Squid 5 transparantmode running over absooland

Post Reply
sysop
Site Admin
Posts: 10
Joined: Wed Nov 26, 2025 10:42 pm

Squid 5 transparantmode running over absooland

Post by sysop »

Squid 5 transparet mode self-signed certificateand running


download squid

http://www.squid-cache.org/Versions/v5/ ... a91.tar.gz

Dependences


Code: Select all

apt install devscripts build-essential openssl libssl-dev fakeroot libcppunit-dev libsasl2-dev cdbs ccze libfile-readbackwards-perl libcap2 libcap-dev libcap2-dev libnetfilter-conntrack-dev htop ccze sysv-rc-conf 
cd /opt/squid-5
configure

Code: Select all

./configure --x-includes=/usr/include --x-libraries=/usr/lib --with-default-user=proxy --with-logdir=/var/log/squid --with-pidfile=/var/run/squid.pid --enable-storeio=ufs,aufs,diskd --enable-linux-netfilter --enable-removal-policies=lru,heap --enable-gnuregex --enable-follow-x-forwarded-for --enable-x-accelerator-vary --enable-zph-qos --enable-delay-pools --enable-snmp --enable-underscores --with-openssl --enable-ssl-crtd --enable-http-violations --enable-async-io=24 --enable-storeid-rewrite-helpers --with-large-files --with-libcap --with-netfilter-conntrack --with-included-ltdl --with-maxfd=65536 --with-filedescriptors=65536 --with-pthreads --without-gnutls --without-mit-krb5 --without-heimdal-krb5 --without-gnugss --disable-icap-client --disable-wccp --disable-wccpv2 --disable-dependency-tracking --disable-auth --disable-epoll --disable-ident-lookups --disable-icmp

compile


make all

instala

make install


make selfsigned certificate

Code: Select all

openssl req -new -newkey rsa:4096 -sha256 -days 3654 -nodes -x509 -keyout myCA.key  -out myCA.pem
openssl x509 -in myCA.pem -outform DER -out myCA.der
Configuration of squid



create a carpet to create and intechange of certificates

Code: Select all

/usr/local/squid/libexec/security_file_certgen -c -s /usr/local/squid/cert -M4MB

squid´configuration

Code: Select all


acl localnet all

acl SSL_ports port 443
acl Safe_ports port 80          # http
acl Safe_ports port 21          # ftp
acl Safe_ports port 443         # https
acl Safe_ports port 70          # gopher
acl Safe_ports port 210         # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280         # http-mgmt
acl Safe_ports port 488         # gss-http
acl Safe_ports port 591         # filemaker
acl Safe_ports port 777         # multiling http
acl CONNECT method CONNECT


never_direct allow all
always_direct allow all

# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager



http_access allow localnet 
http_access allow localhost

debug_options ALL,2

visible_hostname proxy.three.metal.heart.darknet.b.mad

# for clients with a configured proxy. con tls un solo puerto para todo
http_port 3127 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/ssl/myCA.pem
# for clients who are sent here via iptables ... REDIRECT.
http_port 3128 intercept
# for https clients who are sent here via iptables ... REDIRECT
https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/ssl/myCA.pem

sslcrtd_program /usr/local/squid/libexec/security_file_certgen -s /usr/local/squid/cert -M 4MB sslcrtd_children 8 startup=1 idle=1


ssl_bump server-first all
sslproxy_cert_error allow all
cache_dir ufs /var/spool/squid 200 16 256
coredump_dir /var/cache/squid

refresh_pattern ^ftp:           1440    20%     10080
refresh_pattern ^gopher:        1440    0%      1440
refresh_pattern -i (/cgi-bin/|\?) 0     0%      0
refresh_pattern .               0       20%     4320
genrate of cache

/usr/local/squid/sbin/squid -z

and running squid

/usr/local/squid/sbin/squid


ip talbles redirection

Code: Select all

 iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 3128
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 3129
and now install the client certificate

to visit web vith secure conexion https:// you must instal the client certificae
like certefied authority rename myCA.der a myCA.crt . too myCA.cer
to firefox y Android runnin myCA.crt automatic (be carefull in android pass and myCA.cer rn in windows
installl the certificate .crt you can dowload an run automatic, do not forget put on the box
of certificacion web. y and charge in theshop of certificados

operera and crome do it by hand


Sysop
Post Reply