LINUXOR.SK ... open source notes ...

Proxy - ssl_exclude_domains.conf (lab)

category: solutionz/proxy · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Squid with SSL interception

noteThe two entries look like example entries, not like servers the lab had to reach; the notes do not say why they are there. The production lists are not in the notes.

The list of server names that Squid must not intercept. The ssl_exclude_domains ACL in squid.conf reads it with ssl::server_name, and the rule ssl_bump splice ssl_exclude_domains turns every connection whose TLS server name matches into a plain tunnel, so the client sees the origin server's own certificate.

ItemValue
Path/etc/squid/ssl_exclude_domains.conf
Hostproxy.lab.example.net, the lab VMware guest, RHEL 7.5
Read byacl ssl_exclude_domains ssl::server_name "/etc/squid/ssl_exclude_domains.conf"
Formatone name per line; a leading dot matches the domain and every name under it
Activated witha Squid reload or restart; the notes record neither
Software versionSquid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version)

The file

ini
.example.com
.example.org

The entries

EntryEffect
.example.comexample.com and every host under it is spliced, never bumped
.example.orgthe same for example.org

As I read the ssl::server_name ACL of Squid 3.5, it matches whatever server name Squid has at the step where the rule is evaluated: the host of the CONNECT request at step 1, the name the client sent in its TLS handshake (SNI) from step 2 on, and the names in the server's certificate at step 3. In this configuration the rule comes after peek step1, so it is normally decided at step 2 on the SNI. A client that sends a bare address in CONNECT and no server name is not matched here and falls through to the address list in ssl_exclude_ips.conf and then to stare and bump.

Checked against Squid 7.7

As builtToday
acl ssl_exclude_domains ssl::server_name "<file>"Unchanged. Squid 7.7 documents the ACL as computing the server name from "CONNECT request URI, TLS client SNI, and TLS server certificate subject (CN and SubjectAltName)" and, unlike dstdomain, doing no DNS lookups. Since Squid 4 it takes options: --client-requested (the SNI regardless of what the server says), --server-provided (the names in the server certificate, none if there is no certificate yet) and --consensus (the SNI only when the certificate confirms it)
.example.com as the first entryThe ssl_bump documentation of Squid 7.7 uses the same example, acl broken_sites ssl::server_name .example.com with ssl_bump splice broken_sites, which supports reading these two lines as example entries
Overlapping entriesSquid 7 merges overlapping sub-domain and wildcard entries of ssl::server_name instead of keeping both

The file itself needs no change for Squid 7.7. What I would reconsider is the match: without an option the ACL trusts whatever name is at hand, and a client can put any name into its SNI; --server-provided or --consensus makes the exclusion depend on the certificate the server shows.

← solutionz/proxy