Security warning: Netscape 4.0x https & Squid 1.2beta proxy

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Sat, 18 Jul 1998 00:22:49 +0200

If you are using Squid 1.2beta and Netscape 4.x then you MUST use
different server names for your HTTP and Security (SSL) proxy. This is
due to a bug in Netscape4.0x that may cause https requests to be sent in
plain text to a Squid 1.2beta proxy server.

You don't need to have separate HTTP and Security (SSL) proxies. Using
different aliases (CNAMEs) for the same proxy server IP address is
enough.

I have verified this Netscape 4.0x bug using Netscape Communicator 4.04
Linux and 4.05 Linux. Other platforms may be affected as well. Netscape
3.01 Linux does NOT have the same problem.

A bug report is filed to Netscape.

---
Henrik Nordström
Sparetime Squid Hacker
Received on Fri Jul 17 1998 - 15:26:40 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:41:09 MST