[squid-dev] Fwd: RFP: ssl-bump support for upstream proxy in transparent mode

Alexandr sss at sss.chaoslab.ru
Fri Jun 30 17:21:30 UTC 2017



-------- Исходное сообщение --------
Тема: RFP: ssl-bump support for upstream proxy in transparent mode
Дата: 2017-06-25 01:38
От: Alexandr <sss at sss.chaoslab.ru>
Кому: squid-dev at lists.squid-cache.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

good day.
i am interested in ssl-bump, or at list splice in transparent mode for
upstream proxy.
use-case:
1. squid used in transparent mode like this:
iptables:
iptables -t nat -A PREROUTING -i br0 -p tcp -m tcp --dport 80 -j DNAT
- --to-destination 192.168.0.1:3129
iptables -t nat -A PREROUTING -i br0 -p tcp -m tcp --dport 443 -j DNAT
- --to-destination 192.168.0.1:3130
squid.conf:
cache_peer 192.168.0.1 parent 8118 0 no-digest no-query no-netdb-
exchange no-delay name=tor max-conn=8 standby=2 default
cache_peer 192.168.0.1 parent 8128 0 no-digest no-query no-netdb-
exchange no-delay name=i2p max-conn=16 standby=4 default

cache_peer_access i2p allow i2p
cache_peer_access i2p deny all
cache_peer_access tor allow tor
cache_peer_access tor allow blocked_russia
cache_peer_access tor deny all

never_direct allow tor
never_direct allow blocked_russia
never_direct allow i2p

always_direct deny tor
always_direct deny blocked_russia
always_direct deny i2p


http_port 192.168.0.1:3129 intercept
https_port 192.168.0.1:3130 intercept ssl-bump connection-auth=off
generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
cert=/etc/squid/ssl/example.com.cert
key=/etc/squid/ssl/example.com.private cipher=HIGH:!WEAK:!MEDIUM:!RC4
sslflags=VERIFY_CRL_ALL

//currently configured to splice ssl connections via tor/i2p and
blocked_russia acls

2. ssl-bump/splice is required for all connections
3. most internet is accessible directly, but some parts accessible only
via upstream proxy, in transparent mode ssl/tls connections via
upstream proxy currently does not work.

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEl/sA7WQg6czXWI/dsEApXVthX7wFAllO6fUACgkQsEApXVth
X7wmzA//QLVxTd4NI7sk+GtHnEWnClEd4eRDBvbVmQOol/aoRkOTjv9DHMhYjV5y
kkNoHeQUtlyTvwrLPNLt3PYmFD8vz3Kc+2KWnhSq0UxLBasgO8SDn5MqZOm+RV9R
P/7sVI37pjibW9d3euPl2Antxg2n8hhffKa97EcoWWnnmGUDzv3n1tHLnB5HafqI
W0DRORAcpuRocPZ1Y91uqKbPlJD9X4ANGIeHc/Pf2FMoOGmp/7YVoP4gWFRIgyK4
faMDlyCS3vNMhBZAE+/+jgGgkw84s2xUtdvgJCbglq+0kBoMxXSllQLzBNcuLs1X
+0wuvs8GtL7mOcYGe5HmHbe5zYmNHe2fI+BKTE/Cq1IxlNXq7H+Ad4zfhvWkVjTy
1uy2s9E6mNb7BOn86wmI7QsqZS4G37nQVq++VDNu95GWXecenoErDvY37CXtKIJ8
Jmn77Z9KyWfrM6kZLKMQZHvGsm1geYMOM0MgxvuujC1nfqRbzPhqGeTbZI2QoeFl
yUUtOCJNznYdpBCfExyUBMjHTot3mY2Cwpyv/x+EwGj6lwqKhDBrbpwTmW4wr8v0
frOOLsXYPiMw5pp/SMqj4YglxIqQSsA+/ZZ1rJ1oXowkJcz4WRTxYoW7m6yDwDbo
hmVPtGz36r74AW+aGgrvE+8akxnC0Z6WyWe9SHHnydw+REbe2yo=
=NZDU
-----END PGP SIGNATURE-----


More information about the squid-dev mailing list