• Semperverus@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    ·
    9 days ago

    “Hey there customer, if you want internet access on our network (the only one available in your area), you have to install our intermediary certificate on your machine!”

    • exu@feditown.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 days ago

      From having worked in an enterprise environment, there’s a chunk of websites that break when you intercept their SSL connection.

        • exu@feditown.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 days ago

          Not really, because the client system is configured to go through the proxy. That proxy will connect to the website and do filtering on the unencrypted content because it is initiating the connection. Next it’ll re-encrypt everything with its own certificate and serve it to the client.

            • exu@feditown.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 days ago

              Yes, but that’s what you would need to do and get if everyone had to install an intermediate cert.