Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent Proxy - ssl_error_bad_cert_domain

    Scheduled Pinned Locked Moved Cache/Proxy
    7 Posts 3 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      slu
      last edited by

      Hi,

      install today a https proxy and install my CA in the browser.
      Most https pages work, but on some I get the following error: Error code: ssl_error_bad_cert_domain

      Did I do something wrong in my config?

      pfSense Gold subscription

      1 Reply Last reply Reply Quote 0
      • K
        killmasta93
        last edited by

        Why not better with WPAD? much easier and no need to install cert on each computer

        Tutorials:

        https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

        1 Reply Last reply Reply Quote 0
        • S
          slu
          last edited by

          No option for this setup, it is much easier to install the certs.
          Lot of products use this transparent proxy, why it should work with pfsense?

          Maybe it is a setting and my fault?

          pfSense Gold subscription

          1 Reply Last reply Reply Quote 0
          • S
            slu
            last edited by

            If i understand this right, the problem on this web server is the SNI.
            Open the website without squid show as CN the FQDN, with ssl_bump is the CN the ip address.

            Maybe Squid 3.5 solve this issue?

            pfSense Gold subscription

            1 Reply Last reply Reply Quote 0
            • K
              killmasta93
              last edited by

              Not really sure if 3.5 will fix your issue but give it a try but when i mean WPAD you can run it along with transparent proxy too just the wpad will block https and the transparent proxy will block the http

              Tutorials:

              https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

              1 Reply Last reply Reply Quote 0
              • C
                chidgear
                last edited by

                @killmasta93:

                Not really sure if 3.5 will fix your issue but give it a try but when i mean WPAD you can run it along with transparent proxy too just the wpad will block https and the transparent proxy will block the http

                OMFG!!!! blowmind!!!!
                I never thought that where possible!
                I have to try that… when i get some PC to do the tests. I cannot risk to do it on the working enviroment.
                Thanks for the advise.

                @slu:

                Hi,

                install today a https proxy and install my CA in the browser.
                Most https pages work, but on some I get the following error: Error code: ssl_error_bad_cert_domain

                Did I do something wrong in my config?

                slu, I had similar troubles (a blue squid with the word "NOW" appears on the upper left corner) I solved this obtaining the IP address, sometimes it appears in the screen followed by the port, example:```
                123.45.167.89:443

                So, in this case, you need to add 123.45.167.89 to the "Bypass Proxy for These Destination IPs" field in "Transparent Proxy Settings" (if using squid3). I suggest you to use an alias (Firewall -> Aliases). This way, you only need to edit the alias, and avoid to fill the proxy settings every time, and get lost by the amount of IP's in the future.
                
                Good Luck!
                1 Reply Last reply Reply Quote 0
                • K
                  killmasta93
                  last edited by

                  OMFG!!!! blowmind!!!!
                  I never thought that where possible!
                  I have to try that… when i get some PC to do the tests. I cannot risk to do it on the working enviroment.
                  Thanks for the advise.

                  yeah cool but if you want limiter it will break it :( but now not sure if limiter is worth it when traffic shaping using codel seems to work wonders for now on the VOIP

                  Tutorials:

                  https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.