[squid-users] Best practices for beefing up security for squid with ssl-bump

Masha Lifshin mlifshin at phantomdesign.com
Sat May 13 02:33:52 UTC 2017


Dear Squid Users list,

I have a Squid 4 configured as explicit proxy with ssl-bump interception.
I am working on making it as secure as possible, given the vulnerability
risks with doing ssl inspection (
https://insights.sei.cmu.edu/cert/2015/03/the-risks-of-ssl-inspection.html).

I am implementing the hardening suggestions at
http://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit

One other feature I have found is the SSL Server Certificate Validator.  As
far as I understand one can write a helper that performs additional
certificate validation checks that squid doesn't perform out of the box?
Does anyone know of any widely agreed upon open source helpers, or is this
something where people are rolling their own?

Are there other configuration options that can help?  I am curious what
else others in the community are doing along these lines, and if there are
recommended best practices in the squid community?  I appreciate your
insights.

Thank you very much,
-Masha
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20170512/72aa786b/attachment.html>


More information about the squid-users mailing list