LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-08-2016, 04:00 PM   #1
9acca9
LQ Newbie
 
Registered: Aug 2016
Posts: 5

Rep: Reputation: Disabled
Squid 3.3.8 Https (not transparent)


I want to limit the bandwidth for youtube, so I want to intercept https connections. I followed several tutorials and can not. Could someone give me a hand ??

Code:
# Squid listen Port
http_port 192.168.1.215:3128 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB key=/etc/squid/example.com.private cert=/etc/squid/example.com.cert
# SSL Bump Config
always_direct allow all
ssl_bump server-first all
sslproxy_cert_error deny all
sslproxy_flags DONT_VERIFY_PEER
sslcrtd_program /usr/lib64/squid/ssl_crtd -s /var/lib/ssl_db -M 4MB sslcrtd_children 8 startup=1 idle=1
I import the example.com.pem to the webbrowser and then any web https i go i get "The proxy server is refusing connections". if not https go well.

What can i do?????

This is access.log

Code:
192.168.1.172 TCP_HIT/200 52543 GET http://www.silencio.com.ar/wp-content/uploads/2016/07/AHJ8239-540x386.jpg - HIER_NONE/- image/jpeg
192.168.1.172 TCP_HIT/200 49912 GET http://www.silencio.com.ar/wp-content/uploads/2016/07/strokes-2001-adentro-540x386.jpg - HIER_NONE/- image/jpeg
192.168.1.172 TCP_HIT/200 43804 GET http://www.silencio.com.ar/wp-content/uploads/2016/07/ArcticMonkeys012-540x386.jpg - HIER_NONE/- image/jpeg
192.168.1.172 TCP_DENIED/200 0 CONNECT www.google-analytics.com:443 - HIER_NONE/- -
192.168.1.172 TCP_MISS/301 807 GET http://www.youtube.com/ - HIER_DIRECT/64.233.186.91 text/html
192.168.1.172 NONE/200 0 CONNECT www.youtube.com:443 - HIER_DIRECT/64.233.186.91 -
192.168.1.172 NONE/200 0 CONNECT blocklist.addons.mozilla.org:443 - HIER_DIRECT/52.35.149.230 -
Thanks!
 
Old 08-19-2016, 02:09 PM   #2
ReinaldoGomes
LQ Newbie
 
Registered: Jul 2016
Posts: 15

Rep: Reputation: Disabled
Have you considered changing to Squid 3.5? There's been several changes, including on SSL interception, and it should be easier for you to get troubleshooting support.
 
  


Reply

Tags
https, squid, ssl



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
https through transparent squid jibamandal Linux - Security 1 09-20-2015 05:39 PM
Squid transparent proxy for HTTPS AmitGupta Linux - Security 1 08-29-2014 02:06 AM
Transparent Slackware proxy using Squid and SquidGuard : HTTPS Facebook? kikinovak Slackware 1 08-26-2013 07:48 AM
Transparent Squid https errer gulnawaz Linux - Newbie 11 01-03-2013 05:01 AM
transparent proxy squid: problem with the HTTPS pnguwe Linux - Networking 7 11-22-2011 08:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration