The following error was encountered while trying to retrieve the URL: https://www.youtube.com/*Failed to establish a secure connection to 64.233.185.93The system returned:(92) Protocol error (TLS code: X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY)SSL Certficate error: certificate issuer (CA) not known: /C=us/L=Nowhere/O=TG/CN=TG Proxy CA/emailAddress=##@##.comThis proxy and the remote host failed to negotiate a mutually acceptable security settings for handling your request. It is possible that the remote host does not support secure connections, or the proxy is not satisfied with the host security credentials.
The following error was encountered while trying to retrieve the URL: https://172.217.3.238/*Failed to establish a secure connection to 172.217.3.238The system returned:(92) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)Handshake with SSL server failed: error:140920F8:SSL routines:ssl3_get_server_hello:unknown cipher returnedThis proxy and the remote host failed to negotiate a mutually acceptable security settings for handling your request. It is possible that the remote host does not support secure connections, or the proxy is not satisfied with the host security credentials.
root@OPNsense:~ # curl https://www.youtube.com/ -vkI* Trying 172.217.164.46...* TCP_NODELAY set* Connected to www.youtube.com (172.217.164.46) port 443 (#0)* ALPN, offering h2* ALPN, offering http/1.1* Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH* successfully set certificate verify locations:* CAfile: /usr/local/share/certs/ca-root-nss.crt CApath: none* TLSv1.2 (OUT), TLS header, Certificate Status (22):* TLSv1.2 (OUT), TLS handshake, Client hello (1):* TLSv1.2 (IN), TLS handshake, Server hello (2):* TLSv1.2 (IN), TLS handshake, Certificate (11):* TLSv1.2 (IN), TLS handshake, Server key exchange (12):* TLSv1.2 (IN), TLS handshake, Server finished (14):* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):* TLSv1.2 (OUT), TLS handshake, Finished (20):* TLSv1.2 (IN), TLS change cipher, Change cipher spec (1):* TLSv1.2 (IN), TLS handshake, Finished (20):* SSL connection using TLSv1.2 / ECDHE-ECDSA-AES128-GCM-SHA256* ALPN, server accepted to use h2* Server certificate:* subject: C=US; ST=California; L=Mountain View; O=Google LLC; CN=*.google.com* start date: Oct 23 16:54:00 2018 GMT* expire date: Jan 15 16:54:00 2019 GMT* issuer: C=US; O=Google Trust Services; CN=Google Internet Authority G3* SSL certificate verify ok.* Using HTTP2, server supports multi-use* Connection state changed (HTTP/2 confirmed)* Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0* Using Stream ID: 1 (easy handle 0x6499fa8d000)> HEAD / HTTP/2> Host: www.youtube.com> User-Agent: curl/7.61.1> Accept: */*>* Connection state changed (MAX_CONCURRENT_STREAMS == 100)!< HTTP/2 200HTTP/2 200< expires: Tue, 27 Apr 1971 19:44:06 ESTexpires: Tue, 27 Apr 1971 19:44:06 EST< x-frame-options: SAMEORIGINx-frame-options: SAMEORIGIN< content-type: text/html; charset=utf-8content-type: text/html; charset=utf-8< x-content-type-options: nosniffx-content-type-options: nosniff< strict-transport-security: max-age=31536000strict-transport-security: max-age=31536000< p3p: CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."p3p: CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."< cache-control: no-cachecache-control: no-cache< x-xss-protection: 1; mode=block; report=https://www.google.com/appserve/security-bugs/log/youtubex-xss-protection: 1; mode=block; report=https://www.google.com/appserve/security-bugs/log/youtube< date: Tue, 06 Nov 2018 23:48:22 GMTdate: Tue, 06 Nov 2018 23:48:22 GMT< server: YouTube Frontend Proxyserver: YouTube Frontend Proxy< set-cookie: VISITOR_INFO1_LIVE=gjFq7WYssGA; path=/; domain=.youtube.com; expires=Sun, 05-May-2019 23:48:21 GMT; httponlyset-cookie: VISITOR_INFO1_LIVE=gjFq7WYssGA; path=/; domain=.youtube.com; expires=Sun, 05-May-2019 23:48:21 GMT; httponly< set-cookie: YSC=zLHS8Ul1c_4; path=/; domain=.youtube.com; httponlyset-cookie: YSC=zLHS8Ul1c_4; path=/; domain=.youtube.com; httponly< set-cookie: GPS=1; path=/; domain=.youtube.com; expires=Wed, 07-Nov-2018 00:18:21 GMTset-cookie: GPS=1; path=/; domain=.youtube.com; expires=Wed, 07-Nov-2018 00:18:21 GMT< alt-svc: quic=":443"; ma=2592000; v="44,43,39,35"alt-svc: quic=":443"; ma=2592000; v="44,43,39,35"< accept-ranges: noneaccept-ranges: none< vary: Accept-Encodingvary: Accept-Encoding<* Connection #0 to host www.youtube.com left intactroot@OPNsense:~ #
The following error was encountered while trying to retrieve the URL: https://104.16.112.58/*Failed to establish a secure connection to 104.16.112.58The system returned:(92) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)Handshake with SSL server failed: error:140920F8:SSL routines:ssl3_get_server_hello:unknown cipher returned