Re: [squid-users] RE: transparent https interception without mitm

2014-07-11 Thread Amos Jeffries
On 12/07/2014 12:24 a.m., James Harper wrote: Is it possible for squid to intercept and apply acl's to https without actually decrypting and generating certificates etc? The conversation would go something like: It actually almost works if I put a dummy cert on the https_port config

RE: [squid-users] RE: transparent https interception without mitm

2014-07-11 Thread James Harper
Unfortunately it seems to throw the details it gathered away after checking what bump to use as all I get in there is the destination IP. Logging %ssl::cert_subject just shows -. http:/www.squid-cache.org/Doc/config/logformat/: %ssl::cert_subject log the Subject field of a SSL