Jump to content

Recommended Posts

Posted

Hi all,

 

We have a particular problem with certain devices and our wireless BYOD setup.

 

Essentially, users connect to an open network and authenticate via a captive portal (AD integrated) for Internet access.

 

The connection is filtered and goes out via a firewall at layer 3/4. All's OK apart from when the user tries to access an SSL enabled website. The firewall decrypts the SSL session, re-establishes an SSL session replacing the real certificate with a SSL certificate generated on-the-fly by the firewall. The problem is the BYOD devices don't trust the certificate (can't be verified) as they don't have root certificate installed.

 

Is there a simple way to resolve this issue? Is there any easy way to push out the root cert to user's devices? I wondered if we could place a copy of the root certificate on our website, that users could be instructed to download using the URL e.g. go to website.com/root.cert?

 

I know one way is to copy the certificate to the SD card, but our users would find this too complicated.

 

Any advise is much appreciated.

 

Many Thanks,

 

Bruce.

 

PS The connection goes via Bloxx (filtering) and Watchguard (firewall) but I can't quite remember which is performing the SSL decryption/re-encryption.

Posted

Just a quick thought but do you tell your users that you decript and intercept their SSL data? Are there warnings about banking using school facilities etc? It seems mad doing online banking in school but you never know with some users. This among other things.

 

I think what you are talking about is discussed here. Installing anything on someones own device is fraught with difficulty and I don't see a way around it. Totally possible to install a cert on school own devices but fraught with difficulty on user owned devices. (Both logistically and legally)

 

The Smoothwall Blog: 7 Ways To Deal With HTTPS traffic

  • Thanks 1
  • 4 weeks later...
Posted
Just a quick thought but do you tell your users that you decript and intercept their SSL data? Are there warnings about banking using school facilities etc? It seems mad doing online banking in school but you never know with some users. This among other things.

 

I think what you are talking about is discussed here. Installing anything on someones own device is fraught with difficulty and I don't see a way around it. Totally possible to install a cert on school own devices but fraught with difficulty on user owned devices. (Both logistically and legally)

 

The Smoothwall Blog: 7 Ways To Deal With HTTPS traffic

 

This has been discussed and the staff/students are informed about it, I appreciate it's not ideal (I had the same thoughts on Internet banking myself) but it does enable us to filter on SSL enabled content.

 

I think as you said for BYOD certificate SSL/TSL decryption/re-encryption doesn't seem practical.

 

That may still leave some College managed Android devices.

 

Thanks,

 

Bruce.

Posted
Not 100% sure how your solution works, but could you use a real world certificate for the job?

 

In this scenario it wouldn't because a new certificate would need creating on-the-fly for each SSL site visited by the end users....

Posted

Smoothwall (by default) doesn't decrypt traffic to banking websites - there's a specific "unless it's a banking website" exclusion turned on as-shipped.

 

I suspect other vendors do something similar.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...