Squid ‚Ì SSL Bump ‚ªŽÀÛ‚É“®ì‚µ‚Ä‚¢‚é‚©‚Ç‚¤‚©‚ðŠm”F‚·‚é•û–@
(ƒJƒXƒ^ƒ€ CA ‚ªƒCƒ“ƒXƒg[ƒ‹‚³‚ê‚Ä‚¢‚È‚¢ƒNƒŠ[ƒ“‚È Windows ƒNƒ‰ƒCƒAƒ“ƒg‚ð—á‚Éà–¾‚µ‚Ü‚·)
Chrome/Edge ‚Å‚±‚̃Gƒ‰[‚ª•\ަ‚³‚ê‚é‚̂͂Ȃº‚Å‚·‚©H
net::ERR_CERT_AUTHORITY_INVALID
‚±‚̃Gƒ‰[‚ÍAˆÈ‰º‚Ì󋵂ł̂ݔ¶‚µ‚Ü‚·B
ƒuƒ‰ƒEƒU‚ªÄ–¼‚³‚ꂽ HTTPS Ø–¾‘‚ðŽó‚¯Žæ‚Á‚½‚à‚Ì‚ÌA‚»‚ê‚ð”s‚µ‚½ CA ‚ðM—Š‚µ‚Ä‚¢‚È‚¢ê‡B
⚠️ d—vŽ–€ (”ñí‚Éd—v)
SSL Bump ‚ª—LŒø‚ɂȂÁ‚Ä‚¢‚È‚¢ê‡A
‚±‚̃Gƒ‰[‚Í”¶‚µ‚Ü‚¹‚ñB
——R‚ÍŠÈ’P‚Å‚·B
SSL Bump ‚ª—LŒø‚ɂȂÁ‚Ä‚¢‚È‚¢ê‡
¨ ƒuƒ‰ƒEƒU‚ÍŒ³‚̃EƒFƒuƒTƒCƒg (Google/Microsoft ‚È‚Ç) ‚©‚ç‚ÌŒöŽ®Ø–¾‘‚݂̂ðŽQÆ‚µ‚Ü‚·B
¨ —ÎF‚̓싞ùƒAƒCƒRƒ“‚݂̂ª•\ަ‚³‚ê‚Ü‚·B
¨ ERR_CERT_AUTHORITY_INVALID ‚Í•\ަ‚³‚ê‚Ü‚¹‚ñB
👉 ‚µ‚½‚ª‚Á‚ÄA‚±‚̃Gƒ‰[Ž©‘Ì‚ªA
SSL Bump ‚ªŽÀÛ‚É HTTPS ‚ðŽÀ‘•‚µ‚Ä‚¢‚邱‚Ƃ̒¼Ú“I‚ÈØ‹’‚ƂȂè‚Ü‚·B
^‚ÌuŠmŒÅ‚½‚騋’v‚͂ǂ±‚É‚ ‚é‚̂łµ‚傤‚©H
‹C‚¢‚Ä‚¢‚È‚¢‚©‚à‚µ‚ê‚Ü‚¹‚ñ‚ªAˆÈ‰º‚Ìs‚ÍuŠK‘w\‘¢v‚Ì•´‚ê‚à‚È‚¢Ø‹’‚Å‚·B
Via: ICAP/1.0 YourServerName (C-ICAP/0.5.12 srv_content_filtering service), 1.1 No1.f88tw (squid/6.12)
‚È‚º‚±‚Ìs‚ÍHTTPS‚É‚¨‚¢‚Ä‚»‚ê‚Ù‚Çd—v‚Ȃ̂łµ‚傤‚©H
’Êí‚ÌHTTPS‚Ì“®ì‚Å‚ÍAˆÈ‰º‚̂悤‚ɂȂè‚Ü‚·B
CONNECTƒgƒ“ƒlƒ‹‚ªŠm—§‚³‚ꂽŒãA
Squid‚ÍHTTPƒwƒbƒ_[‚ð”Fޝ‚Å‚«‚Ü‚¹‚ñB
c-icap‚͌ĂÑo‚³‚ê‚Ü‚¹‚ñB
‚‚܂èAˆÈ‰º‚̂悤‚ɂȂè‚Ü‚·B
SSLƒoƒ“ƒv‚Í”¶‚µ‚Ü‚¹‚ñB
¨ HTTPS‚̓vƒƒLƒV‚ɂƂÁ‚ĈƉ»‚³‚ꂽƒuƒ‰ƒbƒNƒ{ƒbƒNƒX‚Å‚·B
👉 ‚µ‚©‚µA¡‰½‚ªŒ©‚¦‚Ü‚·‚©H
HTTPSƒŒƒXƒ|ƒ“ƒXƒwƒbƒ_[‚Í
uICAPƒT[ƒrƒXŒo—Rv‚Æ’¼Úަ‚µ‚Ä‚¨‚èA
Squid‚Æc-icap‚̃o[ƒWƒ‡ƒ“‚Æ–ðŠ„‚ðŽ¦‚µ‚Ä‚¢‚Ü‚·B
‚±‚ê‚̓A[ƒLƒeƒNƒ`ƒƒ“I‚ÉŽŸ‚Ì‚±‚Æ‚ðˆÓ–¡‚µ‚Ü‚·B
🧠 Squid‚ªSSLƒoƒ“ƒv‚ðŠ®—¹‚µ‚Ü‚µ‚½B
¨ HTTPS‚𕜆‚µ‚Ü‚µ‚½B
¨ ƒRƒ“ƒeƒ“ƒc‚ðc-icap‚É‘—M‚µ‚Ü‚µ‚½B
¨ ĈƉ»‚³‚êAƒNƒ‰ƒCƒAƒ“ƒg‚É‘—‚è•Ô‚³‚ê‚Ü‚µ‚½B¿¦ŽŽV“IŒ×•½‘ä PowerShell https://aka.ms/pscore6
PS C:\Users\c05> curl.exe https://www.baidu.com --proxy http://192.168.0.88:3128 -k -v
* Trying 192.168.0.88:3128...
* Connected to 192.168.0.88 (192.168.0.88) port 3128
* CONNECT tunnel: HTTP/1.1 negotiated
* allocate connect buffer
* Establish HTTP proxy tunnel to www.baidu.com:443
> CONNECT www.baidu.com:443 HTTP/1.1
> Host: www.baidu.com:443
> User-Agent: curl/8.9.1
> Proxy-Connection: Keep-Alive
>
< HTTP/1.1 200 Connection established
<
* CONNECT phase completed
* CONNECT tunnel established, response 200
* schannel: disabled automatic use of client certificate
* ALPN: curl offers http/1.1
* ALPN: server did not agree on a protocol. Uses default.
* using HTTP/1.x
> GET / HTTP/1.1
> Host: www.baidu.com
> User-Agent: curl/8.9.1
> Accept: */*
>
* Request completely sent off
< HTTP/1.1 200 OK
< Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
< Content-Length: 2443
< Content-Type: text/html
< Pragma: no-cache
< Server: bfe
< Set-Cookie: BDORZ=27315; max-age=86400; domain=.baidu.com; path=/
< Date: Fri, 30 Jan 2026 08:44:48 GMT
< Via: ICAP/1.0 YourServerName (C-ICAP/0.5.12 srv_content_filtering service ), 1.1 No1.proxy (squid/6.12)
< Cache-Status: No1.proxy;fwd=miss;detail=match
< Connection: keep-alive
<
<!DOCTYPE html>
<!--STATUS OK--><html> <head><meta http-equiv=content-type content=text/html;charset=utf-8><meta http-equiv=X-UA-Compatible content=IE=Edge><meta content=always name=referrer><link rel=stylesheet type=text/css href=https://ss1.bdstatic.com/5eN1bjq8AAUYm2zgoY3K/r/www/cache/bdorz/baidu.min.css><title>•S“xˆê‰ºC你A’m“¹</title></head> <body link=#0000cc> <div id=wrapper> <div id=head> <div class=head_wrapper> <div class=s_form> <div class=s_form_wrapper> <div id=lg> <img hidefocus=true src=//www.baidu.com/img/bd_logo1.png width=270 height=129> </div> <form id=form name=f action=//www.baidu.com/s class=fm> <input type=hidden name=bdorz_come value=1> <input type=hidden name=ie value=utf-8> <input type=hidden name=f value=8> <input type=hidden name=rsv_bp value=1> <input type=hidden name=rsv_idx value=1> <input type=hidden name=tn value=baidu><span class="bg s_ipt_wr"><input id=kw name=wd class=s_ipt value maxlength=255 autocomplete=off autofocus=autofocus></span><span class="bg s_btn_wr"><input type=submit id=su value=•S“xˆê‰º class="bg s_btn" autofocus></span> </form> </div> </div> <div id=u1> <a href=http://news.baidu.com name=tj_trnews class=mnav>V闻</a> <a href=https://www.hao123.com name=tj_trhao123 class=mnav>hao123</a> <a href=http://map.baidu.com name=tj_trmap class=mnav>’n图</a> <a href=http://v.baidu.com name=tj_trvideo class=mnav>视频</a> <a href=http://tieba.baidu.com name=tj_trtieba class=mnav>贴吧</a> <noscript> <a href=http://www.baidu.com/bdorz/login.gif?login&tpl=mn&u=http%3A%2F%2Fwww.baidu.com%2f%3fbdorz_come%3d1 name=tj_login class=lb>“o录</a> </noscript> <script>document.write('<a href="http://www.baidu.com/bdorz/login.gif?login&tpl=mn&u='+ encodeURIComponent(window.location.href+ (window.location.search === "" ? "?" : "&")+ "bdorz_come=1")+ '" name="tj_login" class="lb">“o录</a>');
</script> <a href=//www.baidu.com/more/ name=tj_briicon class=bri style="display: block;">X‘½产•i</a> </div> </div> </div> <div id=ftCon> <div id=ftConw> <p id=lh> <a href=http://home.baidu.com>关˜°•S“x</a> <a href=http://ir.baidu.com>About Baidu</a> </p> <p id=cp>©2017 Baidu <a href=http://www.baidu.com/duty/>Žg—p•S“x‘O•K读</a> <a href=http://jianyi.baidu.com/ class=cp-feedback>ˆÓ见”½馈</a> ‹žICP证030173† <img src=//www.baidu.com/img/gs.gif> </p> </div> </div> </div> </body> </html>
* Connection #0 to host 192.168.0.88 left intact
PS C:\Users\c05>
http://mypaper.m.pchome.com.tw/f88tw/post/1370820447