Re: [fw-wiz] Security of HTTPS

From: Ng Pheng Siong (ngps_at_netmemetic.com)
Date: 11/28/04

  • Next message: Frank Knobbe: "Re: [fw-wiz] Security of HTTPS"
    To: Kevin Sheldrake <kev@electriccat.co.uk>
    Date: Mon, 29 Nov 2004 00:33:15 +0800
    
    

    On Sun, Nov 28, 2004 at 03:38:09PM -0000, Kevin Sheldrake wrote:
    > I expect others do too, to enable content filtering at an organisational
    > boundary, re-encrypting with their own certificate upon success. If their
    > own certificate has been signed by a trusted party (CA) then the user will
    > be practically unaware of the decryption.

    Nit: Not "re-encrypting with their own certificate". More properly, proxy
    the HTTPS traffic, where the in-house part is between the browser and the
    proxy. The proxy generates a certificate for the real server dynamically,
    signs it with the in-house CA, and presents this certificate to the client
    as the server's certificate. If the in-house CA certificate has been signed
    by a trusted CA then the browser will accept this proxy certificate as the
    server's certificate.

    Be prepared to buy hardware SSL accelerators for the proxy.

    Cheers.

    -- 
    Ng Pheng Siong <ngps@netmemetic.com> 
    http://sandbox.rulemaker.net/ngps -+- M2Crypto, ZServerSSL for Zope, Blog
    http://www.sqlcrypt.com -+- Database Engine with Transparent AES Encryption
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Frank Knobbe: "Re: [fw-wiz] Security of HTTPS"

    Relevant Pages

    • Re: Preventing tunnels through HTTPS proxies
      ... The client is given a Certificate signed by the proxy that ... who then will present its certificate to the ... proxy (now becoming the client). ... Next step is a redirect to the main requested website, i prefer use HTTP ...
      (Security-Basics)
    • Re: HTTPS proxy tool that resigns SSL certs
      ... > Does anyone know of an HTTPS proxy tool that will let you resign SSL> certificates when doing a MITM attack? ... but this will still pop up a certificate warning. ... > client end network - DNS, routing, etc... ...
      (Pen-Test)
    • Re: Save from Proxy
      ... that is going via proxy I doubt this because number of times when I ... certificates or what soever be ... outside of the untrusted network, but becomes invalid, as soon as you ... this is a clear sign that the administrators are replacing it. ...
      (comp.os.linux.security)
    • Re: HTTP Proxy Question
      ... First, you changed your browser's proxy to use the localhost proxy, correct? ... point one browser through the proxy and the other directly at the site. ... FF3 and IE7 have become annoying if you aren't using a MS or Mozilla approved certificate provider. ... When I start IE7 or Firefox, the proxy shows the start of the connection, but the browse shows that it can not connect to the server. ...
      (Pen-Test)
    • Re: ISA2006 (No SP1) Single NIC Workgroup DMZ Client Certificate Auth
      ... You can't "proxy" a certificate. ... You'll have to use Server Publishing for this site if you insist on cert ...
      (microsoft.public.isa)