Jump to content

Recommended Posts

Posted

I thought I'd followed the instructions from RM - to the letter. However, the ...CA.cer file doesn't show?

 

Do you have the RMEducationCA.cer file, if so you can follow the manual instructions for adding it into a GPO
Posted

Ring them!

I have a file of stuff including the certificate I think but I can't add it here

Don't know if it is right but could send to an external email if you pm me

Posted

I have done that. They have a case running. Helpful I suspect that I have now actually downloaded and installed the flipping certificate. :rolleyes: Our network is a bit odd anyhow sometimes proxies don't get picked up already. I doubt this is going to make life any easier for me!

 

Ring them!

I have a file of stuff including the certificate I think but I can't add it here

Don't know if it is right but could send to an external email if you pm me

Posted
Just a thought (without sounding negative), but aren't we all trying to fight a losing battle with regards to encryption? The amount of processing power needed to unencrypt every single Google Search made is going to be huge. What happens when other search engines or websites in general introduce the same encryption technologies? And how many certificates could we all end up deploying for every single website?

 

Thoughts on this would be welcome :)

 

Well the certificate is this instance is for the RM Safetynet, not specifically for Google.

 

It's the RM filtering software that is doing the decrypting not devices school side.

 

You are only distributing the root CA certificate from the PKI however the web proxy devices will be generating certificates on the fly as intermediate CA's for each and every SSL website visited thus as the number of users and numbers of SSL websites increases then load on these devices will also increase.

 

Just something to stick in the back of your minds :)

 

Ben

  • Thanks 1
Posted
You are only distributing the root CA certificate from the PKI however the web proxy devices will be generating certificates on the fly as intermediate CA's for each and every SSL website visited thus as the number of users and numbers of SSL websites increases then load on these devices will also increase.

 

Just something to stick in the back of your minds :)

 

Ben

 

Exactly which proves the point I'm right, so why are LAs insisting on this? At that rate you could end up with a datacentre just for unencrypting secure traffic - hardly very 'green' now is it? :)

Posted

Well if you could go ask Google to stop being numpties and forcing all searches via SSL so filtering providers can continue to block material in the same manner as has been done for the last goodness knows how long, then we wouldn't have to deploy our root certificates to devices.

 

It's not the LA that are insisting on it @Michael but rather it's the chocolate mountain ;)

Posted
Hmm but correct me if I'm wrong, if I search for bbc, then visit/click on bbc.co.uk from an encrypted Google page, surely the web filters still kick in as if I had typed bbc.co.uk directly into the browser?
Posted

Google have now confirmed the change will be made in early February.

We have now called over 2000 RM SafetyNet customers and provided additional support and advice to over 1000 of these. It is reassuring to hear that a number of schools have already applied the certificates successfully. Our helpdesk will continue to contact customers as we head through this month.

Our preparations for starting SSL interception for Google searches are going well. As of today, Google still haven’t made their switch to HTTPS but they have now suggested the date will be at the beginning of February. With this in mind, RM Education is taking a staggered approach to switching customers on to the new SSL service, ensuring a smooth transition for all. As we receive confirmation that SSL certificates have successfully deployed, we will move schools over. If you are happy to be moved onto the new service now, please call 01235 826263 and we’ll arrange to do so. It will help to ensure a more staggered transition and quickly capture and resolve any potential issues.

The FAQs on our information page are being continuously updated so please keep checking back. Our Interception Policy document has also been updated.

A topic that has raised queries is around the different proxy settings you can use for different users. We have added some more detailed information regarding that. Transparent proxy has also raised questions, if you are a transparent proxy user please find further information in the FAQs.

To confirm what you need to do next:

• If you haven’t already, download and deploy the certificates at your earliest convenience.

• To check that your certificates have deployed, please visit this link on a range of devices across your network to ensure you get a positive result. If you receive an error, please call 01235 826263.

• If you have deployed your certificates successfully and would like to move to the new SSL proxy now, please call 01235 826263. Otherwise, we will switch you over as soon as Google make the change.

Don’t forget! If Google make this change and you haven’t yet deployed your certificates:

• Be mindful about search terms being used in Google. SafeSearch will be enforced but this is NOT equal to RM SafetyNet Plus filtering

• Consider switching to another search engine which hasn’t yet moved to HTTPS

• If the worst happens, and an inappropriate search result is returned, it will be filtered according to your normal RM SafetyNet Plus rules when the link itself is clicked.

RM Education

Posted

Posting this here, because I know RM are watching...

 

 

Does anyone know how to convert the .CRT to PEM?

 

I need the cert as a PEM for our Learnpads. It has to be pasted into a text box if that matters.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...