Transparent Redirection of Port 443 (HTTPS)

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Transparent Redirection of Port 443 (HTTPS)

Postby yadie099 » Jun 25 04 10:10 am

How can I use transparent redirection for http secure session on port 443?
I tried adding the port in the www proxy - Session - Transparent proxy, but when I do this https pages cannot be displayed.
Https sessions are fine if the browser is configured for a proxy, but I want to be able to transparently redirect without configuring the browser for a proxy.
yadie099
 
Posts: 32
Joined: Sep 27 03 1:01 pm

Postby adrien » Jun 26 04 3:25 am

the short answer is that you can't intercept SSL connections. This is for a couple of reasons, the first one being that these connections are negotiated end to end and encrypted. If we intercepted such a connection, we would break it.

Having said that, it probably is now possible to intercept such connections with WinGate 6.0 beta 3, however the client browser will complain that the SSL certificate does not match the one it expects to see since it will see WinGate's one. Furthermore WinGate would connect on to the next server with just HTTP, this would more often than not fail.

All in all, not a good idea. In fact this is called the man-in-the-middle attack. If you want your users to be able to use HTTPS, the easiest thing to do is do nothing - let them just make NAT connections.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby yadie099 » Jun 30 04 9:05 am

Thanks
ssl connections work fine when proxy is setup in the browser. I wondered if it could work without explicitly setting a proxy in the browser.
yadie099
 
Posts: 32
Joined: Sep 27 03 1:01 pm

Postby adrien » Jul 01 04 12:39 am

If you take the proxy setting out of the browser for HTTPS, then it should just make a connection through WinGate's ENS without any problems.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland


Return to WinGate

Who is online

Users browsing this forum: No registered users and 10 guests