IrritableTech Posted December 18, 2014 Posted December 18, 2014 Well you've got impero which sounds like it is helping. I've written a blog about the potential safeguarding issues. It's not perfect, but may explain my concern. http://irte.eu/q6
localzuk Posted December 18, 2014 Posted December 18, 2014 Impero is not a "man in the middle" proxy - it is a client based program that operates in a very different way. All filtering solutions will have this issue, if they are proxy type services. The issue is that the filter has to decrypt the data, then re-encrypt it in order to process the page.
Edu-IT Posted December 18, 2014 Posted December 18, 2014 Failed for me when I tested it. Wonder if it's something to do with the ISP. Who are you with?
IrritableTech Posted December 18, 2014 Posted December 18, 2014 Wonder if it's something to do with the ISP. Who are you with? I'm not with RM and haven't installed the certificate - should have added that. That page should fail for me!
synaesthesia Posted December 18, 2014 Posted December 18, 2014 Righto. All seems fine here, safesearch is still forced, can't see an issue. Fortigate. (Surprising really, it's utterly crap at everything else!)
Edu-IT Posted December 18, 2014 Posted December 18, 2014 Righto. All seems fine here, safesearch is still forced, can't see an issue. Fortigate. (Surprising really, it's utterly crap at everything else!) I don't think Google have implemented SSL yet.
localzuk Posted December 18, 2014 Posted December 18, 2014 I don't think Google have implemented SSL yet. SSL has been implemented for ages! They just haven't turned off their nossl system yet.
synaesthesia Posted December 18, 2014 Posted December 18, 2014 looks secure to me, example search URL picked up by the fortigate is: https://www.google.co.uk/?gws_rd=ssl#safe=strict&q=test
IrritableTech Posted December 18, 2014 Posted December 18, 2014 Those who aren't getting SSL google, can you do me a favour? Can you tell me what IP address nosslsearch.google.com comes back with please?
IrritableTech Posted December 18, 2014 Posted December 18, 2014 Getting 216.239.32.20 here. Me too. I think that is the issue. My ISPs DNS server are set to 216.239.38.120. They've done it as an IP rather than a CNAME and the IP has changed... I think.
Edu-IT Posted December 18, 2014 Posted December 18, 2014 SSL has been implemented for ages! They just haven't turned off their nossl system yet. That is what I meant...!
Quackers Posted December 18, 2014 Posted December 18, 2014 I thought this happened months ago ? I'm all confused now, as we had an issue of google always using HTTPS earlier in the year and could not enforce safe search as a result. We had to implement SSL Inspection and push out the SSL to all clients.
IrritableTech Posted December 18, 2014 Posted December 18, 2014 I thought this happened months ago ? I'm all confused now, as we had an issue of google always using HTTPS earlier in the year and could not enforce safe search as a result. We had to implement SSL Inspection and push out the SSL to all clients. Nope - still ways around that, but you can sit smug in the knowledge that you've already done what we will probably need to do very soon! :-)
IrritableTech Posted December 18, 2014 Posted December 18, 2014 I've decided to post some further info in a forum which is for registered users only - it contains some potentially important advice for those who aren't doing HTTPS inspections. http://www.edugeek.net/forums/security/146987-google-safe-search.html 1
Steve21 Posted December 18, 2014 Posted December 18, 2014 Literally just got this through if anyones interested: Action required: changes affecting your Internet filtering Further information regarding your filtering - action required We have completed our development of the new functionality and a group of customers have tested the roll out of certificates. We have completed an instruction document for deploying SSL certificates on Windows networks; this is attached to the dedicated web page. The Windows SSL certificate is also now packaged and available for download and deployment, it can be found on the above web page. If you are comfortable with the deployment, then you are free to begin a roll out in your school, if you are unsure, please call us or wait for our team to make contact with you to offer help. The FAQ document here has been updated to include additional information on transparent proxy as this raised a number of queries. Our SSL helpdesk has now started to call all of our SafetyNet customers. They will make contact to find out if you need assistance with deploying the certificates. If you do, they will arrange a suitable time for an engineer to talk you through the process and answer any queries you may have. If you would like to speak to a support representative about this issue, please call 0808 1729 535. You may have noticed that late last week YouTube was moved behind SSL encryption, (this does appear to be a regional change so you may not have noticed). There is more information available in our technical article. We would like to reassure our customers that we are here to help and will continue to share more information and installation instructions as it becomes available. RM Education Steve 2
localzuk Posted December 18, 2014 Posted December 18, 2014 It appears that our LEA DNS servers aren't resolving the right addresses - so I've reported it to the LEA IT people - this will affect any schools using SWGfL via South West One in Somerset I think, as we all use SWO's DNS servers as our upstream servers.
DCUK6 Posted December 19, 2014 Posted December 19, 2014 OFSTED knows of this and will check/ask about your internet filter. Our LEA told us of a few schools that have ran into trouble because the LEA filter didnt block unsafe content.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now