HI Team,
I have seen many tutorials of Squid Proxy HTTPS inspection they say we need to install the certificate in every clients machine to work.!!!!
it Possible run Squid Proxy HTTPS inspection without install certificate in all machine
Basic cryptography says no. Squid needs to sit in the layer 7 traffic and it needs to decrypt the traffic for that. The only way it can do that is by establishing the TLS connection with the client on a trusted certificate.
Bart...
Thank you
i haves 100 pc in my network :'( :'( no solution !!
If those 100 PCs are windows computers and belong to an AD domain, you can use a group policy. On most other operating systems, it should be possible to roll out the certificate using SSH.
good idea
thank you
Puppet, chef and ansible are perfect for this type of task on non-windows clients.
Bart...