http_port 3128
http_port 3127 intercept
https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_certs/squid.crt key=/etc/squid/ssl_certs/squid.key cipher=ECDHE-RSA-RC4-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:DHE-RSA-CAMELLIA128-SHA:AES128-SHA:RC4-SHA:HIGH:!aNULL:!MD5:!ADH
always_direct allow all
sslproxy_cert_error allow all
sslproxy_flags DONT_VERIFY_PEER
acl blocked ssl::server_name "/etc/squid/blocked_https.txt"
acl step1 at_step SslBump1
ssl_bump peek step1
ssl_bump terminate blocked
ssl_bump splice all
sslcrtd_program /usr/lib/squid/ssl_crtd -s /var/lib/squid/ssl_db -M 4MB
sslcrtd_children 16 startup=1 idle=1
sslproxy_capath /etc/ssl/certs
sslproxy_cert_error allow all
ssl_unclean_shutdown on
Its not blocking anything.
1463478184.338 182900 192.168.0.66 TAG_NONE/200 0 CONNECT
106.10.137.175:443 - HIER_NONE/- -
1463478209.166 240232 192.168.0.66 TAG_NONE/200 0 CONNECT
74.125.200.239:443 - HIER_NONE/- -
1463478209.200 240267 192.168.0.66 TAG_NONE/200 0 CONNECT
216.58.199.142:443 - HIER_NONE/- -
1463478213.443 181611 192.168.0.66 TAG_NONE/200 0 CONNECT
31.13.79.246:443 - HIER_NONE/- -
1463478246.369 13073 192.168.0.66 TAG_NONE/200 0 CONNECT
74.125.200.189:443 - HIER_NONE/- -
1463478246.369 13806 192.168.0.66 TAG_NONE/200 0 CONNECT
216.58.199.142:443 - HIER_NONE/- -
1463478265.935 119576 192.168.0.66 TAG_NONE/200 0 CONNECT
106.10.199.11:443 - HIER_NONE/- -