Re: [fw-wiz] Security of HTTPS

From: Ng Pheng Siong (ngps_at_netmemetic.com)
Date: 11/28/04

  • Next message: Frank Knobbe: "Re: [fw-wiz] Security of HTTPS"
    To: Kevin Sheldrake <kev@electriccat.co.uk>
    Date: Mon, 29 Nov 2004 00:33:15 +0800
    
    

    On Sun, Nov 28, 2004 at 03:38:09PM -0000, Kevin Sheldrake wrote:
    > I expect others do too, to enable content filtering at an organisational
    > boundary, re-encrypting with their own certificate upon success. If their
    > own certificate has been signed by a trusted party (CA) then the user will
    > be practically unaware of the decryption.

    Nit: Not "re-encrypting with their own certificate". More properly, proxy
    the HTTPS traffic, where the in-house part is between the browser and the
    proxy. The proxy generates a certificate for the real server dynamically,
    signs it with the in-house CA, and presents this certificate to the client
    as the server's certificate. If the in-house CA certificate has been signed
    by a trusted CA then the browser will accept this proxy certificate as the
    server's certificate.

    Be prepared to buy hardware SSL accelerators for the proxy.

    Cheers.

    -- 
    Ng Pheng Siong <ngps@netmemetic.com> 
    http://sandbox.rulemaker.net/ngps -+- M2Crypto, ZServerSSL for Zope, Blog
    http://www.sqlcrypt.com -+- Database Engine with Transparent AES Encryption
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Frank Knobbe: "Re: [fw-wiz] Security of HTTPS"

    Relevant Pages

    • Re: HTTPS proxy tool that resigns SSL certs
      ... > Does anyone know of an HTTPS proxy tool that will let you resign SSL> certificates when doing a MITM attack? ... but this will still pop up a certificate warning. ... > client end network - DNS, routing, etc... ...
      (Pen-Test)
    • Re: Save from Proxy
      ... that is going via proxy I doubt this because number of times when I ... certificates or what soever be ... outside of the untrusted network, but becomes invalid, as soon as you ... this is a clear sign that the administrators are replacing it. ...
      (comp.os.linux.security)
    • Re: ISA2006 (No SP1) Single NIC Workgroup DMZ Client Certificate Auth
      ... You can't "proxy" a certificate. ... You'll have to use Server Publishing for this site if you insist on cert ...
      (microsoft.public.isa)
    • Re: RPC Over HTTP
      ... I am having trouble with the actual proxy ... >What URL do you use to access your SBS from a remote ... >CEICW and create the certificate. ... >time you connect from a remote client, ...
      (microsoft.public.windows.server.sbs)
    • Re: [fw-wiz] Application Proxy/L7 Firewall Recommendation?
      ... > certificate presented by your decrypting proxy doesn't match the expected ... > certificate of the site I'm connecting to. ... The client must trust this CA ... The generated cert is then used to initiate a TLS session with the client ...
      (Firewall-Wizards)