I decided to finally set up the tls version last night since it was included in the Entware repository. There's also a package for easyrsa. Getting it set up was a little different from the guide in the OP but it was close enough that I was able to figure it out. Very pleased with it so far.
Fairly easy just install it and add optional paramaters to the /opt/etc/init.d/S80pixelserv-tls file and either use AB Solutions or my script (ublockr) for making a hostfile for all those pesky ad sites
i opened ten links after reboot router and see at serverstats very high usage req:279, cls:2017 and slh:215.....is this normal?
@kvic in the stats above the numbers do not seem to add up - is there overlap between cls and slh which explains why the sum doesn't add up to req?
An old feature is that max and average times are distorted by those requests that are abandoned due to timeouts, would be more interesting to know timings of requests that are completed successfully - including those that need certificate generation?
I haven't tried the easyrsa package from Entware-ng. I believe it's the older 2.x version.
The new EasyRSA 3.0 is even simpler to use. For crypto newbies, it's fool proof IMO. For semi/pro's, data files/directories are better organised and more coherent.
The package is only a few KiB mainly one shell script driving command line tools from OpenSSL libraries which perform heavy lifting.
For Asuswrt/Merlin users, OpenSSL comes preinstalled with the firmware. Only have to download EasyRSA 3.0 to your router (e.g. /tmp since it's tiny). Here is one guide to generate ca.crt and ca.key for pixelserv-tls.
Once finished, free to trash EasyRSA 3.0
Just a quick bootcamp for potential users.
Chrome offers an "Allow invalid certificates for resources loaded from localhost." option in chrome://flag
I had some issues with mktemp, as I saw pointed out earlier in this thread. Rather than modify anything, I just installed mktemp in Entware and was able to otherwise proceed according to the information you provided. The process was a bit smoother in 3.0, you were right. Really great work on pixelserv-tls.
An old feature is that max and average times are distorted by those requests that are abandoned due to timeouts, would be more interesting to know timings of requests that are completed successfully - including those that need certificate generation?
Hopefully the number of pixleserv processes does drop back to one... BTDTGTTS.
pixelserv-tls version: V35.HZ12.Kh compiled: Mar 26 2016 12:16:28 options: 192.168.66.254 -p 80 -p 81 -p 8080 -p 8081 -k 443 -o 2
982 uts, 43 req, 501 avg, 808 rmx, 70 tav, 1993 tmx, 0 err, 1 tmo, 15 cls, 0 nou, 0 pth, 4 nfe, 1 ufe, 1 gif, 0 bad, 1 txt, 1 jpg, 2 png, 1 swf, 5 ico, 22 slh, 0 slm, 0 sle, 0 slu, 2 sta, 2 stt, 0 204, 7 rdr, 0 pst, 0 hed, 0 log
slh: # of HTTPS /w a good cert 24
So far have only managed to get Firefox to use the generated cert on win7 laptop. Google Chrome/IE refuses to play. Might be issue with corporate/domain/antivirus PC with some locked down settings. Is there a definitive guide for each OS/browser (Trusted root authoritative stores etc)?
Except Firefox, everything else uses the certificates from Windows security vault. Here is a guide to import the CA cert into there:
https://support.comodo.com/index.php?/Default/Knowledgebase/Article/View/636/17/
https://doubleclick.net/servstats
https://192.168.66.254/servstats
This site can’t provide a secure connection
192.168.66.254 uses an unsupported protocol.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
Thread starter | Title | Forum | Replies | Date |
---|---|---|---|---|
C | Diversion Pixelserv replacement | Asuswrt-Merlin AddOns | 2 | |
L | Is Diversion better than NextDNS, PiHole or AdGuard Home? | Asuswrt-Merlin AddOns | 10 |
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!