LINUXOR.SK ... open source notes ...

Proxy - ssl_exclude_ips.conf (lab)

category: solutionz · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Squid with SSL interception

note8.8.8.8 is a public resolver, not a server the lab had to reach; it looks like an example entry, and the notes do not say why it is there. The production list is not in the notes.

The list of destination addresses that Squid must not intercept. The ssl_exclude_ips ACL in squid.conf reads it with dst, and the rule ssl_bump splice ssl_exclude_ips turns every connection to a listed address into a plain tunnel. It is the second exclusion, after ssl_exclude_domains.conf, for destinations a client names by address rather than by name.

ItemValue
Path/etc/squid/ssl_exclude_ips.conf
Hostproxy.lab.example.net, the lab VMware guest, RHEL 7.5
Read byacl ssl_exclude_ips dst "/etc/squid/ssl_exclude_ips.conf"
Formatone address or network per line, as the dst ACL takes them
Activated witha Squid reload or restart; the notes record neither
Software versionSquid 3.5 (the RHEL 7.5 package, squid-3.5.20-12.el7; the notes print no version)

The file

ini
8.8.8.8

The entries

EntryEffect
8.8.8.8a CONNECT to this address is spliced, never bumped

A dst ACL matches the destination address of the request; when the client gave a host name, Squid resolves it to compare, which is my understanding of the ACL and not something the notes show. Where the list is evaluated matters: it comes after ssl_bump peek step1 all, so like the name list it is decided at step 2, although the destination address is already known at step 1 from the CONNECT request.

Checked against Squid 7.7

As builtToday
acl ssl_exclude_ips dst "<file>"The dst ACL is unchanged; Squid 7 merges overlapping addresses and ranges in it
An address list as the second exclusionThe Squid wiki still warns that a destination matched before the connection is bumped may be known only as an address; the ssl::server_name ACL with --server-provided or --consensus, available since Squid 4, decides on the name the server proves with its certificate instead

The file works as it is on Squid 7.7. Whether an address list is the right second exclusion is the question, not its syntax.

← solutionz