4 ms·
Why is your App trying to install a root certificate alongside the VPN settings? Is that certificate unique per device?
by fkistner 11y ago
Why is your App trying to install a root certificate alongside the VPN settings?
Is that certificate unique per device?
- tomkinstinch 11y agoMadBlocker uses the VPN subsystem for filtering, even though the traffic doesn't leave the device. In order for the VPN profile to work with the On Demand VPN system (used for sending ad domain requests to 127.3.5.7), it has to use cert-based auth, and MadBlocker is using a self-signed certificate so I could use a reasonable expiration time (ten years) without paying a ton of money for a cert signed by a commercial CA. It seemed silly to pay for a cert that sees no use. I had actually used a proper cert earlier in testing, but figured people would get frustrated with the one-year expiration time.
- fkistner 11y agoAllright, makes sense. But does it not mean that you could basically spoof any secure connection (provided you could establish a man-in-the-middle)? Just wondering, since the VPN destination is not easily verifiable: What stops you from shipping a profile tomorrow that directs traffic towards your server for online banking sites and breaking the TLS encryption using that root certificate?
- lawnchair_larry 11y agoIf the cert is not trusted for server auth and doesn't have the CA flag set, it can't be used this way. Certs are also used to authenticate to VPNs, and can be trusted only for that purpose.
- blub 11y agoI was surprised to hear it's a root cert. Any pointers on what to look for in the cert details windows on iOS to check if that's the case?