From: Michael Tremer Date: Sat, 2 May 2015 10:56:09 +0000 (+0200) Subject: squid: Disable SSL support X-Git-Tag: v2.17-core91~84 X-Git-Url: http://git.ipfire.org/?p=ipfire-2.x.git;a=commitdiff_plain;h=88b1e637ac581b836bcdfa4a44deeef2d8ff9711 squid: Disable SSL support The SSL support parts of squid are a great security risk. The majority of all security issues has been in this area. As we are not using any of that in production we can as well disable SSL support. This won't affect squid's possibility to forward SSL connections with the CONNECT method. --- diff --git a/lfs/squid b/lfs/squid index 48aaa965ae..d4fc4c5a13 100644 --- a/lfs/squid +++ b/lfs/squid @@ -78,12 +78,12 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) --libexecdir=/usr/lib/squid \ --localstatedir=/var \ --disable-ipv6 \ + --disable-ssl \ --enable-poll \ --disable-icmp \ --disable-wccp \ --enable-ident-lookups \ --enable-storeio="aufs,diskd,ufs" \ - --enable-ssl \ --enable-underscores \ --enable-http-violations \ --enable-removal-policies="heap,lru" \