You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置带Let's Encrypt证书的Squid通用HTTPS正向代理

Alright, let's get your public HTTPS forward Squid proxy configured properly—covering SSL termination with your Let's Encrypt cert, local subnet blocking, and validation checks to make sure everything works as expected.

1. Verify OpenSSL Support is Enabled

First, let's confirm your Squid instance actually has OpenSSL support active (since just adding --with-openssl to the init script might not be enough if the binary wasn't compiled with it). Run this command:

squid -v

Look for --with-openssl in the output under "configure options". If it's missing, you'll need to either:

  • Install the SSL-enabled package for your distro (e.g., squid-openssl on Debian/Ubuntu), or
  • Recompile Squid from source with the --with-openssl flag properly set during the configure step.
2. Set Up Let's Encrypt Certificates for SSL Bumping

Since you're running an HTTPS forward proxy, you need Squid to handle SSL termination for client connections. Here's how to configure that:

  1. Copy your Let's Encrypt certificates to a Squid-accessible directory (create it if needed):
    sudo mkdir -p /etc/squid/ssl
    sudo cp /etc/letsencrypt/live/proxy.mydomain.com/fullchain.pem /etc/squid/ssl/
    sudo cp /etc/letsencrypt/live/proxy.mydomain.com/privkey.pem /etc/squid/ssl/
    sudo chown -R proxy:proxy /etc/squid/ssl
    sudo chmod 600 /etc/squid/ssl/privkey.pem
    
  2. Edit your Squid config file (usually /etc/squid/squid.conf) to enable SSL bumping and reference the certs:
    # Enable HTTPS proxy listening on port 3128 (standard proxy port)
    http_port 3128 ssl-bump \
      cert=/etc/squid/ssl/fullchain.pem \
      key=/etc/squid/ssl/privkey.pem \
      generate-host-certificates=on \
      dynamic_cert_mem_cache_size=4MB
    
    # Configure SSL bump rules for forward proxy
    ssl_bump server-first all
    sslproxy_cert_error allow all
    
    The ssl_bump server-first setting lets Squid handle the SSL handshake between client and target server, which is necessary for a forward HTTPS proxy.
3. Block Access to Your Local Subnet

To prevent proxy users from accessing your internal network, add these rules to squid.conf (replace 192.168.1.0/24 with your actual local subnet CIDR):

# Define your local subnet as an ACL
acl local_subnet src 192.168.1.0/24

# Deny access to the local subnet BEFORE allowing general access
http_access deny local_subnet

Important: Squid processes http_access rules in order, so make sure this deny rule comes before any allow all rule.

4. Configure Public Access & Basic Proxy Settings

Add these final config lines to allow public access and set up basic proxy behavior:

# Allow all other requests (from public internet users)
http_access allow all

# Set the visible hostname to match your proxy domain
visible_hostname proxy.mydomain.com

# Disable caching if you don't want to store cached content (optional but common for forward proxies)
cache deny all
5. Test & Activate the Configuration
  1. First, check for config syntax errors:
    squid -k parse
    
    If you see no errors, proceed.
  2. Restart Squid to apply changes:
    sudo service squid restart
    
  3. Verify the service is running:
    sudo service squid status
    
  4. Test the proxy from an external machine:
    # Test accessing a public website through the proxy
    curl -x https://proxy.mydomain.com:3128 https://example.com
    
    # Test accessing your local subnet (should return a 403 Forbidden)
    curl -x https://proxy.mydomain.com:3128 http://192.168.1.1
    
  5. Don't forget to open the proxy port in your firewall (e.g., for UFW):
    sudo ufw allow 3128/tcp
    

A quick heads-up: Running a public forward proxy can attract abuse (like spam or malicious traffic). You might want to add additional security measures like authentication (Basic or Digest) or rate limiting later on, but that's beyond your initial request.

内容的提问来源于stack exchange,提问作者user631567

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:12:51