Search squid archive

Re: [Fwd: ssl-bump and tunneling]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hey James,

Indeed there is a way.
It's kind of basic logic of interception.
SSL interception works with dst IP only as the basic level of the function.
When the SSL is being intercepted the only level of the connection available is the IP and only after intercepting it becomes the level of the domain from squid point of view. There might be another way to "identify" the destination domain by the certificate but it can be a fake one so I don't think it will be even done.

Regards,
Eliezer

On 04/26/2014 10:10 PM, James Lay wrote:
Well there it is then...I've done the iptables thing to bypass these for
now...is there any way to see exactly why these aren't functioning
through as Intercepted?  In any case thanks for the response..that does
help me.

James





[Index of Archives]     [Linux Audio Users]     [Samba]     [Big List of Linux Books]     [Linux USB]     [Yosemite News]

  Powered by Linux