LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-12-2011, 11:54 AM   #1
Lexus45
Member
 
Registered: Jan 2010
Distribution: Debian, Centos, Ubuntu, Slackware
Posts: 361
Blog Entries: 3

Rep: Reputation: 48
Squid HTTPS-proxy and certificate


Hello all.
I would like to discuss setting up Squid as a https proxy.

In fact, the Squid settings are clear - http://www.squid-cache.org/Versions/...ttps_port.html

just add
Code:
https_port [server.name:port cert=certificate.pem [key=key.pem]
But I'm not sure what's the right way to create this certifacate.pem file.

We'd like to push the traffic from our employees through the proxy. This traffic includes Skype traffic too. But the Skype support only 2 proxy types: SOCKS and HTTPS, according to its settings. So, we need to make our proxy not only HTTPS, but HTTPS also.

What I've learned is that PEM-format may be used with Apache. But I don't know exactly what certificate is used on out webserver (I do not administrate it, but I know for sure that it's configured with HTTPS support). The easiest way, as I see it, is to cope the PEM-certificate from the webserver to the proxy-server.Correct me please if I'm mistaken.

Best regards, Alexey.
=======================
I think this is the way to go:
http://www.madboa.com/geek/openssl/#cert-self

Last edited by Lexus45; 11-12-2011 at 01:01 PM.
 
Old 11-14-2011, 10:20 AM   #2
mulyadi.santosa
Member
 
Registered: Sep 2011
Posts: 96

Rep: Reputation: 15
Hi Alexey...

After reading the related documentation, I came to conclusion that https_port only works when you operate Squid as somekind of reverse proxy.

Specifically, to be able as https reverse proxy, it must hold the same certificate as the original web server. So in this case, somehow you need to get the Skype server(s) certificate.

Unless you're able to do that somehow, this https_port option is useless for your IMHO.
 
Old 11-14-2011, 12:14 PM   #3
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,
Quote:
The easiest way, as I see it, is to cope the PEM-certificate from the webserver to the proxy-server.Correct me please if I'm mistaken.
If they both run on the same box (so the CN in the certificate will match), then there will be no problem.

Why don't you try the ss5 socks server?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
transparent proxy squid: problem with the HTTPS pnguwe Linux - Networking 7 11-22-2011 08:00 AM
Https bypasses squid proxy amreshfaldesai Linux - Networking 2 10-01-2011 01:00 AM
Squid reverse proxy problem (HTTPS to HTTP) RussP Linux - Networking 1 10-02-2008 01:20 PM
slow squid proxy connection with https sides Sammy2ooo Linux - Newbie 0 10-09-2003 02:43 PM
Squid proxy and https roba Linux - Software 2 08-14-2002 04:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:01 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration