Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread David Touzeau
Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon *From:*David Touzeau *Sent:* Monday, January 4, 2021 3:25 PM *To:* ngtech1...@gmail.com; squid-users@lists.squid-cache.org *Subject:* Re: [squid-users] PCI Certification compliance

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread ngtech1ltd
soon -Original Message- From: Alex Rousskov Sent: Monday, January 4, 2021 4:48 PM To: squid-users@lists.squid-cache.org Cc: ngtech1...@gmail.com Subject: Re: [squid-users] PCI Certification compliance lists On 1/4/21 4:27 AM, ngtech1...@gmail.com wrote: > The main issue is that

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread Alex Rousskov
On 1/4/21 4:27 AM, ngtech1...@gmail.com wrote: > The main issue is that ssl-bump requires couple “fast” acls. It does not: The ssl_bump directive supports both fast and slow ACLs. Alex. ___ squid-users mailing list squid-users@lists.squid-cache.org http

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread ngtech1ltd
David Touzeau Sent: Monday, January 4, 2021 3:25 PM To: ngtech1...@gmail.com; squid-users@lists.squid-cache.org Subject: Re: [squid-users] PCI Certification compliance lists Hi Eliezer: http://articatech.net/tmpf/categories/banking.gz http://articatech.net/tmpf/categories/cleaning.gz Le

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread David Touzeau
Eliezer Croitoru Tech Support Mobile: +972-5-28704261 Email: ngtech1...@gmail.com <mailto:ngtech1...@gmail.com> Zoom: Coming soon *From:*squid-users *On Behalf Of *David Touzeau *Sent:* Monday, January 4, 2021 10:23 AM *To:* squid-users@lists.squid-cache.org *Subject:* Re: [squid-user

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread ngtech1ltd
-users On Behalf Of David Touzeau Sent: Monday, January 4, 2021 10:23 AM To: squid-users@lists.squid-cache.org Subject: Re: [squid-users] PCI Certification compliance lists Hi Eiezer, I can help you by giving a list but Just by using "main domains": * Banking/transcations :

Re: [squid-users] PCI Certification compliance lists

2021-01-04 Thread David Touzeau
Hi Eiezer, I can help you by giving a list but Just by using "main domains": * Banking/transcations : 27 646 websites. * AV sofwtare and updates sites (fw, routers...) : 133 295 websites I can give it to you the lists , they are incomplete and it should decrease squid performance by loadin

Re: [squid-users] PCI Certification compliance lists

2021-01-03 Thread Alex Rousskov
On 1/3/21 10:17 AM, NgTech LTD wrote: > As i noticed in the past it seems that for a good splice and or bump I > need the any-of acl to be used. > Its a bit different then the way squid acls work in general. The ACLs in ssl_bump rules work exactly the same as ACLs in other directives. The any-of

Re: [squid-users] PCI Certification compliance lists

2021-01-03 Thread NgTech LTD
I'm trying to figure out what can be done with 5.0.4. I believe there is either a bug or misunderstanding by me what and how things should be done or configured. The first thing is to be able to bump all and add exceptions. The second would be to bump specific sites. As i noticed in the past it se

Re: [squid-users] PCI Certification compliance lists

2021-01-03 Thread Amos Jeffries
On 4/01/21 3:12 am, ngtech1ltd wrote: I am looking for domains lists that can be used for squid to be PCI Certified. I have read this article: https://www.imperva.com/learn/data-security/pci-dss-certification/ And couple others to try and understand what might a Squid proxy ssl-bump exception r

[squid-users] PCI Certification compliance lists

2021-01-03 Thread ngtech1ltd
I am looking for domains lists that can be used for squid to be PCI Certified. I have read this article: https://www.imperva.com/learn/data-security/pci-dss-certification/ And couple others to try and understand what might a Squid proxy ssl-bump exception rules should contain. So technically we n