OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • Squid without Certificate is it Possible
« previous next »
  • Print
Pages: [1]

Author Topic: Squid without Certificate is it Possible  (Read 8466 times)

khairy.boub

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Squid without Certificate is it Possible
« on: September 19, 2017, 11:09:02 am »
HI Team,
I have seen many tutorials of Squid Proxy HTTPS inspection they say we need to install the  certificate in every clients machine to work.!!!! 
it Possible run Squid Proxy HTTPS inspection without install certificate in all machine
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Squid without Certificate is it Possible
« Reply #1 on: September 19, 2017, 11:36:22 am »
Basic cryptography says no. Squid needs to sit in the layer 7 traffic and it needs to decrypt the traffic for that. The only way it can do that is by establishing the TLS connection with the client on a trusted certificate.

Bart...
Logged

khairy.boub

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: Squid without Certificate is it Possible
« Reply #2 on: September 19, 2017, 11:57:09 am »
Thank you
 i haves 100 pc in my network  :'( :'( no solution !!
Logged

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Squid without Certificate is it Possible
« Reply #3 on: September 19, 2017, 12:08:47 pm »
If those 100 PCs are windows computers and belong to an AD domain, you can use a group policy. On most other operating systems, it should be possible to roll out the certificate using SSH.
Logged

khairy.boub

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: Squid without Certificate is it Possible
« Reply #4 on: September 19, 2017, 12:15:28 pm »
good idea
thank you
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Squid without Certificate is it Possible
« Reply #5 on: September 19, 2017, 06:28:12 pm »
Puppet, chef and ansible are perfect for this type of task on non-windows clients.

Bart...
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • Squid without Certificate is it Possible
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2