Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid ssl filter CA issues certificates for ip, not domain

    Scheduled Pinned Locked Moved Cache/Proxy
    27 Posts 6 Posters 6.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • reza3swR
      reza3sw
      last edited by

      @doktornotor:

      @reza3sw:

      I put two photos first

      No idea where did you put two photos.

      I am sorry I did not understand
      Probably a problem with my upload center, which is not a photo.

      I'm uploading again

      First Photo

      Second Photo

      یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

      نهج البلاغه

      1 Reply Last reply Reply Quote 0
      • reza3swR
        reza3sw
        last edited by

        I am able to log in to HTTPS sites if I enter the domain name successfully with the internal certificate, but if I get the IP address of that site, I get an error certificate?
        Why this error occurs?

        This problem is problematic on Android phones to enter programs such as telegrams that use HTTPS and IP, and the program does not work?
        Is there a way to set up an IP certificate?
        Because it seems that the internal certificate we create works properly with the domain name of the sites.
        Thank you friends

        یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

        نهج البلاغه

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          This is an expected and documented behaviour, and not any issue with Squid. You would get exactly the same "problem" without Squid.

          https://wiki.squid-cache.org/Features/MimicSslServerCert

          1 Reply Last reply Reply Quote 0
          • reza3swR
            reza3sw
            last edited by

            @doktornotor:

            This is an expected and documented behaviour, and not any issue with Squid. You would get exactly the same "problem" without Squid.

            https://wiki.squid-cache.org/Features/MimicSslServerCert

            So why when the HTTPS / SSL Interception option enables SSL filtering.

            This activates this and does not exist when it is disabled?
            And my Android phone that connects to this firewall via Wi-Fi

            If this option is enabled, some of the programs will not connect to the Internet? But if this option is disabled, they will be connected.

            I even installed the internal certificate I built on my mobile phone, but the problem remains

            یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

            نهج البلاغه

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              There's nothing that activates. When you try browsing https://8.42.96.25 (or any other IPs that www.roblox.com resolves to) instead of https://www.roblox.com, you get exactly the same result without any proxy. Because the site clearly does not have any of it's IPs in its certificate's SAN.

              1 Reply Last reply Reply Quote 0
              • reza3swR
                reza3sw
                last edited by

                @doktornotor:

                There's nothing that activates. When you try browsing https://8.42.96.25 (or any other IPs that www.roblox.com resolves to) instead of https://www.roblox.com, you get exactly the same result without any proxy. Because the site clearly does not have any of it's IPs in its certificate's SAN.

                Thanks for your good guidance
                But what is this problem?

                Why does SSL filtering enable HTTPS / SSL interception when it is enabled? In squid

                Is it possible to connect some Android apps to mobile phones?

                یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                نهج البلاغه

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @reza3sw:

                  Why does SSL filtering enable HTTPS / SSL interception when it is enabled?

                  ??? ??? ???

                  1 Reply Last reply Reply Quote 0
                  • reza3swR
                    reza3sw
                    last edited by

                    @doktornotor:

                    @reza3sw:

                    Why does SSL filtering enable HTTPS / SSL interception when it is enabled?

                    ??? ??? ???

                    :D :D

                    I know my questions are a lot.
                    But I did not find a place.

                    Thanks for the time you left

                    یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                    نهج البلاغه

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      Well I don't get the question really… that's the whole purpose of the feature. If you don't want it, do NOT make the proxy transparent (or whitelist stuff that's not supposed to get proxied).

                      1 Reply Last reply Reply Quote 0
                      • reza3swR
                        reza3sw
                        last edited by

                        @doktornotor:

                        Well I don't get the question really… that's the whole purpose of the feature. If you don't want it, do NOT make the proxy transparent (or whitelist stuff that's not supposed to get proxied).

                        Again thanks for the guidance

                        But to control some sites, I need to enable this option, and on the other hand, I have the problem

                        یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                        نهج البلاغه

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.