Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #181922

Re: https_port

From "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu>
Newsgroups linux.debian.user
Subject Re: https_port
Date 2017-06-08 14:50 +0200
Message-ID <tQ52V-4l3-1@gated-at.bofh.it> (permalink)
References <tPJ2q-77i-15@gated-at.bofh.it> <tPKhP-7Rr-5@gated-at.bofh.it> <tPKBf-7Z0-79@gated-at.bofh.it> <tPSfs-4Fa-121@gated-at.bofh.it> <tQ4JA-4eB-17@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

How to generate the certificate and the key to make a very basic 
configuration of the https connection.

As basic as possible.
regards






On 08/06/17 03:28, Adiel Plasencia Herrera wrote:
>>Hello,>>They would help me with a configuration of my squid that I want 
to>implement.>>My proxy passes all traffic to a parent proxy and I want 
clients to>connect to my proxy via https.>>Can you help me how to implement 
the connection to my proxy via https?>>To better explain what I want 
attached 2 pictures. The image with>1.jpg name shows my proxy configuration 
with type HTTp that connects>well to internet.>>What I want is for the 
connection to my proxy to be by the form of the>2.jpg image that uses the 
HTTPS type.>>Or if it is possible then leave the 2 forms.
What operating system are you using, and what applications are you 
wanting to use this proxy connection?

The normal configuration is simply to add an https_port line with cert= 
parameter to your squid.conf. More details on that below.


>>>This is my current configuration:>acl trabajadores src 10.5.7.3 
10.5.7.5><snip>
>>http_access allow trabajadores>http_access deny !Safe_ports>http_access 
deny CONNECT !SSL_ports
You custom http_access rules ("allow trabajadores") should be down here 
after the basic security checks.

>http_access deny all>>>http_port 3128

Date: Thu, 8 Jun 2017 01:04:31 +1200
From: Amos Jeffries <squid3@treenet.co.nz>
To: squid-users@lists.squid-cache.org
Subject: Re: [squid-users] https_port
Message-ID: <764ecd5f-6f6c-0eb5-90b4-5591ab5e1920@treenet.co.nz>
Content-Type: text/plain; charset=utf-8; format=flowed

The above port is for receiving plain-text connections to the proxy. 
Most software supports this, with a few exceptions (usually Java apps).


To accept TLS connections to the proxy (not HTTPS *over* the proxy), 
what you do is add an https_port line here. That https_port line needs a 
cert= parameter containing the proxy server certificate. You may need 
other TLS/SSL parameters to fine tune what the TLS does, but just start 
with getting that basic setup to work.
  <http://www.squid-cache.org/Doc/config/https_port/ 
[http://www.squid-cache.org/Doc/config/https_port/]>

For example:
   https_port 3129 cert=/etc/squid/proxy.pem

(the proxy.pem file here contains both the public server cert and 
private server key for that cert).

Many GUI applications (most notably browsers) do not support this type 
of connection to a proxy (or not well if they do). Which is where the 
Q's about your OS and applications come in. You may need to setup 
environment variables or PAC files to get the applications to work.


Note that this is *very* different situation to intercepting port 443 
traffic. Much more different than port 3128 vs. intercepted port 80. 
HTTPS traffic goes through these TLS proxy connections with 
double-layered encryption, so this setup does *not* magically make the 
proxy able to see inside HTTPS if that is what you are really after.

Amos

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

NTP.conf   pool vs server ray <ray@aarden.us> - 2017-06-07 15:20 +0200
  Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 15:30 +0200
    Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:50 +0200
  Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:40 +0200
    Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:00 +0200
    Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:00 +0200
      Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:10 +0200
        Re: NTP.conf pool vs server Joshua Schaeffer <jschaeffer0922@gmail.com> - 2017-06-07 17:30 +0200
          Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:50 +0200
        Re: NTP.conf   pool vs server Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-07 18:10 +0200
      Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:20 +0200
      Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 01:10 +0200
        Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 14:30 +0200
          Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 14:50 +0200
            Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 15:30 +0200
              Re: https_port Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-08 17:00 +0200
                Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 17:20 +0200
                Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:30 +0200
                Re: https_port Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-08 17:40 +0200
                Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:50 +0200
                Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 18:00 +0200
                Re: https_port Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-08 19:10 +0200
                Re: https_port Charlie Kravetz <cjk@teamcharliesangels.com> - 2017-06-09 16:40 +0200
                Reply-to-all or reply-to-list again (was: https_port) Nicolas George <george@nsup.org> - 2017-06-09 16:50 +0200
                Re: Reply-to-all or reply-to-list again (was: https_port) Fungi4All <fungilife@protonmail.com> - 2017-06-09 17:20 +0200
                Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 17:20 +0200
                Re: Reply-to-all or reply-to-list again Nicolas George <george@nsup.org> - 2017-06-09 18:00 +0200
                Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 21:20 +0200
                Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 04:20 +0200
                Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 16:00 +0200
                Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 16:30 +0200
                Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 18:00 +0200
                Re: Reply-to-all or reply-to-list again (was: https_port) Gene Heskett <gheskett@shentel.net> - 2017-06-09 17:30 +0200
          Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 16:10 +0200
    Re: NTP.conf   pool vs server John Hasler <jhasler@newsguy.com> - 2017-06-07 18:10 +0200
      Re: NTP.conf   pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-07 18:30 +0200
        Re: NTP.conf   pool vs server David Wright <deblis@lionunicorn.co.uk> - 2017-06-11 18:00 +0200
          Re: NTP.conf   pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-11 19:30 +0200
      Re: NTP.conf   pool vs server Teemu Likonen <tlikonen@iki.fi> - 2017-06-08 08:40 +0200
        Re: NTP.conf   pool vs server Curt <curty@free.fr> - 2017-06-08 09:20 +0200
        Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 15:40 +0200
    Re: NTP.conf   pool vs server Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-07 18:40 +0200
  Re: NTP.conf   pool vs server Kushal Kumaran <kushal@locationd.net> - 2017-06-07 17:00 +0200

csiph-web