Hacker News new | past | comments | ask | show | jobs | submit login

How does that work with SSL?



Proxy does SSL checking, browser trusts proxy's CA certificate, requests are re-signed on the fly.


This is more difficult with mobile devices, and also doesn't it display warning dialogs?


The warning dialogs do not display if you add the authority certificate used by the proxy to your trust store, and the proxy properly re-signs everything.


How do you distinguish between eg EV SSL versus non-EV?


That may indeed be a problem. Could use an out-of-browser gui, or possibly configure your browser to trust your own CA as a CA capable of EV somehow, and stick your own EV id in the generated certificate. I dont think this is configurable in most common browsers at the moment, though.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: