3 ms·
Will Mitmproxy stop working?
by q2dg 2y ago
Will Mitmproxy stop working?
- notpushkin 2y agoChrome treats certificates added by user as not requiring CT: https://github.com/mitmproxy/mitmproxy/discussions/5720 https://github.com/mitmproxy/mitmproxy/discussions/5720
- zinekeller 2y agoAnd to wit, Firefox too: > Setting this preference to 2 causes Firefox to enforce CT for certificates issued by roots in Mozilla's Root CA Program.
- perching_aix 2y agoI believe so. You'll need to disable CT enforcement / or add your SPKI hash to the ignore list in the browser settings temporarily to get it working. [0] I guess this is also how corporations get around this issue? Still unsure. [0] https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency https://wiki.mozilla.org/SecurityEngineering/Certificate_Tra...
- mcpherrinm 2y agoNo. CT is only required for public CAs. You only need those browser policy settings if you’re using a public CA without CT.
- perching_aix 2y agoI'd imagine this is why certs that terminate in root certificates manually added to the trust store will work fine then [as stated by other comments]?
- mcpherrinm 2y agoRight, any CA you add yourself that isn’t part of what Mozilla ships isn’t considered a publicly trusted CA.