Re: [squid-users] https interception some whitelisted sites not working properly

From: Eliezer Croitoru <eliezer_at_ngtech.co.il>
Date: Fri, 02 May 2014 00:55:03 +0300

Hey there,

This was asked in the past month twice if i'm not wrong.
In the stage when you use ssl_bump.. squid dosn't have any sense of
dstdomain.
Means that when squid bumps and knows the site name the connection is
already bumped and knows about it but when you want to apply a whitelist
squid only works on the IP level.
So instead use iptables and\or squid "dst" as a whitelist level.

Eliezer

On 05/02/2014 12:21 AM, Ikna Nou wrote:
> acl broken_sites dstdomain "/etc/squid3/acl/ssl_whitelist.acl"
Received on Thu May 01 2014 - 21:56:06 MDT

This archive was generated by hypermail 2.2.0 : Fri May 02 2014 - 12:00:03 MDT