Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Https filtering - iTunes, iPhones?

    Scheduled Pinned Locked Moved Cache/Proxy
    3 Posts 2 Posters 727 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      uncleaelfrich
      last edited by

      I have implemented the https filtering tutorial as found here https://docs.diladele.com/tutorials/filtering_https_traffic_squid_pfsense/

      I have gotten everything to work EXCEPT for itunes, icloud, and my iphones and ipad.

      I have tried the iphones both with and without putting the proxy in the general settings for the wifi. I have added the websites for iOS, macOS, etc. that apple gives. https://support.apple.com/en-us/HT201999 But I am still unable to reach the iTunes store or to update any apps on our iphones.

      I am sure I am not the first person to experience this problem, but I haven’t been able to find any solutions online. Can anyone please help me with this problem?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • S
        sichent Banned
        last edited by

        The apple products (and most mobile ones) use so called SSL pinning when application refuses to accept any other HTTPS certificate except the one known to it,
        See https://docs.diladele.com/faq/squid/sslbump_exlusions/apple_app_store.html

        Hope it helps.
        (here in the test lab I had to add .mzstatic to make the iTunes work though proxy).

        1 Reply Last reply Reply Quote 0
        • U
          uncleaelfrich
          last edited by

          I found that adding

          apple.com
          icloud.com
          mzstatic.com

          to the whitelist at Services>Squid Proxy Server>ACLs seems to work for me (in addition to the FAQ from diladele from sichent above, if you are using the Diladele Web Safety.)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.