Re: [squid-users] Transparent proxy with HTTPS on freebsd

From: Matus UHLAR - fantomas <uhlar_at_fantomas.sk>
Date: Mon, 4 May 2009 10:26:43 +0200

On 29.04.09 04:58, nyoman karna wrote:
> you can NOT use transparent proxy for HTTPS.
>
> since using transparent proxy for HTTPS
> will be considered as man-in-the-middle attack.
>
> you probably may use PAC (as Amos suggested)
> but IMO it ruin the basic idea of using transparent proxy
> (which is user does not need to put any setting in their browser)

the whole idea of intercepting proxy (also called transparent) is sick.
WPAD is way to go - browser will autodetect the proxy, so user can log there
and all problems caused by intercepting connections will be gone.

-- 
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Micro$oft random number generator: 0, 0, 0, 4.33e+67, 0, 0, 0...
Received on Mon May 04 2009 - 08:26:48 MDT

This archive was generated by hypermail 2.2.0 : Tue May 05 2009 - 12:00:01 MDT