Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-09-01 Thread Stanford Prescott
Thanks for the info, Rafael. Stan On Mon, Aug 31, 2015 at 11:39 PM, Rafael Akchurin < rafael.akchu...@diladele.com> wrote: > The SSL pinning means dropbox application does know the fingerprint of the > certificate of the connection out-of-band and will simply refuse to work > with another (even

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Rafael Akchurin
The SSL pinning means dropbox application does know the fingerprint of the certificate of the connection out-of-band and will simply refuse to work with another (even trusted one). It is not possible to change this behaviour without recompiling unless developers of dropbox has some "managed" mo

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Stanford Prescott
Yes, SSLBump still works with the web apps, but it would be a lot more convenient if the mobile apps would also work. Does anyone know how to pin Squid's self-signed certificate's public key to Googledrive and Dropbox so that it would work with SSLBump enabled? Stan On Mon, Aug 31, 2015 at 3:29

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 BTW, GoogleDrive web application still works with bump. Use it, Luke ;) 01.09.15 2:21, Jason Haar пишет: > On 01/09/15 02:59, Shane King wrote: >> Accessing via the browser may work but the sync clients that sit in >> the system tray use certifica

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 But everything will very secure, is it? :) 01.09.15 2:21, Jason Haar пишет: > On 01/09/15 02:59, Shane King wrote: >> Accessing via the browser may work but the sync clients that sit in >> the system tray use certificate pinning I believe.

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Aha. And future of caching software too. With total HTTPS migration. 01.09.15 2:21, Jason Haar пишет: > On 01/09/15 02:59, Shane King wrote: >> Accessing via the browser may work but the sync clients that sit in >> the system tray use certificate

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Jason Haar
On 01/09/15 02:59, Shane King wrote: > Accessing via the browser may work but the sync clients that sit in > the system tray use certificate pinning I believe. So if certificate > pinning is being used, ssl bumping will not work. You will see an > alert message in the pcap followed by a connection

Re: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Shane King
message From: Stanford Prescott Date: 8/31/2015 07:34 (GMT-07:00) To: squid-users Subject: [squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled We have users of Squid 3.5.x with SSLBump enabled complaining about their DropBox and GoogleDrive apps not conne

[squid-users] Dropbox and GoogleDrive apps won't connect with SSLBump enabled

2015-08-31 Thread Stanford Prescott
We have users of Squid 3.5.x with SSLBump enabled complaining about their DropBox and GoogleDrive apps not connecting. We are assuming this is related to the fact that these apps use HTTPS but they are not part of any of the browsers, therefor these apps do not have the sefl-signed certificate inst