Re: [squid-users] Cannot block https sites

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Sun, 22 Feb 2004 18:09:43 +0100 (CET)

On Fri, 20 Feb 2004 h35.office@bmlv.gv.at wrote:

> Thanks, but it doesnt work.
> I want do block https://servername.domain.d/log

This you can't, at least not unless your Squid is a SSL accelerator
running at servername.domain.d.

> I see in access.log if i connect to the https site this:
> https://servername.domain.d:443

Do you really see the https:// part?

You should only see

CONNECT servername.domain.d:443

as this is all information available to a HTTP proxy on proxied https://
requests. All the rest is encrypted by SSL and not visible to the proxy.

Regards
Henrik
Received on Sun Feb 22 2004 - 10:09:49 MST

This archive was generated by hypermail pre-2.1.9 : Mon Mar 01 2004 - 12:00:03 MST