chazzy2501 Posted January 6, 2015 Posted January 6, 2015 I've just set it up and although it seems to work fine, I'm a little confused. So I've added the RM cert to the trusted root of every PC & I've redirected to the new "sslfilter.proxy.swgfl.org.uk:8080". Now when I go to a https site I was expecting to see an RM cert on the padlock. I don't though, it looks normal, the cert chain goes to godaddy or where ever. Am I wrong...
plexer Posted January 6, 2015 Posted January 6, 2015 If it's working correctly and interception has happened you should see the RM cert and root CA in the chain. Ben
speckytecky Posted January 7, 2015 Posted January 7, 2015 Glad I'm not the only one who looked at the message and thought, what the heck Bain't going to get no award from the Plain English Campaign is it!! I've just set it up and although it seems to work fine, I'm a little confused. So I've added the RM cert to the trusted root of every PC & I've redirected to the new "sslfilter.proxy.swgfl.org.uk:8080". Now when I go to a https site I was expecting to see an RM cert on the padlock. I don't though, it looks normal, the cert chain goes to godaddy or where ever. Am I wrong...
Oaktech Posted January 7, 2015 Posted January 7, 2015 I was given a date of the 15th for switch on... I've made all the changes, so I'm just waiting to see what goes wrong.
Boredguy Posted January 7, 2015 Posted January 7, 2015 Just get ready for the influx of staff who can't remember their password for the proxy bypass once you updated the server they are going through. We updated our GPO's over the break and I've had to reset several staff proxy logins as they could not remember their password
JGoswell Posted January 9, 2015 Posted January 9, 2015 It’s good to see that you are all preparing your networks ahead of the changes proposed by Google. Our preparations for starting SSL interception for Google searches are going well. At the moment we have not made our change and neither has Google which is why you have not seen any difference. Google haven’t defined a date for this switch over to happen and still state ‘mid-January’, so with this in mind we are planning a staggered approach to switching customers on to the new SSL service, ensuring a smooth transition for all. As we speak with schools and receive their confirmation that SSL certificates have successfully deployed, we will move them over. If you are happy to be moved onto the new service now, please call 01235 826263 and we’ll arrange to do so. It will help us to ensure a more staggered transition and quickly make changes if necessary. If you have any further questions please call us on 0123582626 3
snagrat Posted January 9, 2015 Posted January 9, 2015 Will the old proxy servers still work after the change then (obviously without the SSL interception bit) or will they be disabled?
witch Posted January 9, 2015 Posted January 9, 2015 I've done mine other than the 32 netbooks that have to be done individually - yay!!
Edu-IT Posted January 9, 2015 Posted January 9, 2015 It’s good to see that you are all preparing your networks ahead of the changes proposed by Google. Our preparations for starting SSL interception for Google searches are going well. At the moment we have not made our change and neither has Google which is why you have not seen any difference. Google haven’t defined a date for this switch over to happen and still state ‘mid-January’, so with this in mind we are planning a staggered approach to switching customers on to the new SSL service, ensuring a smooth transition for all. As we speak with schools and receive their confirmation that SSL certificates have successfully deployed, we will move them over. If you are happy to be moved onto the new service now, please call 01235 826263 and we’ll arrange to do so. It will help us to ensure a more staggered transition and quickly make changes if necessary. If you have any further questions please call us on 0123582626 Can schools start to use the new proxy addresses (sslfilter.blah) even if they haven't been moved over? @snagrat I'd expect the old proxy.blah addresses to work regardless, with the proviso that they don't filter Google. The way it's worded on the RM site suggests this but it's not recommended.
snagrat Posted January 9, 2015 Posted January 9, 2015 Can schools start to use the new proxy addresses (sslfilter.blah) even if they haven't been moved over? @snagrat I'd expect the old proxy.blah addresses to work regardless, with the proviso that they don't filter Google. The way it's worded on the RM site suggests this but it's not recommended. I checked one school and the sslfilter and sslfilter.staffproxy worked without the SSL certificate installed, or without being moved over.
FragglePete Posted January 9, 2015 Posted January 9, 2015 Did mine via the GPO method today. Script worked quite nicely. You can test the cert is installed by going to RM SafetyNet - SSL Filtering Certificate Test - (I think that was it). Pete 1
JGoswell Posted January 11, 2015 Posted January 11, 2015 Our old proxy servers will be left running as not all schools wish to have their traffic SSL intercepted. Also it gives the option for schools to have student users filtered by the SSL proxy, but have staff users on the non-SSL proxy (some schools may not want to have staff traffic intercepted).
divadiow Posted January 13, 2015 Posted January 13, 2015 are you all just using the VB script to create the object and link it at the top level or are you importing the certificate into the Default Domain Policy? I know it doesn't matter, but I cant make up my mind what I prefer for neatness across existing installs and automated builds to come
Boredguy Posted January 13, 2015 Posted January 13, 2015 We created a new policy and applied the certificate to it and then assigned it to stations instead of editing the Default Domain Policy. Also when we did it, RM had not provided the script but just the certificate file and notes.
divadiow Posted January 13, 2015 Posted January 13, 2015 was there a specific reason for not wanting in the default domain policy?
Boredguy Posted January 13, 2015 Posted January 13, 2015 For us it was just easier to use a custom policy so that if we move away from SWGfL at the end of our current contract, a GPO saying "RM Safetynet Certificate" is easier to spot than having to remember to dig into the domain policy to delete the certificate.
divadiow Posted January 13, 2015 Posted January 13, 2015 good point. locating for automated removal and updating with new policy contents if need be too
speckytecky Posted January 22, 2015 Posted January 22, 2015 Umh - after a timely prompt from RM been trying to sort this one today. Not so far successful. Our main DC is Server 2008 Standard 32 bit (As the flipping tin won't install IE11 and IE11 has deployed to clients that's an issue) and it seems that this option isn't available for that. We also have a second DC that's Server 2008 R2 64 bit so it's that one I tried to install the certificate through. The VBS ran ok but when it comes to search for the actual certificate it's not visible?
witch Posted January 22, 2015 Posted January 22, 2015 I thought RM offered support?I'm sure the original email said to contact them if you were having trouble? (TBH I just followed the install instructions and it all worked on my 2008R2 server)
Boredguy Posted January 22, 2015 Posted January 22, 2015 Do you have the RMEducationCA.cer file, if so you can follow the manual instructions for adding it into a GPO
Michael Posted January 22, 2015 Posted January 22, 2015 Just a thought (without sounding negative), but aren't we all trying to fight a losing battle with regards to encryption? The amount of processing power needed to unencrypt every single Google Search made is going to be huge. What happens when other search engines or websites in general introduce the same encryption technologies? And how many certificates could we all end up deploying for every single website? Thoughts on this would be welcome 1
Boredguy Posted January 22, 2015 Posted January 22, 2015 Well the certificate is this instance is for the RM Safetynet, not specifically for Google. It's the RM filtering software that is doing the decrypting not devices school side.
Michael Posted January 22, 2015 Posted January 22, 2015 As you can probably tell, I'm just very sceptical of what is actually achieved from this. Going to the extreme, how are the likes of intelligent agencies going to respond to these Google policies? When you make Google Searches at home, all requests will be encrypted. I think it's important to highlight that your search criteria in Google itself is encrypted, but lets just say your search criteria was 'bbc'. Searching of the words 'bbc' would be encrypted, but then it would be possible to view/track that you viewed the BBC website thereafter from the requests your computer makes. That's essentially how intelligent agencies would go about it, looking at logs on your computer and the IP address of your computer etc... So the question is, is it really relevant what you search within Google, when you can see afterwards what websites were visited using existing monitoring systems? 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now