Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Email certificate error

    Scheduled Pinned Locked Moved Cache/Proxy
    7 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lannet2k
      last edited by

      Hi,
      I setup the squid to be transparent ( just finish a fresh install on 2.2 ) , but with no ssl, still with some email I get a request from the email program about a selfsigne certificate ??
      How is it possible to avoid this warning ?
      Thanks

      1 Reply Last reply Reply Quote 0
      • J
        Jambro1964
        last edited by

        Sounds like you still have the HTTPS/SSL interception checked. If that is turned off then all HTTPS will go through and not be proxied.
        If you want to use SSL man in the middle you have to generate a CA cert in cert manager and also export it and install it all devices.
        Kind of a pain but if you want to check the content of the HTTPS you have to do it this way.

        Jim

        1 Reply Last reply Reply Quote 0
        • L
          lannet2k
          last edited by

          Hi thanks for the answer.
          Yes youare correct, but I just try disabling the transparent Proxy and still get the warning :(
          It's about the pfsense certificate , don't understand why.

          Update.
          The only way to solve it was to import the PFSense certificate on the email program, but still I don't understand why ??

          ![email warning.jpg](/public/imported_attachments/1/email warning.jpg)
          ![email warning.jpg_thumb](/public/imported_attachments/1/email warning.jpg_thumb)

          1 Reply Last reply Reply Quote 0
          • J
            Jambro1964
            last edited by

            If you are using the SSL bump in the middle then you need to import the CA certificate you are using on all the machines behind the proxy server.
            The proxy server decrypts using the public SSL CAs and then encrypts it back using your local CA and your machine needs that CA to display it in the browser.

            Jim

            1 Reply Last reply Reply Quote 0
            • L
              lannet2k
              last edited by

              Thanks Jim,
              no I don't use the ssl :)

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                If you truly have transparent mode disabled and you have configured your system manually to use the proxy or automatically via WPAD, it should not give any certificate errors.  Something weird is going on.

                1 Reply Last reply Reply Quote 0
                • L
                  lannet2k
                  last edited by

                  Yes , I just wiped all and installed a fresh copy.
                  Hope it works better :)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.