3 ms·
> But not for proxying HTTPS requests to actual users. Proxying everything, including HTTPS traffic, is not uncommon for internal proxies at corporations. Sin
by sehrope 13y ago
> But not for proxying HTTPS requests to actual users.
Proxying everything, including HTTPS traffic, is not uncommon for internal proxies at corporations.
Since they control the desktop infrastructure a lot of companies install an internal CA as trusted root. This trusted root can then masquerade as any website it wants since it can sign any certificate it generates on the fly. As a regular user you wouldn't even notice unless you are certificate pinning.
The other big use for internal CAs is being able to issue SSL certs for internal apps without having to have them signed externally (both the inconvenience and $$$ involved).
- pampa 13y agoAND because of the inconvenience and $$$ involved a lot of applications use a self signed cert and just skip checking the validity of the CA. I have written a few apps like that myself, so I suppose it is a common pattern.