Proxy - ssl_exclude_domains.conf (lab)
Proxy Solution · Config document · referenced from Squid with SSL interception
The list of server names that Squid must not intercept. The ssl_exclude_domains ACL in squid.conf reads it with ssl::server_name, and the rule ssl_bump splice ssl_exclude_domains turns every connection whose TLS server name matches into a plain tunnel, so the client sees the origin server's own certificate.
| Item | Value |
|---|---|
| Path | /etc/squid/ssl_exclude_domains.conf |
| Host | proxy.lab.example.net, the lab VMware guest, RHEL 7.5 |
| Read by | acl ssl_exclude_domains ssl::server_name "/etc/squid/ssl_exclude_domains.conf" |
| Format | one name per line; a leading dot matches the domain and every name under it |
| Activated with | a Squid reload or restart; the notes record neither |
| Software version | Squid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version) |
The file
.example.com .example.org
The entries
| Entry | Effect |
|---|---|
.example.com | example.com and every host under it is spliced, never bumped |
.example.org | the same for example.org |
As I read the ssl::server_name ACL of Squid 3.5, it matches whatever server name Squid has at the step where the rule is evaluated: the host of the CONNECT request at step 1, the name the client sent in its TLS handshake (SNI) from step 2 on, and the names in the server's certificate at step 3. In this configuration the rule comes after peek step1, so it is normally decided at step 2 on the SNI. A client that sends a bare address in CONNECT and no server name is not matched here and falls through to the address list in ssl_exclude_ips.conf and then to stare and bump.
Checked against Squid 7.7
| As built | Today |
|---|---|
acl ssl_exclude_domains ssl::server_name "<file>" | Unchanged. Squid 7.7 documents the ACL as computing the server name from "CONNECT request URI, TLS client SNI, and TLS server certificate subject (CN and SubjectAltName)" and, unlike dstdomain, doing no DNS lookups. Since Squid 4 it takes options: --client-requested (the SNI regardless of what the server says), --server-provided (the names in the server certificate, none if there is no certificate yet) and --consensus (the SNI only when the certificate confirms it) |
.example.com as the first entry | The ssl_bump documentation of Squid 7.7 uses the same example, acl broken_sites ssl::server_name .example.com with ssl_bump splice broken_sites, which supports reading these two lines as example entries |
| Overlapping entries | Squid 7 merges overlapping sub-domain and wildcard entries of ssl::server_name instead of keeping both |
The file itself needs no change for Squid 7.7. What I would reconsider is the match: without an option the ACL trusts whatever name is at hand, and a client can put any name into its SNI; --server-provided or --consensus makes the exclusion depend on the certificate the server shows.