Jump to content

Recommended Posts

Posted

How does everyone deploy the SSL decryption certificate to BYOD devices? We allow students and staff to use their own devices on the schools wifi but we need to properly monitor the internet traffic and search’s on these devices.

 

Thanks

Posted
How does everyone deploy the SSL decryption certificate to BYOD devices? We allow students and staff to use their own devices on the schools wifi but we need to properly monitor the internet traffic and search’s on these devices.

 

Thanks

We use an internal captive portal via our ruckus system. The BYOD works like a hotel system where they join the SSID, browser pushes them to an internal landing page where the certificate is stored or they can continue to login.

 

A walled garden with Azure and Google URLs listed so that the devices don't report "no internet" issues.

 

Once logged in they get pushed to our internal landing page which is actually a page on a Google Sites.

Posted
We use an internal captive portal via our ruckus system. The BYOD works like a hotel system where they join the SSID, browser pushes them to an internal landing page where the certificate is stored or they can continue to login.

 

A walled garden with Azure and Google URLs listed so that the devices don't report "no internet" issues.

 

Once logged in they get pushed to our internal landing page which is actually a page on a Google Sites.

 

Does it force the users to install the cert or can they carry on without it and not install the cert? Also do you use IIS for your landing page or is it part of Ruckus

Posted (edited)
Does it force the users to install the cert or can they carry on without it and not install the cert? Also do you use IIS for your landing page or is it part of Ruckus
It doesn't force users to install it, they can carry on to the login page to be authebticated against the Smoothwall.

 

They have to download the cert and install it themselves. I tried to get a .bat file to install the cert but it never progressed. I have an alternate link which points to the Smoothwall too as a backup location to get the MITM cert.

 

I use WAMP on an internal server. It's a very simple HTML page. Once they click continue there is a custom form where the AD details are passed to Ruckus for Authentication.

 

If the user does not install the cert, they will get HTTPS errors though the sites in the Proxy Exceptions list on the Smoothwall will work and display correctly without any HTTPS errors.

 

It now might be a case of asking yourself if BYOD is now pointless if users aren't going to install the cert and set a rule so that HTTPS sites not get inspected on BYOD SSIDs and put it down on your risk register. Or, only have guest wifi available and students need to use only school owned devices.

Edited by timbo343
Posted

There’s also the privacy concerns.

You’ll find a lot of sites will not function correctly with SSL Interception enabled E.G Banking. Yes there is risk of malicious content being reachable.

 

I think Android will constantly tell the use that a MITM cert is in use.

Posted
There’s also the privacy concerns.

You’ll find a lot of sites will not function correctly with SSL Interception enabled E.G Banking. Yes there is risk of malicious content being reachable.

 

I think Android will constantly tell the use that a MITM cert is in use.

 

Thanks. All our students bring in and use their own MacBook so at the moment we can use the alerts on the firewall to notify our safeguarding team when they are searching things on the internet due to the SSL decryption cert not on their devices. This means we are not able to effectively monitor them as per the recent KCSIE changes unless anyone else know of a better way to monitor BYOD clients?

Posted (edited)
Thanks. All our students bring in and use their own MacBook so at the moment we can use the alerts on the firewall to notify our safeguarding team when they are searching things on the internet due to the SSL decryption cert not on their devices. This means we are not able to effectively monitor them as per the recent KCSIE changes unless anyone else know of a better way to monitor BYOD clients?
Deploying the MITM certificate isnt going to give you the "monitor' aspect of KCSiE. At that point, depending on what monitoring solution you are using, you'll probably have to get the student to install the monitor application.

 

The MITM will offer the ability to see inside searches but true monitoring needs another application.

 

You'll probably find that students will get annoyed by the certificate not being on their device so they'll set up hotspots via their phones. After all, it's their own device and they can do what they want with it. Do you stop students using their own data on their phones?

 

I feel that the whole KCSiE only applies to school owned devices and if a student does not want to install the MITM certificate, that is their choice but not installing it will mean they wont be able use the net in school, which begs the question, has BYOD now met it's day?

Edited by timbo343
  • Thanks 1
Posted
MITM means you can see all https data, why doesn't that mean you can monitor?
Monitor means track what the user types in an online word document or a comment.

 

The HTTPS cert doesn't look at this level, it looks at searches, url and DNS but if a student types in how to make a bomb on a chat or something then you will not be notified about the alert.

Posted
Why not?, you can decrypt everything they send and receive
Filter isn't monitor, they are 2 different things. By putting the MITM cert on on a device doesn't mean to say you are 100% conforming to the monitor standards.

 

Smoothwall have a webinar on the 16th October which i advise you and your DSLs to watch / partake in. https://smoothwall.zoom.us/webinar/register/WN__TmuHFAJRCK1Iq9OVsoKOA?utm_content=266710037&utm_medium=social&utm_source=facebook&hss_channel=fbp-122077641210875#/registration

Posted
Filter isn't monitor, they are 2 different things. By putting the MITM cert on on a device doesn't mean to say you are 100% conforming to the monitor standards.

I would say it depends on your definition of monitor. And KCSIE isn't explicit. Having MITM means you can see searches, sub pages and videos being looked at, Smoothwall can alert on suspisious things. It isn't just filtering it, it may even not block some things, but it can alert the DSL.

Posted
BYOD I think is moving towards relaxing restrictions and increasing guidance on how to stay safe , Pinterest for example has the risk of adult content but they are using it at home for school work.
Posted

I wouldn't bother deploying an SSL cert for BYOD devices; it's pointless to some extent.

 

What I would do is create 2 seperate SSIDs - one for staff and the other for pupils with RADIUS authentication.

 

Create 2 VLANS on your switches - one for staff and the other for pupils, and assign them accordingly to your SSIDs.

 

On your firewall, create 2 rules and add all the categories etc that require blocking and attach relevant AD groups to your rules. Don't forget to add your VLANS to this.

 

You will find this will be a much better option.

 

Apologies if this is a little sparse, but I set this up a while ago and I don't have access to give you a complete rundown of how I did it.

Posted
I would say it depends on your definition of monitor. And KCSIE isn't explicit. Having MITM means you can see searches, sub pages and videos being looked at, Smoothwall can alert on suspisious things. It isn't just filtering it, it may even not block some things, but it can alert the DSL.

 

You could run your own instance of a browser and get almost exactly what the user gets if you really wanted to

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...