Re: [squid-users] https facebook dstdomain acl doesn't work

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Wed, 29 Feb 2012 17:26:18 +1300

On 29/02/2012 9:27 a.m., Muhammad Yousuf Khan wrote:
> Thanks,
>
> if i use squid as non transparent proxy would it work for HTTPS for
> just blocking a domain.

Yes. HTTPS tunnel CONNECT requests have a special type of URL, which
only contains deatinstion domain name and port. You can use the domain
name to block access in a forward proxy. Only the URL path and HTTP
header details are hidden inside the encryption.

Amos
Received on Wed Feb 29 2012 - 04:26:22 MST

This archive was generated by hypermail 2.2.0 : Wed Feb 29 2012 - 12:00:06 MST