Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
| netadmin:proxy:squid:filtrage_https [2025/11/17 22:01] – yoann | netadmin:proxy:squid:filtrage_https [2025/11/18 20:04] (Version actuelle) – [Exclusion du bumping-SSL] yoann | ||
|---|---|---|---|
| Ligne 45: | Ligne 45: | ||
| </ | </ | ||
| - | On peut maintenant créer | + | < |
| + | Pour ce cas d' | ||
| + | </ | ||
| + | |||
| + | On peut maintenant créer différentes versions du certificat racine | ||
| <code bash> | <code bash> | ||
| # Format DER (bianire) pour les machines Windows | # Format DER (bianire) pour les machines Windows | ||
| Ligne 67: | Ligne 72: | ||
| grep --invert-match -e ' | grep --invert-match -e ' | ||
| </ | </ | ||
| + | |||
| + | |||
| + | < | ||
| + | acl SSL_ports port 443 | ||
| + | |||
| + | acl Safe_ports port 80 # http | ||
| + | acl Safe_ports port 21 # ftp | ||
| + | acl Safe_ports port 443 # https | ||
| + | acl Safe_ports port 1025-65535 | ||
| + | |||
| + | acl purge method PURGE | ||
| + | acl CONNECT method CONNECT | ||
| + | |||
| + | http_access allow manager localhost | ||
| + | http_access deny manager | ||
| + | |||
| + | http_access allow purge localhost | ||
| + | http_access deny purge | ||
| + | |||
| + | http_access deny !Safe_ports | ||
| + | http_access deny CONNECT !SSL_ports | ||
| + | |||
| + | http_access allow localhost | ||
| + | http_access deny all | ||
| + | |||
| + | http_port 127.0.0.1: | ||
| + | ssl_bump bump all | ||
| + | |||
| + | coredump_dir / | ||
| + | logfile_rotate 0 | ||
| + | |||
| + | refresh_pattern -i (/ | ||
| + | refresh_pattern . | ||
| + | |||
| + | cache_dir ufs / | ||
| + | </ | ||
| + | |||
| + | |||
| + | Initialiser le repertoire de stockage des certificats SSL gérés par Squid | ||
| + | |||
| + | <code bash> | ||
| + | runuser -u proxy -- / | ||
| + | </ | ||
| + | |||
| + | <note warning> | ||
| + | Cette étape est nécessaire pour que Squid puisse démarrer sans erreur | ||
| + | </ | ||
| + | |||
| < | < | ||
| Ligne 95: | Ligne 148: | ||
| firewall-cmd --reload | firewall-cmd --reload | ||
| </ | </ | ||
| + | |||
| + | ===== Exclusion du bumping-SSL ===== | ||
| + | |||
| + | L' | ||
| + | |||
| + | :TODO: | ||
| + | |||
| + | sources : | ||
| + | * https:// | ||
| + | * https:// | ||
| + | |||
| + | |||
| + | ===== Dépannage ===== | ||
| + | |||
| + | Le service squid ne démarre pas normalement, | ||
| + | |||
| + | < | ||
| + | nov. 17 23:14:09 tethys (squid-1)[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1309]: | ||
| + | nov. 17 23:14:09 tethys squid[1310]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:09 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1311]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1313]: | ||
| + | nov. 17 23:14:10 tethys squid[1312]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1308]: | ||
| + | nov. 17 23:14:10 tethys squid[1270]: | ||
| + | nov. 17 23:14:10 tethys squid[1270]: | ||
| + | nov. 17 23:14:10 tethys squid[1270]: | ||
| + | nov. 17 23:14:10 tethys squid[1270]: | ||
| + | nov. 17 23:14:10 tethys systemd[1]: squid.service: | ||
| + | nov. 17 23:14:10 tethys systemd[1]: squid.service: | ||
| + | nov. 17 23:14:10 tethys systemd[1]: squid.service: | ||
| + | </ | ||
| + | |||
| + | Le message '' | ||
| ===== Références ===== | ===== Références ===== | ||
| Ligne 105: | Ligne 227: | ||
| * [[https:// | * [[https:// | ||
| * [[https:// | * [[https:// | ||
| + | * [[https:// | ||