A simple squid server deployed with SSL support to SslBump Peek and Splice with LDAP authentication
964
Based on CentOS latest and SQUID. Currently, CentOS8 and SQUID 4
I've written this to enable some of the teams to get access to our app's UIs on AWS. We needed to allow only authenticated users to get access, and only to some URL. These URLs are published in HTTPS, so I needed to read the destination and block it if not part of the deployment
The easiest way to achieve this was docker.
Clone https://github.com/nnsense/docker-squid_ssl_ldap.
Create a directory for squid config files (ie /mnt/squid) and copy the squid.conf file, the ldap_password file and the wl_allowed file.
The first one is obviously the squid configuration. The second, is the password for LDAP bind (the user is specified while creating the docker), the third is a regex list of allowed sites.
Change the LDAP details into the squid.conf file.
Add the bind user's password into /mnt/squid/ldap_password
Add the squid.conf file into /mnt/squid/squid.conf.
Add the wl_allowed file into /mnt/squid/wl_allowed and add your allowed URL list.
docker build -t squid-ssl .docker run --restart="always" -d --name squid -p 8443:3128 -v /mnt/squid/wl_allowed:/etc/squid/wl_allowed -v /mnt/squid/squid.conf:/etc/squid/squid.conf -v /mnt/squid/ldap_password:/etc/squid/ldap_password squid-ssldocker run --restart="always" -d --name squid -p 8443:3128 -v /mnt/squid/wl_allowed:/etc/squid/wl_allowed -v /mnt/squid/squid.conf:/etc/squid/squid.conf -v /mnt/squid/ldap_password:/etc/squid/ldap_password nnsense/squid_ssl_ldap
Note:
/etc/squid into /mnt/squid/ and then mount /mnt/squid/ to /etc/squid. Up to you.Content type
Image
Digest
Size
113.7 MB
Last updated
almost 6 years ago
docker pull nnsense/squid_ssl_ldap