• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

SSL inspection

Scheduled Pinned Locked Moved pfSense Packages
5 Posts 3 Posters 4.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    samer79
    last edited by Dec 10, 2010, 3:27 AM

    Hello,

    When can we have SSL port 443 inspection, this will be an excellent feature for the PFsense, will it be a snort development or a different package (WAF Web application firewall)?

    Regards,
    Sam

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Dec 13, 2010, 1:31 PM

      If you want to do that, setup squid and hardcode the proxy settings into the clients.

      If you want to do transparent SSL inspection, that is impossible. Some routers claim to do this but you have to install special certificates on every client so it's hardly "transparent" in the traditional sense.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • C
        chronos00
        last edited by Dec 15, 2010, 2:34 PM

        Perhaps I am misunderstanding, but if you want to intercept SSL comunications, that can be done by proxying web access to your clients and stripping the SSL URLs, and changing them for non SSL URLs. For more information, see this site

        Another way is to use bogus certificates to replace the original ones while proxying. Believe it or not this can be done; some publicly accepted CAs had a bug that allowed the creation of certificates with "\0" in their URLs, wich is why most browsers will show the certificate for "www.google.com\0.mih4x0rdomain.com" as "www.google.com". I understand this has been corrected in most cases, but some of this certificates have not exipred yet. More info here

        Hope this helps.
        Regards

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Dec 15, 2010, 2:37 PM

          Both of those are pretty much what I said… but obviously relying on that second bug to stick around would not be wise.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • S
            samer79
            last edited by Dec 21, 2010, 2:32 PM

            Any example on how to use the first option (SSL STRIP)?

            1 Reply Last reply Reply Quote 0
            3 out of 5
            • First post
              3/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received