Jump to content

Recommended Posts

Posted

Don't you just love it when search providers decide they are going to move all search results to be behind SSL encryption which then requires a MitM certificate to be installed for your users to access it.

 

Had an advanced warning e-mail from RM that they will be requiring all client devices to have the certificate installed and a proxy server address added by January when the new changes will take effect.

 

As all our students BYoD devices go directly to RM's Safetynet transparent filtering installing the MitM certificate is not going to be easy.

 

Anyone got any ideas incase we have to go down the certificate installation route. We have a ruckus Wifi network and all our BYoD kit is isolated on it's own dedicated vLAN and no local filtering solution.

Posted (edited)

I've been thinking about the implications of this change myself. Prompted quite a response on twitter yesterday morning...

 

Lightspeed and Smoothwall have both offered suggestions, but as you highlight it's not straight forward for BYOD.

 

Update on Google Encrypted Search | Lightspeed Systems Community Site

Important Information for Customers Filtering Google Searches

 

It's perhaps even more difficult because we don't know at what point in December the change will occur.

 

Could you redirect your BYOD users to a webpage which offers the certificate for download?

 

[edit] Just to clarify - Google searches have defaulted to HTTPS for a while now, they are however removing the option to force none HTTPS searches using the nosslsearch.google.com DNS trick).

Edited by IrritableTech
Posted

The trouble is our students are using almost every mobile OS you can think of and it was meant to be a nice easy system where they login and the transparent proxy works without any intervention required.

 

If we redirect them to a website, we would have to do that for every single logon which would get annoying very quickly, but if we didn't we would get complaints that "the internet is not working".

 

I've not even thought at what our governors are going to do, as at least one member asks on a regular basis how to login!

Posted

Schools (and providers) can still force safe search using the other google DNS trick (assuming they don't pull that)- some may feel that is enough. The difference comes with how your filter can log or manipulate searches made through google.

 

Without a suitable certificated HTTPS inspection either devices will warn users, or filters will only see that a user visited google but not what they did once they got there.

 

I completely see your point with a webpage redirection, perhaps you could implement this for a week, then assume most have the certificate and remove again? You'd need to make it available though somewhere for new or wiped devices. Or wait until users complain about the pop up security warning, then tell them how to fix the problem? I can't see an easy answer as yet.

 

It's worth remembering that this is an issue for every single https page. So if you allow users to access twitter for example, the same applies. If you want to see which twitter user a device is trying to access, you'll need a certificate to stop the security risk warning.

Posted
So you cant opt to have mitm ssl off for byod devices? Unless your wifi solution provides some sort of app to install the cert its probably not worth having it enabled for byod.
Posted

Well I've currently got a call open with RM regarding the issue since their currently information is as clear as mud... they apparently will want us to set proxy details for each device as well...kind of defeats the point of a transparent proxy.

 

I can see the start of term being a complete nightmare. Why they want searches to be SSL encrypted now I don't know.

Posted
we have been doing some testing on our BYOD installing certs onto devices. Our biggest issue is Chrome on ios devices won't install an unsigned cert.
Posted

Saw RM at a broadband users meeting yesterday and I would say they were pushing the Google safesearch option for BYOD as being the easiest.

I can't wait for the info on the certificates etc - let's hope it is as simple as the RM person said it was :)

Posted
Certificate installation is normally a case of "oh do you want to install me, ok", its if we have to then provide them with the proxy details as well as SWGfL site says after certificate installation you have to change the proxy server address.
Posted
Well I've currently got a call open with RM regarding the issue since their currently information is as clear as mud... they apparently will want us to set proxy details for each device as well...kind of defeats the point of a transparent proxy.

 

If devices are configured to use a proxy they expect that the certificate from the site will be incorrect and therefore don't nag the user - effectively there is a known MitM. If iOS, Android and Windows Phone OS's fully supported wpad.dat then that would be the easiest way round the issue.

Posted
Certificate installation is normally a case of "oh do you want to install me, ok", its if we have to then provide them with the proxy details as well as SWGfL site says after certificate installation you have to change the proxy server address.
I had this part working on our Lightspeed box this week but struggling to find a way to deploy the proxy settings to IE11. Not even begun to experiment on devices. forcesafesearch for byod device sounds most viable for me
Posted

Hmm... I've not heard anything about this from SWGfL here. Maybe my boss has and hasn't passed it on to me.

 

This certainly won't help anyone with BYOD schemes. Its gonna be a nightmare getting the certificate installed for visitors, for example...

Posted

Morning All,

 

Just noticed an email from RM regarding the Google changes and the fact they can't filter them from January apart from adding these new additional certs.

 

Changes to Google SSL and RM Safetynet Plus | RM Education - What we do

 

Is there any work around currently we could implement within ISA in the mean time until they fix their solution? Already looking at replacement filtering systems Smooth/Lightspeed, but obviously that won't be in before January and just don't want there to be a lap over between RMs release, and days where it's unfiltered.

 

Many thanks,

Steve

Posted

I haven't seen any email... :(

 

 

Also, best part of that page:

 

"You may wish to discuss this process with your technical support team"

Posted

Was in my junk box :D Says what Microsoft thinks of their emails lol

 

From January 2015, changes Google are implementing will make it impossible for RM SafetyNet Plus (and other filtering products) to filter Google search results. We have therefore decided to add ‘SSL interception’ to RM SafetyNet Plus, providing a way to continue to filter inappropriate search results.

 

In order to perform ‘SSL interception’, RM SafetyNet Plus needs to decrypt, analyse, and then re-encrypt all traffic using a security certificate. This certificate must be deployed to all computers and devices that browse via an RM SafetyNet Plus filtered connection. RM Education will provide the certificate for download and support documentation which includes a guide to deploying the certificate to common operating systems and browsers, as well as changing your proxy address after the certificate is deployed.

 

Not sure why they want all computers to have cert "and" change of proxy address... :(

 

Steve

Posted
Well SWGfL have come back with "You will not need to enter a proxy server address for your BYoD and be rest assured however, that we will be helping our customers through the deployment" when I called and logged a WTF call with them.
Posted

The proxy change sounds like it is a different address for us to pass upstream traffic to - one set up to not use the nossl address. So, I imagine I'll just have to enter it in our onsite proxy.

 

I can't see how anyone will get around the need to install some form of client certificate to enable filtering on it though - no matter what solution they use for filtering.

Posted
@IrritableTech there are some big changes coming and every filtering product in the world will be effected.

 

We'll have a statement out next week regarding our Lightspeed implementation.

 

A lot of providers are going to have a lot of problems

 

Dave

 

I know Dave - have you not read my blog? :-)

 

Thanks for the update. It'd be nice if Google would give a date at least.

Posted
I've always found safeguarding BYOD ineffective regardless of this announcement, I don't appear to be able to monitor what apps they have, what traffic flows from them, VPN usage is rife - I've just never been able to stop anything much to the teachers chagrin - so I doubt this will make much difference, to be fair I may as well just not bother with any kind of filtering on them and just keep quoting the AUP
Posted
It depends on your environment. If you want to monitor google searches you need to be using SSL interception. This will in most cases incur cost. The web is moving to SSL more and more. In a environment like FE and HE you can not have interception on guest devices but be aware of the implications. Can't stop exe download where they are hosted on SSL Connections.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...