Search squid archive

Re: Bypassing SSL Bump for dstdomain

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 03/05/2013 03:09 AM, Amos Jeffries wrote:


> Squid tunnel functionality requires a CONNECT wrapper to generate
> outgoing connections.
> It is not yet setup to do the raw-TCP type of bypass the intercepted
> traffic would require.

Are you sure? IIRC, "ssl_bump none" tunneling code works for intercepted
connections, and that is what we claim in squid.conf:

> none
>     Become a TCP tunnel without decoding the connection.
>     Works with both CONNECT requests and intercepted SSL
>     connections. This is the default behavior when no
>     ssl_bump option is given or no ssl_bump ACLs match.

HTH,

Alex.



[Index of Archives]     [Linux Audio Users]     [Samba]     [Big List of Linux Books]     [Linux USB]     [Yosemite News]

  Powered by Linux