• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Transparent Proxy - ssl_error_bad_cert_domain

Scheduled Pinned Locked Moved Cache/Proxy
7 Posts 3 Posters 2.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    slu
    last edited by Jan 27, 2016, 3:27 PM

    Hi,

    install today a https proxy and install my CA in the browser.
    Most https pages work, but on some I get the following error: Error code: ssl_error_bad_cert_domain

    Did I do something wrong in my config?

    pfSense Gold subscription

    1 Reply Last reply Reply Quote 0
    • K
      killmasta93
      last edited by Jan 27, 2016, 5:17 PM

      Why not better with WPAD? much easier and no need to install cert on each computer

      Tutorials:

      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

      1 Reply Last reply Reply Quote 0
      • S
        slu
        last edited by Jan 28, 2016, 11:28 AM

        No option for this setup, it is much easier to install the certs.
        Lot of products use this transparent proxy, why it should work with pfsense?

        Maybe it is a setting and my fault?

        pfSense Gold subscription

        1 Reply Last reply Reply Quote 0
        • S
          slu
          last edited by Jan 28, 2016, 4:32 PM

          If i understand this right, the problem on this web server is the SNI.
          Open the website without squid show as CN the FQDN, with ssl_bump is the CN the ip address.

          Maybe Squid 3.5 solve this issue?

          pfSense Gold subscription

          1 Reply Last reply Reply Quote 0
          • K
            killmasta93
            last edited by Jan 30, 2016, 9:54 PM

            Not really sure if 3.5 will fix your issue but give it a try but when i mean WPAD you can run it along with transparent proxy too just the wpad will block https and the transparent proxy will block the http

            Tutorials:

            https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

            1 Reply Last reply Reply Quote 0
            • C
              chidgear
              last edited by Feb 2, 2016, 5:12 PM Feb 2, 2016, 5:09 PM

              @killmasta93:

              Not really sure if 3.5 will fix your issue but give it a try but when i mean WPAD you can run it along with transparent proxy too just the wpad will block https and the transparent proxy will block the http

              OMFG!!!! blowmind!!!!
              I never thought that where possible!
              I have to try that… when i get some PC to do the tests. I cannot risk to do it on the working enviroment.
              Thanks for the advise.

              @slu:

              Hi,

              install today a https proxy and install my CA in the browser.
              Most https pages work, but on some I get the following error: Error code: ssl_error_bad_cert_domain

              Did I do something wrong in my config?

              slu, I had similar troubles (a blue squid with the word "NOW" appears on the upper left corner) I solved this obtaining the IP address, sometimes it appears in the screen followed by the port, example:```
              123.45.167.89:443

              So, in this case, you need to add 123.45.167.89 to the "Bypass Proxy for These Destination IPs" field in "Transparent Proxy Settings" (if using squid3). I suggest you to use an alias (Firewall -> Aliases). This way, you only need to edit the alias, and avoid to fill the proxy settings every time, and get lost by the amount of IP's in the future.
              
              Good Luck!
              1 Reply Last reply Reply Quote 0
              • K
                killmasta93
                last edited by Feb 3, 2016, 12:38 AM

                OMFG!!!! blowmind!!!!
                I never thought that where possible!
                I have to try that… when i get some PC to do the tests. I cannot risk to do it on the working enviroment.
                Thanks for the advise.

                yeah cool but if you want limiter it will break it :( but now not sure if limiter is worth it when traffic shaping using codel seems to work wonders for now on the VOIP

                Tutorials:

                https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                1 Reply Last reply Reply Quote 0
                5 out of 7
                • First post
                  5/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received