Re: [squid-users] SSL bump interception and certificates warnign

From: Alex Crow <alex_at_nanogherkin.com>
Date: Thu, 12 Sep 2013 21:21:57 +0100

On 11/09/13 20:56, Loïc BLOT wrote:
> Then, if i add my own CA to firefox warning will disappear ?

Yes, that is the way SSL works. Just make sure you install the proxy's
CA cert in trusted root CAs in Windows cert store and/or other browsers'
stores and you are good to go.

NB this may not be legal in your jurisdiction if you are doing this for
others than yourself. Especially if it's for a company and you don't
have it mentioned in your employee contract as it could well be used
against you. SSL provides an expectation (albeit rather optimistic at
the moment given the NSA debacle) of end-to-end privacy and you cannot
with good conscience violate that trust even if it is technically
possible. Remember that you are effectively doing an MITM attack.

Cheers

Alex
Received on Thu Sep 12 2013 - 20:22:04 MDT

This archive was generated by hypermail 2.2.0 : Fri Sep 13 2013 - 12:00:07 MDT