配置带Let's Encrypt证书的Squid通用HTTPS正向代理
Alright, let's get your public HTTPS forward Squid proxy configured properly—covering SSL termination with your Let's Encrypt cert, local subnet blocking, and validation checks to make sure everything works as expected.
First, let's confirm your Squid instance actually has OpenSSL support active (since just adding --with-openssl to the init script might not be enough if the binary wasn't compiled with it). Run this command:
squid -v
Look for --with-openssl in the output under "configure options". If it's missing, you'll need to either:
- Install the SSL-enabled package for your distro (e.g.,
squid-opensslon Debian/Ubuntu), or - Recompile Squid from source with the
--with-opensslflag properly set during the configure step.
Since you're running an HTTPS forward proxy, you need Squid to handle SSL termination for client connections. Here's how to configure that:
- Copy your Let's Encrypt certificates to a Squid-accessible directory (create it if needed):
sudo mkdir -p /etc/squid/ssl sudo cp /etc/letsencrypt/live/proxy.mydomain.com/fullchain.pem /etc/squid/ssl/ sudo cp /etc/letsencrypt/live/proxy.mydomain.com/privkey.pem /etc/squid/ssl/ sudo chown -R proxy:proxy /etc/squid/ssl sudo chmod 600 /etc/squid/ssl/privkey.pem - Edit your Squid config file (usually
/etc/squid/squid.conf) to enable SSL bumping and reference the certs:
The# Enable HTTPS proxy listening on port 3128 (standard proxy port) http_port 3128 ssl-bump \ cert=/etc/squid/ssl/fullchain.pem \ key=/etc/squid/ssl/privkey.pem \ generate-host-certificates=on \ dynamic_cert_mem_cache_size=4MB # Configure SSL bump rules for forward proxy ssl_bump server-first all sslproxy_cert_error allow allssl_bump server-firstsetting lets Squid handle the SSL handshake between client and target server, which is necessary for a forward HTTPS proxy.
To prevent proxy users from accessing your internal network, add these rules to squid.conf (replace 192.168.1.0/24 with your actual local subnet CIDR):
# Define your local subnet as an ACL acl local_subnet src 192.168.1.0/24 # Deny access to the local subnet BEFORE allowing general access http_access deny local_subnet
Important: Squid processes http_access rules in order, so make sure this deny rule comes before any allow all rule.
Add these final config lines to allow public access and set up basic proxy behavior:
# Allow all other requests (from public internet users) http_access allow all # Set the visible hostname to match your proxy domain visible_hostname proxy.mydomain.com # Disable caching if you don't want to store cached content (optional but common for forward proxies) cache deny all
- First, check for config syntax errors:
If you see no errors, proceed.squid -k parse - Restart Squid to apply changes:
sudo service squid restart - Verify the service is running:
sudo service squid status - Test the proxy from an external machine:
# Test accessing a public website through the proxy curl -x https://proxy.mydomain.com:3128 https://example.com # Test accessing your local subnet (should return a 403 Forbidden) curl -x https://proxy.mydomain.com:3128 http://192.168.1.1 - Don't forget to open the proxy port in your firewall (e.g., for UFW):
sudo ufw allow 3128/tcp
A quick heads-up: Running a public forward proxy can attract abuse (like spam or malicious traffic). You might want to add additional security measures like authentication (Basic or Digest) or rate limiting later on, but that's beyond your initial request.
内容的提问来源于stack exchange,提问作者user631567

