

and this is the error page I get

Failed to establish a secure connection to ...

 (71) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)
 Handshake with SSL server failed: error:1408E0F4:SSL routines:SSL3_GET_MESSAGE:unexpected message

what is causing this?

in case some want to try:   https://www.3bg.at/
(when disabling SSL-bump no problem)

Thanks,
Walter


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20190628/459aa7a5/attachment.html>


More information about the squid-users mailing list