Proxy - squid.conf (lab)
Proxy Solution · Config document · referenced from Squid with SSL interception
squid.conf of dc1-a-vcprx001 and dc2-a-vcprx001 is not in my notes beyond its two port lines, which are in Listening ports of dc1-a-vcprx001 and Listening ports of dc2-a-vcprx001. The acl step3 line is defined and never used.The whole /etc/squid/squid.conf of the lab proxy proxy.lab.example.net: the file the squid package of RHEL 7.5 installs, with the default http_port 3128 commented out and three blocks added below it, each marked # LOCAL ->: the listening port with ssl-bump and the lab's self-signed certificate, the SSL-bump ACLs and rules, and a commented-out sslproxy_cafile. Everything else is the package default, including the localnet ACL for the RFC 1918 ranges and the http_access order.
| Item | Value |
|---|---|
| Path | /etc/squid/squid.conf |
| Host | proxy.lab.example.net, the lab VMware guest, RHEL 7.5 |
| Edited as | root, with vi, after yum install squid |
| Reads | /etc/squid/ssl_exclude_domains.conf, /etc/squid/ssl_exclude_ips.conf, the key and certificate under /etc/pki/tls/ |
| Activated with | the notes do not record a systemctl start squid or a reload in the lab; the certificate cache /var/lib/ssl_db had to exist first |
| Software version | Squid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version) |
| Comments | # LOCAL -> lines are mine from 2018; # NOTE: lines were added for this write-up; the rest is the package's |
The file
# # Recommended minimum configuration: # # Example rule allowing access from your local networks. # Adapt to list your (internal) IP networks from where browsing # should be allowed acl localnet src 10.0.0.0/8 # RFC1918 possible internal network acl localnet src 172.16.0.0/12 # RFC1918 possible internal network acl localnet src 192.168.0.0/16 # RFC1918 possible internal network acl localnet src fc00::/7 # RFC 4193 local private network range acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines # NOTE: SSL_ports is the only port CONNECT may tunnel to; Safe_ports is # NOTE: every port a plain request may ask for. Both are package defaults. acl SSL_ports port 443 acl Safe_ports port 80 # http acl Safe_ports port 21 # ftp acl Safe_ports port 443 # https acl Safe_ports port 70 # gopher acl Safe_ports port 210 # wais acl Safe_ports port 1025-65535 # unregistered ports acl Safe_ports port 280 # http-mgmt acl Safe_ports port 488 # gss-http acl Safe_ports port 591 # filemaker acl Safe_ports port 777 # multiling http acl CONNECT method CONNECT # # Recommended minimum Access Permission configuration: # # Deny requests to certain unsafe ports http_access deny !Safe_ports # Deny CONNECT to other than secure SSL ports http_access deny CONNECT !SSL_ports # Only allow cachemgr access from localhost http_access allow localhost manager http_access deny manager # We strongly recommend the following be uncommented to protect innocent # web applications running on the proxy server who think the only # one who can access services on "localhost" is a local user #http_access deny to_localhost # # INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS # # Example rule allowing access from your local networks. # Adapt localnet in the ACL section to list your (internal) IP networks # from where browsing should be allowed http_access allow localnet http_access allow localhost # And finally deny all other access to this proxy http_access deny all # Squid normally listens to port 3128 # http_port 3128 # LOCAL -> Squid listen Port with enable SSL-bump # NOTE: bound to the internal address only; the certificate acts as the CA # NOTE: for the host certificates Squid generates on the fly. http_port 10.90.114.114:3128 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB key=/etc/pki/tls/private/proxy.lab.example.net.key cert=/etc/pki/tls/certs/proxy.lab.example.net.crt # LOCAL -> SSL-bump configuration # NOTE: one ACL per SSL-bump step; step3 is defined but used by no rule below. acl step1 at_step SslBump1 acl step2 at_step SslBump2 acl step3 at_step SslBump3 # NOTE: the two exclusion lists, one file name per line, one entry per line. acl ssl_exclude_domains ssl::server_name "/etc/squid/ssl_exclude_domains.conf" acl ssl_exclude_ips dst "/etc/squid/ssl_exclude_ips.conf" # NOTE: evaluated at every step, first match wins: localhost is never bumped; # NOTE: step 1 peeks to learn the server name; excluded names and addresses # NOTE: are spliced at step 2; everything else is stared at and bumped. ssl_bump splice localhost ssl_bump peek step1 all ssl_bump splice ssl_exclude_domains ssl_bump splice ssl_exclude_ips ssl_bump stare step2 all ssl_bump bump all # LOCAL -> SSL CA-bundle # NOTE: left commented out; see the table below. #sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crt # Uncomment and adjust the following to add a disk cache directory. #cache_dir ufs /var/spool/squid 100 16 256 # Leave coredumps in the first cache dir coredump_dir /var/spool/squid # # Add any of your own refresh_pattern entries above these. # refresh_pattern ^ftp: 1440 20% 10080 refresh_pattern ^gopher: 1440 0% 1440 refresh_pattern -i (/cgi-bin/|\?) 0 0% 0 refresh_pattern . 0 20% 4320
The lines
The meaning of the directives below is my reading of the Squid 3.5 documentation and of the SslPeekAndSplice page, which is the reference I used at the time; the notes themselves hold only the file.
| Line | What it does |
|---|---|
acl localnet src … | The clients that may use the proxy: the three RFC 1918 ranges, which are also the source ranges of the firewalld rich rules, plus the IPv6 unique-local and link-local ranges. The package default was kept; the organisation's 2001:db8::/32 is not in it |
acl SSL_ports port 443, acl CONNECT method CONNECT, http_access deny CONNECT !SSL_ports | A CONNECT tunnel, which is how a client sends HTTPS through a forward proxy, is allowed to port 443 only |
http_access deny !Safe_ports | Plain requests to ports outside the Safe_ports list are refused |
http_access allow localhost manager, http_access deny manager | The cache manager interface is reachable from the proxy itself only |
#http_access deny to_localhost | Left commented out as the package ships it |
http_access allow localnet, http_access allow localhost, http_access deny all | The order matters: the first matching http_access line decides, so everything not from localnet or the proxy itself is denied |
# http_port 3128 | The package default, commented out and replaced by the line below |
http_port 10.90.114.114:3128 ssl-bump … | Listen on the internal address only. ssl-bump turns SSL interception on for this port, generate-host-certificates=on makes Squid generate a certificate for each origin server it bumps, dynamic_cert_mem_cache_size=4MB is the size of the in-memory cache of those certificates, key= and cert= are the lab's self-signed key and certificate, which sign the generated ones |
acl step1 at_step SslBump1 and step2, step3 | True at the first, second and third SSL-bump step; step3 is never used |
acl ssl_exclude_domains ssl::server_name "…" | Matches the server name the client sent in the TLS handshake (SNI) against the names in ssl_exclude_domains.conf; a leading dot matches the domain and its subdomains |
acl ssl_exclude_ips dst "…" | Matches the destination address of the connection against ssl_exclude_ips.conf |
ssl_bump splice localhost | Connections from the proxy itself are tunnelled untouched |
ssl_bump peek step1 all | At step 1 Squid only knows the CONNECT target; peek reads the client's handshake to learn the server name without giving up the choice to splice later |
ssl_bump splice ssl_exclude_domains, ssl_bump splice ssl_exclude_ips | At step 2, with the server name known, excluded names and destinations become a plain tunnel: nothing is decrypted |
ssl_bump stare step2 all | Everything else: Squid fetches the origin server's certificate so the generated one can mimic it, keeping bump possible |
ssl_bump bump all | At step 3 the connection is bumped: the client gets a certificate generated and signed by the proxy, Squid talks TLS to the origin itself |
#sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crt | Would tell Squid which CA bundle to verify origin server certificates against. It stayed commented out; the notes do not say why, and what Squid 3.5 did without it is in the last section |
#cache_dir ufs /var/spool/squid 100 16 256 | The disk cache was left off as the package ships it; the notes hold no cache settings at all |
coredump_dir, refresh_pattern … | Package defaults, untouched |
Two things to know before copying it. The localnet ACL and the firewalld rules agree for IPv4, but not for IPv6: firewalld on the production proxies accepts port 3128 from 2001:db8::/32, while this localnet has only fc00::/7 and fe80::/10, so an IPv6 client would pass the firewall and be refused by http_access deny all if the production file kept this block. Whether it did I cannot say: the production file is not in the notes, and the lab interfaces had no IPv6 (IPV6INIT=no). And the file does not set sslcrtd_program, so it names neither the certificate generator nor its database path; the SELinux error on dc2-a-vcprx001 names /var/lib/ssl_db, the path the cache was created at, and whether the production file set sslcrtd_program or left the build's default is not in the notes, see SELinux and client trust.
Checked against Squid 7.7
| As built | Today |
|---|---|
Squid 3.5 from RHEL 7.5 (squid-3.5.20-12.el7) | Squid 7.7 (August 2026) is the only supported series; 3.5 ended with 3.5.27 in August 2018. RHEL 8 ships Squid 4.15, RHEL 9 5.5, RHEL 10 6.10. RHEL 7 left maintenance support on 2024-06-30 |
acl localnet src with the three RFC 1918 ranges, fc00::/7, fe80::/10 | The upstream default added 0.0.0.1-0.255.255.255, 100.64.0.0/10 and 169.254.0.0/16; the five lines of this file are still in it |
acl CONNECT method CONNECT | Gone from the default file: CONNECT is a predefined ACL now, together with all, manager, localhost, to_localhost and to_linklocal |
http_access allow localnet before deny all | Squid 6 changed the shipped default to allow localhost, deny to_localhost, deny to_linklocal, # http_access allow localnet, deny all: a new install proxies for localhost only until the line is uncommented. Upgraded installations keep their settings. RHEL 9's Squid 5.5 still allows localnet; RHEL 10's Squid 6.10 ships the localhost-only default |
http_port … ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB key=… cert=… | ssl-bump and dynamic_cert_mem_cache_size (default 4MB) are unchanged. key= and cert= are spelled tls-key= and tls-cert=, the old spellings are still accepted. generate-host-certificates defaults to on since Squid 4. Squid 7.7 adds that "the first tls-cert= option must be a CA certificate capable of signing the automatically generated certificates" |
ssl_crtd, the certificate generator, with its database created at /var/lib/ssl_db and no sslcrtd_program line in this file | Renamed security_file_certgen in Squid 4; the compiled-in default database moved to <cache dir>/ssl_db, /var/spool/squid/ssl_db on RHEL builds. The default sslcrtd_program line is still … -s <database> -M 4MB, and the helper now refuses -s without -M, so the database is created with security_file_certgen -c -s <dir> -M 4MB |
acl … at_step SslBump1, ssl::server_name, ssl_bump splice, peek, stare, bump | All in 7.7 with the same meaning. New since Squid 4: the ssl::server_name options --client-requested, --server-provided and --consensus, and at_step GeneratingCONNECT. The wiki still says that peeking at the server certificate at step 2 "usually precludes bumping", and to stare when bumping matters, which is what this file does |
#sslproxy_cafile /etc/pki/tls/certs/ca-bundle.crt | Obsolete: Squid 7.7 answers "Remove this line. Use tls_outgoing_options cafile= instead." tls_outgoing_options uses the system CAs by default (default-ca on). In 3.5.20 the directive's default was none and OpenSSL's built-in CA list was used, so the commented line changed nothing then and would be an error to uncomment now |
refresh_pattern ^gopher: … | Dropped from the default file; the ^ftp:, -i cgi-bin and . patterns are unchanged, as are http_port 3128, the commented cache_dir and coredump_dir |
The SSL-bump block of this file would still be read by Squid 7.7 as written. What would not survive an upgrade untouched is around it: the certificate generator's name, path and -M, the tls- spellings, and, on a fresh Squid 6 or later install, the localnet permission that has to be switched on again. The plain self-signed certificate of 2018 was made without CA extensions, so it is not the CA certificate that 7.7 documents as required; whether 7.7 would refuse it was not tested. The Squid wiki's one-step openssl req -new -x509 -extensions v3_ca recipe is the documented way to make one.