3 ms·
Using dynamic generated certificates with Nginx
- cwmma 11y agoso ... how to MITM an TLS connection?
- jvehent 11y agoIf you can a) route the traffic through your proxy and b) generate a valid certificate for the target site that's accepted by web browsers, then yes, it's a mitm :)
- wwwhizz 11y agoWhilst a) is possible under some circumstances, b) should be impossible.
- tobbez 11y ago...unless you have somehow acquired a CA's private keys, or are in control of the clients' certificate stores.
- electrum 11y agoThe latter of which is very common in corporate environments where employee's machines are provisioned by the IT department and contain the company's private CA (which is useful for non-nefarious purposes such as signing certificates for internal services).
- nileshtrivedi 11y agoIn case of (a), you can use MITMProxy[1] - a handy tool especially for debugging traffic from mobile devices. 1: https://mitmproxy.org/ https://mitmproxy.org/
- vtlynch 11y agoThis is basically what existing corporate proxies (like FireEye) and AV software (like Avast!) already do.
- nl5887 11y agoExactly, but now it is integrated in nginx. So this could be an alternative for proprietary software, or Squid.
- feld 11y agoWhat are the filtering capabilities? Someone needs to finish flushing this out (maybe make it speak to snort or something) because there are a lot of corporate proxies out there that don't support TLS 1.2, for example, which is a travesty that they're really downgrading your security.
- nl5887 11y agoCheck out this library: https://github.com/dutchcoders/honos https://github.com/dutchcoders/honos. It adds filtering on host, uri and content type to each request.