gpt4 book ai didi

ubuntu - 鱿鱼 3.5 https 设置 ubuntu 16.04

转载 作者:太空宇宙 更新时间:2023-11-03 13:33:56 27 4
gpt4 key购买 nike

我想知道是否有人能够帮助我解决鱿鱼问题。我正在尝试在 ubuntu 16.04 上设置 squid。我使用 apt-get install 来安装它。我有 3.5 版。

我似乎无法让 https 端正常工作。我只有一台服务器,只有一个网卡。我已经设置了 ip 表规则,如果我去掉 ssl 的东西,我可以让端口 80 的东西正常工作......

我的 Iptables 规则是:

iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 3129
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 3130

我似乎无法解决的错误是:

    systemctl status squid
● squid.service - LSB: Squid HTTP Proxy version 3.x
Loaded: loaded (/etc/init.d/squid; bad; vendor preset: enabled)
Active: active (exited) since Wed 2017-09-06 15:24:58 UTC; 3s ago
Docs: man:systemd-sysv-generator(8)
Process: 31100 ExecStop=/etc/init.d/squid stop (code=exited, status=0/SUCCESS)
Process: 31116 ExecStart=/etc/init.d/squid start (code=exited, status=0/SUCCESS)

Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: 2017/09/06 15:24:58| WARNING: You should probably remove '10.10.8.0/24' from the ACL
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: 2017/09/06 15:24:58| FATAL: Invalid ACL type 'ssl::server_name'
Sep 06 15:24:58 ip-10-10-0-184 squid[31158]: Bungled /etc/squid/squid.conf line 73: acl allowed_https_sites ssl::server_name .ubu
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: FATAL: Bungled /etc/squid/squid.conf line 73: acl allowed_https_sites ssl::server_na
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: Squid Cache (Version 3.5.12): Terminated abnormally.
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: CPU Usage: 0.004 seconds = 0.004 user + 0.000 sys
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: Maximum Resident Size: 46928 KB
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: Page faults with physical i/o: 0
Sep 06 15:24:58 ip-10-10-0-184 squid[31116]: ...fail!
Sep 06 15:24:58 ip-10-10-0-184 systemd[1]: Started LSB: Squid HTTP Proxy version 3.x.

conf 文件如下所示:

    #Anonomize proxi connections

forwarded_for off
request_header_access Allow allow all
request_header_access Authorization allow all
request_header_access WWW-Authenticate allow all
request_header_access Proxy-Authorization allow all
request_header_access Proxy-Authenticate allow all
request_header_access Cache-Control allow all
request_header_access Content-Encoding allow all
request_header_access Content-Length allow all
request_header_access Content-Type allow all
request_header_access Date allow all
request_header_access Expires allow all
request_header_access Host allow all
request_header_access If-Modified-Since allow all
request_header_access Last-Modified allow all
request_header_access Location allow all
request_header_access Pragma allow all
request_header_access Accept allow all
request_header_access Accept-Charset allow all
request_header_access Accept-Encoding allow all
request_header_access Accept-Language allow all
request_header_access Content-Language allow all
request_header_access Mime-Version allow all
request_header_access Retry-After allow all
request_header_access Title allow all
request_header_access Connection allow all
request_header_access Proxy-Connection allow all
request_header_access User-Agent allow all
request_header_access Cookie allow all
request_header_access All deny all

visible_hostname gw.fairsquare.com

#ACL definitions
acl localnet src 0.0.0.1-0.255.255.255 # RFC 1122 'this' network (LAN)
acl localnet src 10.0.0.0/8 # RFC 1918 local private network (LAN)
acl localnet src 100.64.0.0/10 # RFC 6598 shared address space (CGN)
acl localhet src 169.254.0.0/16 # RFC 3927 link-local (directly plugged) machines
acl localnet src 10.10.5.0/24 # RFC 1918 local private network (LAN)
acl localnet src 10.10.6.0/24 # RFC 1918 local private network (LAN)
acl localnet src 10.10.7.0/24 # RFC 1918 local private network (LAN)
acl localnet src 10.10.8.0/24 # RFC 1918 local private network (LAN)
acl localnet src fc00::/7 # RFC 4193 local private network range
acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines

acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT

http_access allow localnet
http_access allow Safe_ports

refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320

#Handling HTTPS requests
https_port 3130 cert=/etc/squid/ssl/squid.pem ssl-bump intercept
acl SSL_port port 443
http_access allow SSL_port
acl allowed_https_sites ssl::server_name .ubuntu.com
acl allowed_https_sites ssl::server_name .amazon.com
#acl allowed_https_sites ssl::server_name [you can add other domains to permit]
acl step1 at_step SslBump1
acl step2 at_step SslBump2
acl step3 at_step SslBump3
ssl_bump peek step1 all
ssl_bump peek step2 allowed_https_sites
ssl_bump splice step3 allowed_https_sites
ssl_bump terminate step2 all

#Handling HTTP requests
http_port 3129 intercept
acl allowed_http_sites dstdomain .amazonaws.com
acl allowed_http_sites dstdomain .amazon.com
acl allowed_http_sites dstdomain .ubuntu.com
#acl allowed_http_sites dstdomain [you can add other domains to permit]
http_access allow allowed_http_sites

via off
forwarded_for off
http_access deny all

我试图找到我拼凑在一起的配置示例...只是想要一个访问列表以允许 ssl 站点退出。

有人可以指出我的错误吗,因为我不确定这个 ssl 名称有什么问题......

感谢您的帮助!

最佳答案

打开你的文件:

nano /etc/squid3/squid.conf

键入 Ctrl + w,然后键入“server_name”并将 server_name 替换为您的服务器名称。

acl allowed_https_sites ssl::**server_name** .ubuntu.com
acl allowed_https_sites ssl::**server_name** .amazon.com

我不知道为什么,但是网络 10.10.8.0/24 也有问题,所以,如果您不使用它,您应该从中删除 10.10.8.0/24 ACL列表。

关于ubuntu - 鱿鱼 3.5 https 设置 ubuntu 16.04,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/46079288/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com