Warwick_Tech Posted October 25, 2019 Posted October 25, 2019 Hey All, Our darlings have discovered a loophole in our BYOD in that it only has basic certificate inspection and not full SSL inspection to block those hiding in plain sight. I've contacted our web filter guys but in the meantime I would like to try and get the SSL certificate on their devices so I know it's working. Two methods I've tried; 1. Captive portal - Problem was there was nowhere to upload the certificate 2. Unifi Guest Portal - again, nowhere to set the certificate I was thinking of a link on the schools website to download the certificate and then lock access there until it was installed, but I'm not sure how practical this is. I don't mind them finding loopholes, but when they're on the guest WiFi it replies on vigilant staff and students to report naughtyness. How do you guys handle SSL encryption via guest WIFI?
robyholmes Posted October 25, 2019 Posted October 25, 2019 Captive portals in including UniFi allow you to redirect to a certain URL. We just point then to the Smoothwall certificate page. However you could host your own if you wanted.
Warwick_Tech Posted October 28, 2019 Author Posted October 28, 2019 Captive portals in including UniFi allow you to redirect to a certain URL. We just point then to the Smoothwall certificate page. However you could host your own if you wanted. so is the certificate page hosted on the smoothwall? Isn't that a 'local' address so if you VLAN your guest traffic it can't see it? I don't think there's a risk of having the certificate accessible globally (schools website for example) or might that cause problems....
Synkrox Posted December 2, 2019 Posted December 2, 2019 We were with WCC until recently with their smoothwall/BYOD setup. I made them aware of this nearly 2 years ago when I started working in Warwickshire. I don't go in for publicly naming, but a chap at WCC with initials S.H. along with his superiors are totally aware that this hole existed and I have paperwork to prove it. We dropped them, ripped out all their gear and now use our own, Ultimately we use explicit proxy with basic authentication as it's the easiest way of doing the SSL filtering without installing certificates to clients. Students manage to follow the instructions pretty well. PM me if you want to discuss further, happy to share my experience with them!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now