3 ms·
TLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.
by Snawoot 3y ago
TLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.
- darkarmani 3y agoInstead of a pihole, you'd run a https proxy that doesn't trust the certs i guess.
- Snawoot 3y agoWhich https proxy you're referring to? HTTP proxies capable of forwarding HTTPS just offer HTTP CONNECT method, which allows client to tunnel regular TCP connection and HTTPS inside it. These proxies do not do anything with certificates.