MITM on HTTPS traffic in Kazakhstan
bugzilla.mozilla.org
MITM on HTTPS traffic in Kazakhstan
1–10 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#2I don't think Firefox or Chrome can do that can it?
Re: MITM on HTTPS traffic in Kazakhstan
#3Re: MITM on HTTPS traffic in Kazakhstan
#4I have custom root certs for internal dev sites for my company. That's fine, but I'd like to add the root with a caveat that I control saying "I trust this root for *.mycompany.com,mycompany.org", but that I know means they wouldn't be able to proxy "mybank.com". I don't think Firefox or Chrome can do that can it?
Re: MITM on HTTPS traffic in Kazakhstan
#5Re: MITM on HTTPS traffic in Kazakhstan
#6I have custom root certs for internal dev sites for my company. That's fine, but I'd like to add the root with a caveat that I control saying "I trust this root for *.mycompany.com,mycompany.org", but that I know means they wouldn't be able to proxy "mybank.com". I don't think Firefox or Chrome can do that can it?
You only need a root if you're issuing other keys.
Re: MITM on HTTPS traffic in Kazakhstan
#7I have custom root certs for internal dev sites for my company. That's fine, but I'd like to add the root with a caveat that I control saying "I trust this root for *.mycompany.com,mycompany.org", but that I know means they wouldn't be able to proxy "mybank.com". I don't think Firefox or Chrome can do that can it?
Re: MITM on HTTPS traffic in Kazakhstan
#8Could someone explain to me what this means and/or why it's bad?
Re: MITM on HTTPS traffic in Kazakhstan
#9Could someone explain to me what this means and/or why it's bad?
Re: MITM on HTTPS traffic in Kazakhstan
#10I have custom root certs for internal dev sites for my company. That's fine, but I'd like to add the root with a caveat that I control saying "I trust this root for *.mycompany.com,mycompany.org", but that I know means they wouldn't be able to proxy "mybank.com". I don't think Firefox or Chrome can do that can it?
No, although the root itself could be scoped that way with an X.509 name constraint. But if you add the root then I believe there's no browser policy to otherwise limit the names for which it can be trusted.