Spam detection software, running on the system "master.squid-cache.org",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Hi list. I have a pretty simple configuration for website
filtering (intercepted) and ssl_bump, which follows below. However, for some
reason, it seems Squid resolves the website domain address, then uses the
[...]
Content analysis details: (5.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
3.6 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[171.171.0.1 listed in zen.spamhaus.org]
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 NORMAL_HTTP_TO_IP URI: URI host has a public dotted-decimal IPv4
address
0.0 NUMERIC_HTTP_ADDR URI: Uses a numeric IP address in URL
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 UNPARSEABLE_RELAY Informational: message has unparseable relay
lines
-0.0 T_SCC_BODY_TEXT_LINE No description available.
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
--- Begin Message ---
- Subject: Squid also checking for IP on ACL
- From: <bruno.larini@xxxxxxxxxxxxxx>
- Date: Mon, 27 Jun 2022 19:01:25 -0300
Hi list.
I have a pretty simple configuration for website filtering (intercepted) and ssl_bump, which follows below.
However, for some reason, it seems Squid resolves the website domain address, then uses the IP to compare with the ACLs.
As the IP is not included in the ACL, the access to the website is denied.
Before that, it already checked for the domain name. I can tell based on the error from the browser.
I'm using Squid version 5.5.
For example, while trying to open https://repo.maven.apache.org/ (included in the allowed sites), the browser shows the error:
The following error was encountered while trying to retrieve the URL: https://199.232.192.215/*
Access Denied.
If I replace 'deny all' with 'allow all', the website will open as expected.
Is there something wrong with my config? I have something similar running and working on version 4.4 (unless I'm missing something).
I'm still only splicing for now.
Thanks for the help!
### SQUID.CONF
...
#
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#
acl allowed_sites dstdomain "/etc/squid/allowed-sites.txt"
http_access allow allowed_sites
acl step1 at_step SslBump1
ssl_bump peek step1
ssl_bump splice all
tls_outgoing_options capath=/etc/pki/tls/certs options=ALL
sslcrtd_program /usr/lib64/squid/security_file_certgen -s /var/lib/squid/ssl_db -M 8MB
sslcrtd_children 3
http_access allow localhost
# And finally deny all other access to this proxy
http_access deny all
# Squid normally listens to port 3128
http_port 192.168.10.10:8080
http_port 192.168.10.10:3128 intercept
https_port 192.168.10.10:3129 tls-cert=/etc/squid/ssl/squidCA.pem tls-key=/etc/squid/ssl/squidCA.key ssl-bump intercept generate-host-certificates=on dynamic_cert_mem_cache_size=8MB
...
### IPTABLES
...
iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.0/24 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.0/24 -p tcp --dport 443 -j REDIRECT --to-port 3129
...
--- End Message ---
_______________________________________________
squid-users mailing list
squid-users@xxxxxxxxxxxxxxxxxxxxx
http://lists.squid-cache.org/listinfo/squid-users