Jump to content

Recommended Posts

Posted

Still waiting for a response from the SWGfL over this since Feb with regards our BYoD users not having a certificate on their devices.

 

Heck they didn't even update their installation notes for putting the certificate onto Windows phones in the last 4 months *grumble*

Posted

Cheers, been getting all my schools ready but bet it borks. RM have given me 6 different proxy server addresses so far. Every time I call them they say 'oh you should not be using that proxy address, I will give you the correct one', and the next time I call they say the same thing. Also needed to setup staff proxy as unfiltered.proxy.school.....sch.uk will not work.

 

fingers crossed.

Posted

unfiltered.proxy disappeared years ago.

According to their paperwork you should be using sslfiter.staffproxy.blah

 

In the Safetynet Deployment guide they have a list of all the old proxys and what you should be using now instead.

Posted

There doesn't seem to be any nice option in regards to BYOD, even been talking to a few firewall/filtering companies and basically it's add certificate to devices, block HTTPS (Google) on them, or hope :)

 

I'm curious to know what happens to devices without the cert once you change over proxies though :p Haven't been able to test it as obviously it's not working yet.

 

Steve

Posted
unfiltered.proxy disappeared years ago.

 

Still works and was told to use it on my servers

 

In the Safetynet Deployment guide they have a list of all the old proxys and what you should be using now instead.

 

That was the first proxy address I used but it was while talking to them on the phone about setting up staff proxy that they told me to try a different proxy, and so the magical mystery proxy address tour started.

 

Anyway I have tested, just not deployed the updated proxy address to all computers via gpo yet.

Posted

We were always told to use update.proxy on the servers as it allowed the common exes & zips through for things like AV updates, but unfiltered was pulled around 10 years ago for us when the proxy bypass feature came in.

 

Looks like tomorrow could be fun, although I can redirect all our BYoD users to a nag page about installing the certificate

Posted
There doesn't seem to be any nice option in regards to BYOD, even been talking to a few firewall/filtering companies and basically it's add certificate to devices, block HTTPS (Google) on them, or hope :)

 

I'm curious to know what happens to devices without the cert once you change over proxies though :p Haven't been able to test it as obviously it's not working yet.

 

Steve

 

If you try to man in the middle a device that doesn't have your proxys cert it will give a warning and if the user chooses to continue then you will de-crypt their ssl traffic, all adding your cert does it make this all transparent to the end user.

 

Ben

  • Thanks 1
Posted (edited)

IE will come up with a warning, but you can continue anyway chrome you wont get anywhere with it, android phones that have the internet app and not chrome will work (with a prompt about security), unsure about chrome app itself on an android phone.

 

firefox allows you to add an exception manually.

Edited by Tesla
  • Thanks 1
Posted
If you try to man in the middle a device that doesn't have your proxys cert it will give a warning and if the user chooses to continue then you will de-crypt their ssl traffic, all adding your cert does it make this all transparent to the end user.

 

Ben

 

Sorry what I meant is for example is there actually any point installing it on all servers etc, apart from a warning, i'm assuming it wouldn't block any services/traffic if it doesn't have the cert? Just don't really see the need for the change in proxy settings if it won't do "something" as you could just use it on the original ones surely?

 

Steve

Posted
For BYOD, we've had to go with the rather clunky "captive portal redirect to different site after login" method. So, basically, when a user connects to our BYOD wireless, they log in via captive portal and then instead of the site they wanted, they get redirected to a page with instructions to install the certificate and an explanation. I've created instructions for iOS, Android, Windows Phone, ChromeOS and Windows. I've not done OS X yet but I'm sure I will add it soon enough!
Posted
What stops them just ignoring the page, and using it unfiltered though?

 

Steve

 

There is no unfiltered? The only difference is whether they end up with a security warning or not every time they use Google.

Posted
There is no unfiltered? The only difference is whether they end up with a security warning or not every time they use Google.

 

From tomorrow they can't filtering Google so it'll be unfiltered? That's the whole purpose of the Cert etc.

 

Therefore from June 24th, unless you take action, Google search results will not be filtered by RM SafetyNet Plus.

 

Steve

Posted
From tomorrow they can't filtering Google so it'll be unfiltered? That's the whole purpose of the Cert etc.

 

Steve

 

That's not what happens. All traffic on our network has to go via our proxy server. Our proxy server connects to sslfilter.proxy.swgfl.org.uk.

 

Therefore, the only issue is whether users install the certificate to get rid of the security warning or not.

 

End users aren't making proxy changes - there's no need for users to be touching any proxy settings any more with transparent proxies and the like.

Posted

Basically the new proxy addresses SWGfL provide will intercept and filter google on https. The old proxy addresses will not. So if you don't change to using the new proxy details, SWGfL are stating the content will not be filtered as per 'unless you take action, Google search results will not be filtered by RM SafetyNet Plus'.

 

As @localzuk says, the certificate is to give the user a transparent experience without the security warning.

Posted

I know that should be the case, but why are RM even saying they'll have issues with BYOD filtering when we asked them about that then? Thus the question there's got to be something that's different else they'd just switch the normal proxies over and we wouldn't need to change our upstreams etc?

 

Steve

Posted
I know that should be the case, but why are RM even saying they'll have issues with BYOD filtering when we asked them about that then? Thus the question there's got to be something that's different else they'd just switch the normal proxies over and we wouldn't need to change our upstreams etc?

 

Steve

 

I don't understand the question really.

 

They're providing 2 options to customers:

 

1. Leave things as they are and Google will not be filtered by them (but SafeSearch will be enforced I believe, by Google).

2. Switch the SSLFilter, whereby you have to get the SSL cert installed everywhere, else users get a security warning. All requests are then still filtered, regardless of the warning or ssl cert installation.

Posted

The only issue with BYoD filtering is as @Boredguy mentioned, it's about the certificate installation. A security warning will confuse and worry some, also I can possibly imagine some apps not working without a valid certificate installed on some devices.

@Techie2000 I don't believe SafeSearch will work on the original/old proxy after the https switchover, as it would require modification of the https stream... but we will find out tomorrow.

Posted
(but SafeSearch will be enforced I believe, by Google).

 

The problem with that though, is that if people don't flag something as NSFW it will still potentially be shown in a safesearch...

 

I've seen massive arguments with artists over it on teh Tumblrs.

Posted
There doesn't seem to be any nice option in regards to BYOD, even been talking to a few firewall/filtering companies and basically it's add certificate to devices, block HTTPS (Google) on them, or hope :)

 

Would making your own internal search engine page be another option - have your DNS server point Google at a page that sends a search query off to google and returns the results to the user?

Posted
Might just as well update the DNS to point to Bing.. until Bing also goes for https searches only....

 

Considering bing harvests results from google, you potentially not losing anything.

 

Could be something to consider... much as I hate to admit it.

Posted (edited)

I know the maintenance window is till 8:30 but is it just me or is the old system still working fine? Just been playing and seeing what if anything breaks.

 

Go to Google and look at HTTPs cert, and whether it's on (IE/Firefox/Chrome) proxy. staffproxy. or sslfilter. all shows Google cert, no warnings/errors? (even on filtered results etc)

 

Steve

Edited by Steve21

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...