3 ms·
But how? Normally the TLS handshake and encryption/decryption happen in user space. Even the kernel doesn’t know anything about it.
by ruszki 2mo ago
But how? Normally the TLS handshake and encryption/decryption happen in user space. Even the kernel doesn’t know anything about it.
- icedchai 2mo agoThere is a transparent proxy installed (along with the necessary certificates on the VM.) For an example, see https://docs.microsandbox.dev/networking/tls https://docs.microsandbox.dev/networking/tls
- ruszki 2mo agoSo, if the program or the proxy solution doesn’t support it, then it doesn’t work? Like with security solutions?
- icedchai 2mo agoThe docs mention it can be bypassed for configured domains.
- ruszki 2mo agoYes, I read it. That means that it doesn’t work in those cases. Btw, as a developer it’s very easy to have something like that. It’s not as trivial as it seems at all. I encountered with similar problems all the time, with similar solutions (mainly for security theater reasons) in the past. There are websites which simply doesn’t work if you replace certificates, regardless of browser or CA for example.
- icedchai 2mo agoYes, I've worked with people who have run into issues with "security" solutions like ZScaler. I have tried it with some APIs (like GitHub) and it does work. Not to say it will work in your case.
- toksdotdev 2mo agomicrosandbox is designed to work with most security products. there's a dedicated section for this in the docs that makes this entire process seamless: https://docs.microsandbox.dev/networking/tls#trusting-host-cas https://docs.microsandbox.dev/networking/tls#trusting-host-c...
- deleted 2mo ago[deleted]
- toksdotdev 2mo agomicrosandbox maintainer here. the custom certificate is installed in the guest's trusted root CA list, so it should work across any program, except where the program opts to explicitly pin certificates for a destination.