使用squid3 -kparsing我看到这个:
正在处理:https_port 443 cert = myCA.pem
错误:'https_port'需要–enable-ssl
如何启用ssl?
输出squid3 -v
squidcaching:版本3.4.8 linuxconfiguration选项:'–build = x86_64-linux-gnu''–prefix = / usr''–includedir = $ {prefix} / include''–mandir = $ {prefix } / share / man''–infodir = $ {prefix} / share / info''–sysconfdir = / etc''–localstatedir = / var''–libexecdir = $ {prefix} / lib / squid3' '–srcdir ='。 '–disable-maintainer-mode''–disable-dependency-tracking''–disable-silent-rules''–datadir = / usr / share / squid3''–sysconfdir = / etc / squid3'' –mandir = / usr / share / man''–enable-inline''–disable-arch-native''–enable-async-io = 8''–enable-storeio = ufs,aufs,diskd ,'rock'–enable-removal-policies = lru,heap''–enable-delay-pools''–enable-cache-digests''–enable-icap-client''–enable-follow- x-forwarded-for“”–enable-auth-basic = DB,fake,getpwnam,LDAP,MSNT,MSNT-multi-domain,NCSA,NIS,PAM,POP3,RADIUS,SASL,SMB“–enable- auth-digest = file,LDAP''–enable-auth-negotiate = kerberos,wrapper''–enable-auth-ntlm = fake,smb_lm''–enable-external-acl-helpers = file_userip,kerberos_ldap_group,LDAP_group ,session,SQL_session,unix_group,wbinfo_group''–enable-url-rewrite-helpers = fake''–enable-eui''–enable-esi''–enable-icmp''–enable-zph- qos''–enable-ecap''–disable-translation''–with-swapdir = / var / spool / squid3''–with-logdir = / var / log / squid3''–with-pidfile = / var / run / squid3.pid''–with-filed escriptors = 65536''–with-large-files''–with-default-user = proxy''–enable-build-info = linux''–enable-linux-netfilter''build_alias = x86_64-linux -gnu''CFLAGS = -g -O2 -fPIE -fstack-protector-strong -Wformat -Werror = format-security -Wall''LDFLAGS = -fPIE -pie -Wl,-z,relro -Wl,-z,now ''CPPFLAGS = -D_FORTIFY_SOURCE = 2''CXXFLAGS = -g -O2 -fPIE -fstack-protector-strong -Wformat -Werror = format-security'
那么,如你的squid3 -v输出所示,你的squid编译选项中没有--enable-ssl标志。 所以没有SSL,恐怕。 使用--enable-ssl标志编译它,或使用不同的方法,如SslBump 。