2 ms·
Anyway, I would say "--ignore-certificate-errors" is an acceptable workaround here. If your proxy is already intercepting all HTTPS traffic, then there's really
by codeka 14y ago
Anyway, I would say "--ignore-certificate-errors" is an acceptable workaround here. If your proxy is already intercepting all HTTPS traffic, then there's really no benefit in the client browser also verifying certificates.
Of course, I would still only run with "--ignore-certificate-errors" for the limited time the proxy has broken certificates or whatever...
- harshreality 14y agoEven with a corporate proxy intercepting SSL connections, individual browsers are still protected against attacks on the local network involving SSL impersonation (rogue access points, DHCP or ipv6 neighbor announcement abuse...). Companies have their firewall infrastructure locked down (hopefully), but lan segments (except in high-security environments) not as much.