[squid-users] SSL_ERROR_RX_RECORD_TOO_LONG

Giacomo Trovato giacomo at gtrovato.com
Thu May 2 14:01:39 UTC 2019


Hi Alex, 

thanks for the answer! 

My pfSense has version 3.5.27_3.

---

Giacomo Trovato

Il 30/04/2019 16:36 Alex Rousskov ha scritto:

> On 4/30/19 8:04 AM, Giacomo Trovato wrote:
> 
>> I've pfSense with Squid + SquidGuard (Splice All - no CA certificate).
>> It worked well until one month ago, now sometimes appears the error
>> message SSL_ERROR_RX_RECORD_TOO_LONG (see attachment).
>> It appears randomly on all PC / smartphone on different HTTPS sites.
>> The devices connected directly (no proxy) work properly.
>> Any hint?
> 
> What is your current Squid version?
> 
> The browser claims that your Squid sent it a very long (most likely
> malformed) TLS record. If this does not happen without Squid, then this
> is likely a Squid bug. I see references to similar problems in old
> (Squid v3) web posts.
> 
> * If you can reproduce with Squid v4 or later, the best next step is to
> share a packet capture of the offending transaction along with the
> cache.log after setting debug_options to ALL,9. Please compress large
> files before sharing.
> 
> * If you cannot reproduce with Squid v4 or later, then the best next
> step is to upgrade your Squid.
> 
> HTH,
> 
> Alex.
> _______________________________________________
> squid-users mailing list
> squid-users at lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20190502/93595410/attachment.html>


More information about the squid-users mailing list