Red Hat Bugzilla – Bug 1204375
squid sends incorrect ssl chain breaking newer gnutls using applications
Last modified: 2017-05-17 06:20:21 EDT
This bug: http://bugs.squid-cache.org/show_bug.cgi?id=3849 was fixed upstream, but doesn't seem to be in the current RHEL7 squid package. This means if you use ssl with a cert chain, any clients using newer gnutls will be unable to use your proxy. ;( We have hit this with a proxy in Fedora, see: https://fedorahosted.org/fedora-infrastructure/ticket/4682 Please consider backporting this fix. Thanks.
Created attachment 1011660 [details] This is a backported patch which should fix bug #1204375
Hi Kevin, which version of squid and RHEL are you exactly using? I backported this patch, for the latest squid (3.3.8) in RHEL 7.1. I'm attaching the PATCH, so you can try, if it fixes this bug in your squid configuration.
Created attachment 1011700 [details] SRPM of squid containing patch
We can confirm this fixes the issue. ;) Thanks!
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-2378.html