Edu-IT Posted December 5, 2014 Posted December 5, 2014 (edited) Lightspeed have confirmed Google have made the changes yesterday it seems. "Back in October, we informed you that Google was planning to move all of their servers to encrypted-only that will always enforce Safe Search. This change-over has happened today." Edited December 5, 2014 by Edu-IT 1
X-13 Posted December 5, 2014 Posted December 5, 2014 Just did a quick google search, it's not HTTPS... RM Safetynet is still triggering as well. [Google images "bloop"... not sure WHY it's getting flagged.]
localzuk Posted December 5, 2014 Posted December 5, 2014 Yeah, I'm still getting non-https here on SWGfL (RM). However, it does something different now - it redirects via the SSL service, ie. https://www.google.co.uk appears in the address bar, then changes to http. Also, the "You're not using SSL" orange/brown box on the right has disappeared.
tom_newton Posted December 5, 2014 Posted December 5, 2014 Not seen the change myself yet: annoyingly these do tend to roll out piece-meal. FWIW, it is not possible to redirect users to another site - you need to MitM to do that as well, which is why the Smoothwall blockpage MITMs on HTTPS regardless of what you have set up. The only way to keep functionality is to MitM, and you will really need to push a cert for that. You can do this with a transparent proxy too, so no need for wpad/proxy.pac, contrary to popular opinion 1
plexer Posted December 5, 2014 Posted December 5, 2014 It depends on your environment. If you want to monitor google searches you need to be using SSL interception. This will in most cases incur cost. The web is moving to SSL more and more. In a environment like FE and HE you can not have interception on guest devices but be aware of the implications. Can't stop exe download where they are hosted on SSL Connections. Monetary cost or time? It's not really going to cost money to implement this. Ben
foofighterjim Posted December 5, 2014 Posted December 5, 2014 Not seen the change myself yet: annoyingly these do tend to roll out piece-meal. FWIW, it is not possible to redirect users to another site - you need to MitM to do that as well, which is why the Smoothwall blockpage MITMs on HTTPS regardless of what you have set up. The only way to keep functionality is to MitM, and you will really need to push a cert for that. You can do this with a transparent proxy too, so no need for wpad/proxy.pac, contrary to popular opinion Hi @tom_newton I am currently reviewing our filtering solution and are looking at Smoothwall. In light of these changes is there any official documentation on this type of setup?
tom_newton Posted December 9, 2014 Posted December 9, 2014 YEs - there's the user manuals, but better than that, when you move to Smoothwall, do a planning call with one of our techs (this is SOP, so no need to even ask!), and they will make sure you are on the same page with regard to certificates, proxies, transparent filtering etc. 1
JGoswell Posted December 9, 2014 Posted December 9, 2014 Google moving all search results behind SSL encryption is providing a tough challenge to many filtering providers. We have plans in place to manage our customers through this change and our initial response and top level plan for SafetyNet+ can be found here: Changes to Google SSL and RM Safetynet Plus | RM Education - What we do We will be issuing further communications on the subject and opening a specific support line later this week. A separate change was made recently by YouTube to also use SSL encryption, this was unexpected and we are now reviewing how we build this into our future plans for SafetyNet+. If you are a SafetyNet user and you have any immediate concerns then please call your support line and we will assist you. As a responsible supplier of E-Safety products we are making every effort to deliver an effective solution for our SafetyNet+ users quickly. Our solution is currently being trialled with early adopters pending a full release in January.
X-13 Posted December 15, 2014 Posted December 15, 2014 So, I've FINALLY got something official from LEA about this... ATM they're saying YouTube is unfiltered because Google changed it without telling anyone and at some point we're going to get access to a certificate for RM to enable SSL interception. How hard is it to push out certs?
localzuk Posted December 15, 2014 Posted December 15, 2014 You can deploy certificates via GPO - so not a huge issue for machines on your network. The issue comes for BYOD type devices. My plan is to redirect users to an instruction page after captive portal login on our guest wifi - Ruckus seems to be able to do this.
X-13 Posted December 15, 2014 Posted December 15, 2014 You can deploy certificates via GPO - so not a huge issue for machines on your network. The issue comes for BYOD type devices. My plan is to redirect users to an instruction page after captive portal login on our guest wifi - Ruckus seems to be able to do this. Oh, cool. We don't have BYOD here, so it's not really an issue. The only Android/iOS devices are Learnpads [~1 year in my office unused], staff android tablets for an EYFS app and work phones [mostly iOS IIRC]. So I may be able to get away with not touching them...
edutech4schools Posted December 16, 2014 Posted December 16, 2014 Lucky I stumbled on these posts as SEGFL have nothing on their website and none of the schools I look after have been informed.
IrritableTech Posted December 18, 2014 Posted December 18, 2014 Is anyone in the UK able to confirm if this change has now been made? Our nosslsearch.google.com hack seems to have stopped working this morning. The RM info suggested that it wasn't going to happen until January - although I'm not sure where they got that info from.
Steve21 Posted December 18, 2014 Posted December 18, 2014 Aye anyone had any updates on this certificate that's been released etc? Steve
IrritableTech Posted December 18, 2014 Posted December 18, 2014 I'm not actually with RM - but there is a download for 'windows networks' on this page... Changes to Google SSL and RM Safetynet Plus | RM Education - What we do 2
Steve21 Posted December 18, 2014 Posted December 18, 2014 I'm not actually with RM - but there is a download for 'windows networks' on this page... Changes to Google SSL and RM Safetynet Plus | RM Education - What we do Doh thanks
X-13 Posted December 18, 2014 Posted December 18, 2014 I'm not actually with RM - but there is a download for 'windows networks' on this page... Changes to Google SSL and RM Safetynet Plus | RM Education - What we do Cheers for that. I don't seem to be getting updates about this...
localzuk Posted December 18, 2014 Posted December 18, 2014 I don't think the work is complete yet - at least, the SWGfL server name for their normal proxy doesn't seem to resolve to an IP address from here. There doesn't appear to be any info on the SWGfL EIS site any more about this - other than the current broken Youtube issue. What was there originally has disappeared.
IrritableTech Posted December 18, 2014 Posted December 18, 2014 I don't think the work is complete yet - at least, the SWGfL server name for their normal proxy doesn't seem to resolve to an IP address from here. There doesn't appear to be any info on the SWGfL EIS site any more about this - other than the current broken Youtube issue. What was there originally has disappeared. Are you still searching without SSL on google then @localzuk ? We were, until this morning - and I don't think my supplier has changed anything - we've still got the DNS hack in place.
localzuk Posted December 18, 2014 Posted December 18, 2014 Yeah, its still using HTTP here. Something has changed somewhere though, as we used to get a yellowy box on the right saying we were using the No SSL service and giving us some form of warning. That box has disappeared, and the URL now goes to https://www.google.co.co.uk first then seems to redirect over to Google after that. 1
Edu-IT Posted December 18, 2014 Posted December 18, 2014 Err: RM SafetyNet - SSL Filtering Certificate Test Confirms the certificate is installed. It isn't. I don't use RM. Anyone else get this?
IrritableTech Posted December 18, 2014 Posted December 18, 2014 Err: RM SafetyNet - SSL Filtering Certificate Test Confirms the certificate is installed. It isn't. I don't use RM. Anyone else get this? Failed for me when I tested it.
localzuk Posted December 18, 2014 Posted December 18, 2014 Err: RM SafetyNet - SSL Filtering Certificate Test Confirms the certificate is installed. It isn't. I don't use RM. Anyone else get this? Fails for me (except on the 1 PC I've deployed the certificate to, where it works).
synaesthesia Posted December 18, 2014 Posted December 18, 2014 Silly question time. What's the actual problem with this? Does SSL searching only cause a problem for particular firewalls/filters? Whatever I do, the searching works absolutely fine here, it's definitely over SSL, Impero still reports the full search string; am I missing something?
Steve21 Posted December 18, 2014 Posted December 18, 2014 Silly question time. What's the actual problem with this? Does SSL searching only cause a problem for particular firewalls/filters? Whatever I do, the searching works absolutely fine here, it's definitely over SSL, Impero still reports the full search string; am I missing something? It's the filtering side, as they're forcing full SSL searches it can't be filtered by most providers (RM in this point) currently without installing certs locally. Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now