Bruce123 Posted December 6, 2013 Posted December 6, 2013 Hi all, We have a particular problem with certain devices and our wireless BYOD setup. Essentially, users connect to an open network and authenticate via a captive portal (AD integrated) for Internet access. The connection is filtered and goes out via a firewall at layer 3/4. All's OK apart from when the user tries to access an SSL enabled website. The firewall decrypts the SSL session, re-establishes an SSL session replacing the real certificate with a SSL certificate generated on-the-fly by the firewall. The problem is the BYOD devices don't trust the certificate (can't be verified) as they don't have root certificate installed. Is there a simple way to resolve this issue? Is there any easy way to push out the root cert to user's devices? I wondered if we could place a copy of the root certificate on our website, that users could be instructed to download using the URL e.g. go to website.com/root.cert? I know one way is to copy the certificate to the SD card, but our users would find this too complicated. Any advise is much appreciated. Many Thanks, Bruce. PS The connection goes via Bloxx (filtering) and Watchguard (firewall) but I can't quite remember which is performing the SSL decryption/re-encryption.
FN-GM Posted December 6, 2013 Posted December 6, 2013 Not 100% sure how your solution works, but could you use a real world certificate for the job?
bjohnny42 Posted December 9, 2013 Posted December 9, 2013 Just a quick thought but do you tell your users that you decript and intercept their SSL data? Are there warnings about banking using school facilities etc? It seems mad doing online banking in school but you never know with some users. This among other things. I think what you are talking about is discussed here. Installing anything on someones own device is fraught with difficulty and I don't see a way around it. Totally possible to install a cert on school own devices but fraught with difficulty on user owned devices. (Both logistically and legally) The Smoothwall Blog: 7 Ways To Deal With HTTPS traffic 1
Bruce123 Posted January 7, 2014 Author Posted January 7, 2014 Just a quick thought but do you tell your users that you decript and intercept their SSL data? Are there warnings about banking using school facilities etc? It seems mad doing online banking in school but you never know with some users. This among other things. I think what you are talking about is discussed here. Installing anything on someones own device is fraught with difficulty and I don't see a way around it. Totally possible to install a cert on school own devices but fraught with difficulty on user owned devices. (Both logistically and legally) The Smoothwall Blog: 7 Ways To Deal With HTTPS traffic This has been discussed and the staff/students are informed about it, I appreciate it's not ideal (I had the same thoughts on Internet banking myself) but it does enable us to filter on SSL enabled content. I think as you said for BYOD certificate SSL/TSL decryption/re-encryption doesn't seem practical. That may still leave some College managed Android devices. Thanks, Bruce.
Bruce123 Posted January 7, 2014 Author Posted January 7, 2014 Not 100% sure how your solution works, but could you use a real world certificate for the job? In this scenario it wouldn't because a new certificate would need creating on-the-fly for each SSL site visited by the end users....
pete Posted January 7, 2014 Posted January 7, 2014 Smoothwall (by default) doesn't decrypt traffic to banking websites - there's a specific "unless it's a banking website" exclusion turned on as-shipped. I suspect other vendors do something similar.
DMcCoy Posted January 7, 2014 Posted January 7, 2014 Is there a simple way to resolve this issue? No It's a MITM attack and devices should treat it as such.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now