Jump to content

Recommended Posts

Posted

Hello,

 

Chrome has started moaning that one of our certificates doesn't have any subject alternate names. It doesn't need any!

 

Has anyone else seen this please?

 

Thanks

Posted
Yep, having fun here with it. Have downloaded the latest Chrome ADMX files and updated central policy store, then set the "Whether to allow certificates issued by local trust anchors that are missing the subjectAlternativeName extension" to enabled. Now it asks you to login when you try to access intranet homepage, so have sent out email telling staff that it's fine to put username in in this situation but at least they can get to it. Fun.
Posted
It's issues like these that assure me that certificate-less SSL/TLS filtering is the absolute best way to go. Why waste time and bandwidth dealing with loading and staying up to date with 3rd party certs when there are solutions out there that filter as good, if not better, without having to inspect HTTPS traffic? Seems a bit silly to me to not only waste time, but to also bring about security issues with "trusted" MITM approaches...
Posted
It's issues like these that assure me that certificate-less SSL/TLS filtering is the absolute best way to go. Why waste time and bandwidth dealing with loading and staying up to date with 3rd party certs when there are solutions out there that filter as good, if not better, without having to inspect HTTPS traffic? Seems a bit silly to me to not only waste time, but to also bring about security issues with "trusted" MITM approaches...

 

I am not using SSL filtering and have this issue.

Posted
It's issues like these that assure me that certificate-less SSL/TLS filtering is the absolute best way to go.

 

Can you expand on what certificate-less SSL/TLS filtering is and how we might go about implementing it on a typical school network?

Posted
I am not using SSL filtering and have this issue.

 

That doesn't make much sense, as certificates are only used for SSL/TLS (HTTPS) traffic. I don't see how you would be getting a certificate error if you aren't using certificates?

Posted
That doesn't make much sense, as certificates are only used for SSL/TLS (HTTPS) traffic. I don't see how you would be getting a certificate error if you aren't using certificates?

 

I didn't say I wasn't using the certificates, I said im not using HTTPS filtering. :)

 

They have been issued by my own internal CA for use on Intranet websites.

Posted

So I had a quick look and Aristotle seems to be an Impero style product and utilises a client to do the filtering? Can't say I'd be too chuffed with that. What about guests or large byod schemes?

 

The website over eggs the complexity of traditional filtering solutions. SSL decrypt and inspect isn't that difficult or expensive (resource wise). This issue is irritating but ultimately will blow over. Filter providers will sort it out and Chrome users can use a different browser for a bit. No biggie.

 

I would hazard a guess that there is a reason that all major filtering providers do it the traditional way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...