Re: [squid-users] URL filtering on HTTPS (transparently)

From: Leonardo Rodrigues Magalhães <leolistas_at_solutti.com.br>
Date: Wed, 13 Aug 2008 10:49:07 -0300

Niladri Mukherjee escreveu:
> We are doing the same by the following.
>
> 1. At squid.conf :
> acl Banned_URLs url_regex -i "/etc/squid/banned_urls.txt"
> http_access allow FullTime_DnlUpl !Banned_URLs
>
> 2. At The file /etc/squid/banned_urls.txt :
> www.xxxxx.com:443
>

    it wont simply work like that .....

    your rules would work if browsers were configured to use squid as
proxy. Ali asked how to TRANSPARENTLY filter https sites .... and squid
cannot simply transparently intercept https requests, as it would be a
man-in-the-middle sort-of attack.

-- 
	Atenciosamente / Sincerily,
	Leonardo Rodrigues
	Solutti Tecnologia
	http://www.solutti.com.br
	Minha armadilha de SPAM, NÃO mandem email
	gertrudes_at_solutti.com.br
	My SPAMTRAP, do not email it
Received on Wed Aug 13 2008 - 13:49:16 MDT

This archive was generated by hypermail 2.2.0 : Wed Aug 13 2008 - 12:00:03 MDT