Skip to main content
CLI man page: safesquid-applicationSignatures(5)
The Application Signatures section (safesquid-applicationSignatures(5)) tags each HTTP request with application signature strings (for example Webmail, BitTorrent, Chrome). Other sections match those tags with exact string compare — especially Access Profiles (Request Types field) and Request Types.
Vendor signature databases download on the appliance update schedule. See startup.ini UPDATE settings, Cloud / categorisation feeds, and Subscription (expired subscription skips all signature processing).

Core mechanics

Processing order

  1. If SUBSCRIPTION_EXPIRED is set, processing is skipped entirely for that connection.
  2. Prior application-signature and request-type tags are cleared.
  3. Built-in tags may be added: IPV4 Host, IPV6 Host, Cross Site Request.
  4. Application Signatures List is walked top to bottom. Every enabled rule whose tests pass may add or remove tags — there is no first-match stop.
  5. Tags from earlier rules in the same pass are visible to later rules via the Application signatures prerequisite field.
  6. Final tags are copied to request_types and logged as application signatures.

Global Enabled quirk

The section global Enabled switch is stored in configuration but request-time matching checks only each rule’s own Enabled flag. Per-rule Enabled off skips that row; global off does not stop the signature loop by itself.

Inner filter order (per row)

For each enabled row, filters run in fixed order; any failure skips to the next row:
  1. Application signatures — prerequisite tags (exact / ! match, same engine as Access Profiles).
  2. Method, Protocol — exact; missing header when field set → skip row.
  3. Mime type — regex on request Content-Type.
  4. Port range list, post data size gates, File, host/referer regex fields, User Agent, X-Forwarded-For, Request header pattern.
  5. On match: add Added application signatures and category tags; remove listed Removed application signatures.
Post data size: when Content-Length is present, the rule is skipped when content_length > minimum or content_length < maximum (optional fields must be active). No Content-Length → min/max checks are not applied.
URL commands are loaded from configuration but not evaluated — leave blank.

Application Categories List

Category definition rows are saved to the local dev XML for UI autocomplete. Runtime category tags come from the category field on Application Signatures List rules, not from the Categories list alone.

Examples

Tag webmail from vendor rule

Vendor database row matches host and User-Agent; adds Webmail.Result: Access Profiles matching Request Types or application signature Webmail apply webmail policy.

Custom rule on top of vendor tags

  • Prerequisite Webmail, Host Name mail\.partner\.com
  • Added application signatures Partner-Webmail
Result: only partner webmail gets the extra tag; generic webmail keeps Webmail only.

Category tag for reporting

On match, category SocialMedia is added to application signatures (same tag list).Result: policies and logs can match category name SocialMedia without a separate Categories list row.

How to verify

  1. Check Reports → Modules Status for application signature load/download state.
  2. Reproduce a request; read Detailed logs column application_signatures.
  3. Enable Trace Entry on a rule where available; confirm tags in Native PROFILE logs.
  4. Debug header X-SafeSquid-Application-Signatures when Send Debugging Headers To includes CLIENT — see Debug response headers.

See also

CLI: man safesquid-applicationSignatures