Hi Michael, I was just reading this thread, and I've been following the same line of thought wrt to monitoring the contents of HTTPS payloads that way I can conduct analysis with an IDS such as Snort, or Bro. Did you end up having any luck with ICAP, or is this a rabbit hole that I'm going down? Cheers, Matt -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/https-traffic-using-squid-and-icap-tp4660720p4670394.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users