Proxy - ssl_exclude_ips.conf (lab)
Proxy Solution · Config document · referenced from Squid with SSL interception
8.8.8.8 is a public resolver, not a server the lab had to reach; it looks like an example entry, and the notes do not say why it is there. The production list is not in the notes.The list of destination addresses that Squid must not intercept. The ssl_exclude_ips ACL in squid.conf reads it with dst, and the rule ssl_bump splice ssl_exclude_ips turns every connection to a listed address into a plain tunnel. It is the second exclusion, after ssl_exclude_domains.conf, for destinations a client names by address rather than by name.
| Item | Value |
|---|---|
| Path | /etc/squid/ssl_exclude_ips.conf |
| Host | proxy.lab.example.net, the lab VMware guest, RHEL 7.5 |
| Read by | acl ssl_exclude_ips dst "/etc/squid/ssl_exclude_ips.conf" |
| Format | one address or network per line, as the dst ACL takes them |
| Activated with | a Squid reload or restart; the notes record neither |
| Software version | Squid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version) |
The file
8.8.8.8
The entries
| Entry | Effect |
|---|---|
8.8.8.8 | a CONNECT to this address is spliced, never bumped |
A dst ACL matches the destination address of the request; when the client gave a host name, Squid resolves it to compare, which is my understanding of the ACL and not something the notes show. Where the list is evaluated matters: it comes after ssl_bump peek step1 all, so like the name list it is decided at step 2, although the destination address is already known at step 1 from the CONNECT request.
Checked against Squid 7.7
| As built | Today |
|---|---|
acl ssl_exclude_ips dst "<file>" | The dst ACL is unchanged; Squid 7 merges overlapping addresses and ranges in it |
| An address list as the second exclusion | The Squid wiki still warns that a destination matched before the connection is bumped may be known only as an address; the ssl::server_name ACL with --server-provided or --consensus, available since Squid 4, decides on the name the server proves with its certificate instead |
The file works as it is on Squid 7.7. Whether an address list is the right second exclusion is the question, not its syntax.