Jump to content

Recommended Posts

Posted

Hello

 

We have recently set up our lightspeed to work in proxy mode - we are only proxying a select list of site. This is so that we can intercept https pages such as google searches to filter and report on them.

 

However the lightspeed box seems to only be able to generate SHA1 certificates. SHA1 has been deprecated in Google Chrome so that if you go to a page with a SHA1 certificate it will flag up a warning message and show red in the URL.

 

We are on the version 2 lightspeed firmware and don't want to have to go to version 3 as it's still in a release candidate state.

 

Has anyone else seen this problem and do they have any strategy to deal with it? Any they just telling users to ignore it or is there some setting that we've missed.

 

Dan

Posted (edited)

What have the support team said about this?

 

I ask because we are doing exactly what your doing in the next half term and if their isn't a workaround, no chance we are doing it.

Edited by mukz
Posted
What have the support team said about this?

 

I ask because we are doing exactly what your doing in the next half term and if their isn't a workaround, no chance we are doing it.

 

If you have chrome you need to do it before the end of January or not update Chrome. A Chrome update is due and it will start throwing warnings on pages to SHA 1 certificates.

Posted
What have the support team said about this?

 

I haven't been dealing with this directly but the support team seemed to imply that this is the just the way it is and there is no fix. The version 3 firmware might be it but when the techs here tried it they said it was horribly broken at the moment.

 

 

If you have chrome you need to do it before the end of January or not update Chrome. A Chrome update is due and it will start throwing warnings on pages to SHA 1 certificates.

 

This is tricky. The lightspeed box generates the replacement certificates. So the first time a user visits a https site a cert will be generated - so it will have a validity past 2015 and therefore trigger the warning.

Also chrome version 42 was the version that implemented the warnings about sha1 - this was released in 2015, currently my chrome is on version 55. Chrome also auto updates - so installing a set version isn't so simple.

Posted
I haven't been dealing with this directly but the support team seemed to imply that this is the just the way it is and there is no fix. The version 3 firmware might be it but when the techs here tried it they said it was horribly broken at the moment.

 

 

 

 

This is tricky. The lightspeed box generates the replacement certificates. So the first time a user visits a https site a cert will be generated - so it will have a validity past 2015 and therefore trigger the warning.

Also chrome version 42 was the version that implemented the warnings about sha1 - this was released in 2015, currently my chrome is on version 55. Chrome also auto updates - so installing a set version isn't so simple.

 

42 put the warning in 56 will put the big warning on the screen.

 

If I was you I would see if you can replace it over the weekend. Shouldn't take long to do.

Posted

Thanks to this post we were contacted by a member of lightspeed support. They organised a time with us to apply a patch to our lightspeed box and we now have it correctly generating sha256 certificates.

So everything is awesome!

Posted
Thanks to this post we were contacted by a member of lightspeed support. They organised a time with us to apply a patch to our lightspeed box and we now have it correctly generating sha256 certificates.

So everything is awesome!

Has it made the red crossed out HTTPS go back to green (or at least grey)?

 

I'm on Lightspeed 2 and currently Chrome 55 so just hope they don't update themselves to 56 if that brings up a full screen warning on every site that goes through the proxy!

 

I tried version 3 at the start of the year as I was told how wonderful it would be, no end of problems, the main being the user agent for v3 is different to v2, and once installed didn't seem to be bothering to contact the filter at user logon so every time anybody opened a browser they were repeatedly prompted for credentials. They pushed out fixes but while it sort of fixed the authentication it broke reporting, gave up and went back to v2.

So if they managed to update your v2 to generate decent certificates I'll get onto them in the morning and get mine sorted out.

Posted
Contacted Lightspeed today - and just for anyone else who might have the same problem, there is a patch for v2 but you have to manually request it to be installed - I mentioned it was to do with SHA1 which prompted them to offer the patch straight away (does not appear in the updates list within the lightspeed management page), and requires the proxy service to be restarted meaning a couple of seconds downtime.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...