Udah pada tau kan gaes, kalo (proxy) squid 3 bisa nge-cache protocol https...
itu mangkanya ane mau berbagi pengalaman sewaktu install squid3.
Sebelum membaca lebih lanjut, pastikan Ubuntu server 14.04 LTS kamu udah jalan dg baik & benar..
artinya udah bisa konek internet, dsb...
Kali ini squid yg ane pake versi squid-3.4.5
pertama intal dl lib yg dibutuhkan
#apt-get install build-essential libssl-dev
kmudian donlot source squid 3.4.5
#wget http://www.squid-cache.org/Versions/v3/3.4/squid-3.4.5.tar.gzextract..
#tar zxvf squid-3.4.5.tar.gzdiikuti langkah berikut
#cd squid-3.4.5
#./configure --prefix=/usr --bindir=/usr/bin --sbindir=/usr/sbin --libexecdir=/usr/lib/squid --sysconfdir=/etc/squid --localstatedir=/var --libdir=/usr/lib --includedir=/usr/include --datadir=/usr/share/squid --infodir=/usr/share/info --mandir=/usr/share/man --enable-default-err-language=English --disable-dependency-tracking --enable-storeio=ufs,aufs,diskd --enable-removal-policies=lru,heap --disable-linux-netfilter --disable-linux-tproxy --enable-pf-transparent --enable-ipfw-transparent --enable-icap-client --disable-wccp --disable-wccpv2 --enable-kill-parent-hack --enable-cache-digests --enable-follow-x-forwarded-for --enable-x-accelerator-vary --enable-zph-qos --with-default-user=proxy --with-logdir=/var/log/squid --with-pidfile=/var/run/squid.pid --with-large-files --enable-large-cache-files --enable-err-languages=English --enable-ltdl-convenience --with-filedescriptors=65536 --enable-ssl --enable-ssl-crtd --disable-auth --disable-ipv6 --disable-translation --with-pthreads
make && make install
sampai tahap diatas pastikan tidak ada error...
untuk melihat apakah squid udah berhasil diinstal..
#squid -vhasilnya kurang lebih spt ini..
Squid Cache: Version 3.4.5
configure options: '--prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--libexecdir=/usr/lib/squid' '--sysconfdir=/etc/squid' '--localstatedir=/var' '--libdir=/usr/lib' '--includedir=/usr/include' '--datadir=/usr/share/squid' '--infodir=/usr/share/info' '--mandir=/usr/share/man' '--enable-default-err-language=English' '--disable-dependency-tracking' '--enable-storeio=ufs,aufs,diskd' '--enable-removal-policies=lru,heap' '--disable-linux-netfilter' '--disable-linux-tproxy' '--enable-pf-transparent' '--enable-ipfw-transparent' '--enable-icap-client' '--disable-wccp' '--disable-wccpv2' '--enable-kill-parent-hack' '--enable-cache-digests' '--enable-follow-x-forwarded-for' '--enable-x-accelerator-vary' '--enable-zph-qos' '--with-default-user=proxy' '--with-logdir=/var/log/squid' '--with-pidfile=/var/run/squid.pid' '--with-large-files' '--enable-large-cache-files' '--enable-err-languages=English' '--enable-ltdl-convenience' '--with-filedescriptors=65536' '--enable-ssl' '--enable-ssl-crtd' '--disable-auth' '--disable-ipv6' '--disable-translation' '--with-pthreads'
Tahap selanjutnya bikin certificate...
iyaaa.. sertipikat digital, gak bisa dijadikan jaminan pinjam duit ya gaes.. xixixi...
#mkdir /etc/squid/ssl_cert
#cd /etc/squid/ssl_cert
#openssl req -new -newkey rsa:2048 -days 365 -nodes -x509 -keyout knCA.pem -out knCA.pem
#openssl x509 -in knCA.pem -outform DER -out knCA.der
#mkdir /var/squid/ssl_db
#cd /var/squid/ssl_db
#/usr/lib/squid/ssl_crtd -c -s /var/squid/ssl_db/certs
#chown -R proxy:proxy /var/squid/ssl_db/
selanjutnya..
edit squid.conf...
...bersambung...
0 komentar:
Post a Comment