LINUXOR.SK ... open source notes ...

Proxy - squid.conf (lab)

category: solutionz/proxy · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Squid with SSL interception

noteThis is the lab file. The production squid.conf of dc1-a-vcprx001 and dc2-a-vcprx001 is not in my notes beyond its two port lines, which are in Listening ports of dc1-a-vcprx001 and Listening ports of dc2-a-vcprx001. The acl step3 line is defined and never used.

The whole /etc/squid/squid.conf of the lab proxy proxy.lab.example.net: the file the squid package of RHEL 7.5 installs, with the default http_port 3128 commented out and three blocks added below it, each marked # LOCAL ->: the listening port with ssl-bump and the lab's self-signed certificate, the SSL-bump ACLs and rules, and a commented-out sslproxy_cafile. Everything else is the package default, including the localnet ACL for the RFC 1918 ranges and the http_access order.

ItemValue
Path/etc/squid/squid.conf
Hostproxy.lab.example.net, the lab VMware guest, RHEL 7.5
Edited asroot, with vi, after yum install squid
Reads/etc/squid/ssl_exclude_domains.conf, /etc/squid/ssl_exclude_ips.conf, the key and certificate under /etc/pki/tls/
Activated withthe notes do not record a systemctl start squid or a reload in the lab; the certificate cache /var/lib/ssl_db had to exist first
Software versionSquid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version)
Comments# LOCAL -> lines are mine from 2018; # NOTE: lines were added for this write-up; the rest is the package's

The file

ini
#
# Recommended minimum configuration:
#

# Example rule allowing access from your local networks.
# Adapt to list your (internal) IP networks from where browsing
# should be allowed
acl localnet src 10.0.0.0/8	# RFC1918 possible internal network
acl localnet src 172.16.0.0/12	# RFC1918 possible internal network
acl localnet src 192.168.0.0/16	# RFC1918 possible internal network
acl localnet src fc00::/7       # RFC 4193 local private network range
acl localnet src fe80::/10      # RFC 4291 link-local (directly plugged) machines

# NOTE: SSL_ports is the only port CONNECT may tunnel to; Safe_ports is
# NOTE: every port a plain request may ask for. Both are package defaults.
acl SSL_ports port 443
acl Safe_ports port 80		# http
acl Safe_ports port 21		# ftp
acl Safe_ports port 443		# https
acl Safe_ports port 70		# gopher
acl Safe_ports port 210		# wais
acl Safe_ports port 1025-65535	# unregistered ports
acl Safe_ports port 280		# http-mgmt
acl Safe_ports port 488		# gss-http
acl Safe_ports port 591		# filemaker
acl Safe_ports port 777		# multiling http
acl CONNECT method CONNECT

#
# Recommended minimum Access Permission configuration:
#
# Deny requests to certain unsafe ports
http_access deny !Safe_ports

# Deny CONNECT to other than secure SSL ports
http_access deny CONNECT !SSL_ports

# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager

# We strongly recommend the following be uncommented to protect innocent
# web applications running on the proxy server who think the only
# one who can access services on "localhost" is a local user
#http_access deny to_localhost

#
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#

# Example rule allowing access from your local networks.
# Adapt localnet in the ACL section to list your (internal) IP networks
# from where browsing should be allowed
http_access allow localnet
http_access allow localhost

# And finally deny all other access to this proxy
http_access deny all

# Squid normally listens to port 3128
# http_port 3128

# LOCAL -> Squid listen Port with enable SSL-bump
# NOTE: bound to the internal address only; the certificate acts as the CA
# NOTE: for the host certificates Squid generates on the fly.
http_port 10.90.114.114:3128 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB key=/etc/pki/tls/private/proxy.lab.example.net.key cert=/etc/pki/tls/certs/proxy.lab.example.net.crt

# LOCAL -> SSL-bump configuration
# NOTE: one ACL per SSL-bump step; step3 is defined but used by no rule below.
acl step1 at_step SslBump1
acl step2 at_step SslBump2
acl step3 at_step SslBump3

# NOTE: the two exclusion lists, one file name per line, one entry per line.
acl ssl_exclude_domains ssl::server_name "/etc/squid/ssl_exclude_domains.conf"
acl ssl_exclude_ips     dst              "/etc/squid/ssl_exclude_ips.conf"

# NOTE: evaluated at every step, first match wins: localhost is never bumped;
# NOTE: step 1 peeks to learn the server name; excluded names and addresses
# NOTE: are spliced at step 2; everything else is stared at and bumped.
ssl_bump splice localhost
ssl_bump peek step1 all
ssl_bump splice ssl_exclude_domains
ssl_bump splice ssl_exclude_ips
ssl_bump stare step2 all
ssl_bump bump all

# LOCAL -> SSL CA-bundle
# NOTE: left commented out; see the table below.
#sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crt

# Uncomment and adjust the following to add a disk cache directory.
#cache_dir ufs /var/spool/squid 100 16 256

# Leave coredumps in the first cache dir
coredump_dir /var/spool/squid

#
# Add any of your own refresh_pattern entries above these.
#
refresh_pattern ^ftp:		1440	20%	10080
refresh_pattern ^gopher:	1440	0%	1440
refresh_pattern -i (/cgi-bin/|\?) 0	0%	0
refresh_pattern .		0	20%	4320

The lines

The meaning of the directives below is my reading of the Squid 3.5 documentation and of the SslPeekAndSplice page, which is the reference I used at the time; the notes themselves hold only the file.

LineWhat it does
acl localnet src …The clients that may use the proxy: the three RFC 1918 ranges, which are also the source ranges of the firewalld rich rules, plus the IPv6 unique-local and link-local ranges. The package default was kept; the organisation's 2001:db8::/32 is not in it
acl SSL_ports port 443, acl CONNECT method CONNECT, http_access deny CONNECT !SSL_portsA CONNECT tunnel, which is how a client sends HTTPS through a forward proxy, is allowed to port 443 only
http_access deny !Safe_portsPlain requests to ports outside the Safe_ports list are refused
http_access allow localhost manager, http_access deny managerThe cache manager interface is reachable from the proxy itself only
#http_access deny to_localhostLeft commented out as the package ships it
http_access allow localnet, http_access allow localhost, http_access deny allThe order matters: the first matching http_access line decides, so everything not from localnet or the proxy itself is denied
# http_port 3128The package default, commented out and replaced by the line below
http_port 10.90.114.114:3128 ssl-bump …Listen on the internal address only. ssl-bump turns SSL interception on for this port, generate-host-certificates=on makes Squid generate a certificate for each origin server it bumps, dynamic_cert_mem_cache_size=4MB is the size of the in-memory cache of those certificates, key= and cert= are the lab's self-signed key and certificate, which sign the generated ones
acl step1 at_step SslBump1 and step2, step3True at the first, second and third SSL-bump step; step3 is never used
acl ssl_exclude_domains ssl::server_name "…"Matches the server name the client sent in the TLS handshake (SNI) against the names in ssl_exclude_domains.conf; a leading dot matches the domain and its subdomains
acl ssl_exclude_ips dst "…"Matches the destination address of the connection against ssl_exclude_ips.conf
ssl_bump splice localhostConnections from the proxy itself are tunnelled untouched
ssl_bump peek step1 allAt step 1 Squid only knows the CONNECT target; peek reads the client's handshake to learn the server name without giving up the choice to splice later
ssl_bump splice ssl_exclude_domains, ssl_bump splice ssl_exclude_ipsAt step 2, with the server name known, excluded names and destinations become a plain tunnel: nothing is decrypted
ssl_bump stare step2 allEverything else: Squid fetches the origin server's certificate so the generated one can mimic it, keeping bump possible
ssl_bump bump allAt step 3 the connection is bumped: the client gets a certificate generated and signed by the proxy, Squid talks TLS to the origin itself
#sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crtWould tell Squid which CA bundle to verify origin server certificates against. It stayed commented out; the notes do not say why, and what Squid 3.5 did without it is in the last section
#cache_dir ufs /var/spool/squid 100 16 256The disk cache was left off as the package ships it; the notes hold no cache settings at all
coredump_dir, refresh_pattern …Package defaults, untouched

Two things to know before copying it. The localnet ACL and the firewalld rules agree for IPv4, but not for IPv6: firewalld on the production proxies accepts port 3128 from 2001:db8::/32, while this localnet has only fc00::/7 and fe80::/10, so an IPv6 client would pass the firewall and be refused by http_access deny all if the production file kept this block. Whether it did I cannot say: the production file is not in the notes, and the lab interfaces had no IPv6 (IPV6INIT=no). And the file does not set sslcrtd_program, so it names neither the certificate generator nor its database path; the SELinux error on dc2-a-vcprx001 names /var/lib/ssl_db, the path the cache was created at, and whether the production file set sslcrtd_program or left the build's default is not in the notes, see SELinux and client trust.

Checked against Squid 7.7

As builtToday
Squid 3.5 from RHEL 7.5 (squid-3.5.20-12.el7)Squid 7.7 (August 2026) is the only supported series; 3.5 ended with 3.5.27 in August 2018. RHEL 8 ships Squid 4.15, RHEL 9 5.5, RHEL 10 6.10. RHEL 7 left maintenance support on 2024-06-30
acl localnet src with the three RFC 1918 ranges, fc00::/7, fe80::/10The upstream default added 0.0.0.1-0.255.255.255, 100.64.0.0/10 and 169.254.0.0/16; the five lines of this file are still in it
acl CONNECT method CONNECTGone from the default file: CONNECT is a predefined ACL now, together with all, manager, localhost, to_localhost and to_linklocal
http_access allow localnet before deny allSquid 6 changed the shipped default to allow localhost, deny to_localhost, deny to_linklocal, # http_access allow localnet, deny all: a new install proxies for localhost only until the line is uncommented. Upgraded installations keep their settings. RHEL 9's Squid 5.5 still allows localnet; RHEL 10's Squid 6.10 ships the localhost-only default
http_port … ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB key=… cert=…ssl-bump and dynamic_cert_mem_cache_size (default 4MB) are unchanged. key= and cert= are spelled tls-key= and tls-cert=, the old spellings are still accepted. generate-host-certificates defaults to on since Squid 4. Squid 7.7 adds that "the first tls-cert= option must be a CA certificate capable of signing the automatically generated certificates"
ssl_crtd, the certificate generator, with its database created at /var/lib/ssl_db and no sslcrtd_program line in this fileRenamed security_file_certgen in Squid 4; the compiled-in default database moved to <cache dir>/ssl_db, /var/spool/squid/ssl_db on RHEL builds. The default sslcrtd_program line is still … -s <database> -M 4MB, and the helper now refuses -s without -M, so the database is created with security_file_certgen -c -s <dir> -M 4MB
acl … at_step SslBump1, ssl::server_name, ssl_bump splice, peek, stare, bumpAll in 7.7 with the same meaning. New since Squid 4: the ssl::server_name options --client-requested, --server-provided and --consensus, and at_step GeneratingCONNECT. The wiki still says that peeking at the server certificate at step 2 "usually precludes bumping", and to stare when bumping matters, which is what this file does
#sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crtObsolete: Squid 7.7 answers "Remove this line. Use tls_outgoing_options cafile= instead." tls_outgoing_options uses the system CAs by default (default-ca on). In 3.5.20 the directive's default was none and OpenSSL's built-in CA list was used, so the commented line changed nothing then and would be an error to uncomment now
refresh_pattern ^gopher: …Dropped from the default file; the ^ftp:, -i cgi-bin and . patterns are unchanged, as are http_port 3128, the commented cache_dir and coredump_dir

The SSL-bump block of this file would still be read by Squid 7.7 as written. What would not survive an upgrade untouched is around it: the certificate generator's name, path and -M, the tls- spellings, and, on a fresh Squid 6 or later install, the localnet permission that has to be switched on again. The plain self-signed certificate of 2018 was made without CA extensions, so it is not the CA certificate that 7.7 documents as required; whether 7.7 would refuse it was not tested. The Squid wiki's one-step openssl req -new -x509 -extensions v3_ca recipe is the documented way to make one.

← solutionz/proxy