download squid
http://www.squid-cache.org/Versions/v5/ ... a91.tar.gz
Dependences
Code: Select all
apt install devscripts build-essential openssl libssl-dev fakeroot libcppunit-dev libsasl2-dev cdbs ccze libfile-readbackwards-perl libcap2 libcap-dev libcap2-dev libnetfilter-conntrack-dev htop ccze sysv-rc-conf
configure
Code: Select all
./configure --x-includes=/usr/include --x-libraries=/usr/lib --with-default-user=proxy --with-logdir=/var/log/squid --with-pidfile=/var/run/squid.pid --enable-storeio=ufs,aufs,diskd --enable-linux-netfilter --enable-removal-policies=lru,heap --enable-gnuregex --enable-follow-x-forwarded-for --enable-x-accelerator-vary --enable-zph-qos --enable-delay-pools --enable-snmp --enable-underscores --with-openssl --enable-ssl-crtd --enable-http-violations --enable-async-io=24 --enable-storeid-rewrite-helpers --with-large-files --with-libcap --with-netfilter-conntrack --with-included-ltdl --with-maxfd=65536 --with-filedescriptors=65536 --with-pthreads --without-gnutls --without-mit-krb5 --without-heimdal-krb5 --without-gnugss --disable-icap-client --disable-wccp --disable-wccpv2 --disable-dependency-tracking --disable-auth --disable-epoll --disable-ident-lookups --disable-icmp
compile
make all
instala
make install
make selfsigned certificate
Code: Select all
openssl req -new -newkey rsa:4096 -sha256 -days 3654 -nodes -x509 -keyout myCA.key -out myCA.pem
openssl x509 -in myCA.pem -outform DER -out myCA.der
create a carpet to create and intechange of certificates
Code: Select all
/usr/local/squid/libexec/security_file_certgen -c -s /usr/local/squid/cert -M4MB
squid´configuration
Code: Select all
acl localnet all
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
never_direct allow all
always_direct allow all
# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager
http_access allow localnet
http_access allow localhost
debug_options ALL,2
visible_hostname proxy.three.metal.heart.darknet.b.mad
# for clients with a configured proxy. con tls un solo puerto para todo
http_port 3127 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/ssl/myCA.pem
# for clients who are sent here via iptables ... REDIRECT.
http_port 3128 intercept
# for https clients who are sent here via iptables ... REDIRECT
https_port 3129 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/ssl/myCA.pem
sslcrtd_program /usr/local/squid/libexec/security_file_certgen -s /usr/local/squid/cert -M 4MB sslcrtd_children 8 startup=1 idle=1
ssl_bump server-first all
sslproxy_cert_error allow all
cache_dir ufs /var/spool/squid 200 16 256
coredump_dir /var/cache/squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
/usr/local/squid/sbin/squid -z
and running squid
/usr/local/squid/sbin/squid
ip talbles redirection
Code: Select all
iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 3128
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 3129
to visit web vith secure conexion https:// you must instal the client certificae
like certefied authority rename myCA.der a myCA.crt . too myCA.cer
to firefox y Android runnin myCA.crt automatic (be carefull in android pass and myCA.cer rn in windows
installl the certificate .crt you can dowload an run automatic, do not forget put on the box
of certificacion web. y and charge in theshop of certificados
operera and crome do it by hand
Sysop