Proxy - ERROR: failure while accepting a TLS connection

Started by zunami, January 10, 2024, 05:35:48 PM

Previous topic - Next topic
Hi,

I am getting the following error message on my transparent proxy:

kid1| ERROR: failure while accepting a TLS connection on conn34218 local=IPOUTSIDE:443 remote=192.168.1.10:49478 FD 37 flags=33: SQUID_TLS_ERR_ACCEPT+TLS_LIB_ERR=14209175+TLS_IO_ERR=1

I am unable to connect to HTTPS websites. I get the following error message:
This website is probably a secure website, but a secure connection could not be established. This is caused by internal-ca, ...

I have installed the certificate that I created, but I am still getting this error.  ::)
I cannot find any information about this error code on the internet.  ???

My settings:

  • Opnsense freshly installed
  • Adguard installed via extension on port 3000
  • UnboundDNS on port 5353
  • DHCP server with Adguard IP as DNS

Proxy settings:

  • Proxy enabled
  • Internal CA issuer created
  • Internal server CA created
  • CA issuer installed on a Windows computer and marked as trusted
  • Enable Transparent HTTP Proxy Port 3128
  • CA for Transparentproxy SSL from CA issuer
  • Enable SSL Mode
  • Enable Transparent HTTPS Proxy Port 3129
  • No Bump Hosts: .google.com .googleapis.com .gstatic.com .1e100.net
  • ClamAV & ICAP extension installed and enabled

This is my complete configuration, and I am getting the error code "kid1| ERROR: failure while accepting a TLS connection".

Questions:  :o

  • Can anyone help me identify what I am doing wrong? (Based on my information and error code)
  • Do I need HTTPS? Or is it that I can only scan external HTTPS connections with the virus scanner in this way?
  • Could it have something to do with Adguard?
I would be very grateful for any help on how to approach this issue.