Re: [fw-wiz] Security of HTTPS

From: David Lang (david.lang_at_digitalinsight.com)
Date: 12/25/04

  • Next message: David Lang: "Re: [fw-wiz] Defense in Depth to the Desktop"
    To: Kevin <kkadow@gmail.com>
    Date: Sat, 25 Dec 2004 00:10:16 -0800 (PST)
    
    

    sorry for the late reply, catching up on my mail

    On Wed, 1 Dec 2004, Kevin wrote:

    > Getting back on the topic of firewalls, I wonder if it would be
    > possible for a firewall not doing MITM for SSL to validate the
    > certificate presented by the remote server, and terminate the
    > attempted SSL session if the certificate does not match the remote
    > host, is not signed by an acceptable CA or has been revoked?

    the problem is that the firewall doesn't know what the client is expecting
    to see in the cert. it could check to see if the cert was signed by a
    known orginization, but not if the identity of the host matches the
    identity stipulated in the cert

    David Lang

    -- 
    There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies.
      -- C.A.R. Hoare
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: David Lang: "Re: [fw-wiz] Defense in Depth to the Desktop"

    Relevant Pages

    • Re: Problems with ActiveSync - Windows Mobile Devices - 0x80072F05
      ... If I uncheck the box "server requires SSL", ... The unfortunate part about this though is our cert was just ... effectively rule out that our firewall is blocking 443. ...
      (microsoft.public.exchange.setup)
    • =?ISO-8859-1?Q?Re:_SSL/TLS_Woes_FTP?=
      ... server needs to allow incoming connections to ports higher than 1024. ... you may need firewall adjustments. ... The z/OS FTP client is also very picky about server certificates. ... server cert must be signed by a CA acceptable to the client, ...
      (bit.listserv.ibm-main)
    • RE: [fw-wiz] HTTPS proxy solutions
      ... Apache listens on the exterior (through a firewall), accepts the SSL ... connection and forwards the clear text HTTP to another internal server. ... What I'm thinking of is a proxy that gathers information about name ...
      (Firewall-Wizards)
    • =?Utf-8?Q?Re:_DNS_und_Zertifikatsprobleme_?= =?Utf-8?Q?bei_dummer_Dom=C3=A4nenbezeichnung?=
      ... SSL POP ist doch ok, oder was gäbe es dagegen zu sagen? ... Exchange wird per 1:1 NAT erreicht. ... Dann ist das keine Firewall sondern ein NAT-Router. ...
      (microsoft.public.de.exchange)
    • AW: SSL connections through firewall
      ... Subject: AW: SSL connections through firewall ... -For virus protection, have a corporate version of Virus Server. ...
      (Security-Basics)