Re: TLS Pool could add HTTPS to Privoxy
Fabian Keil <[email protected]> Sat, 12 Dec 2015 12:57:39 +0100
| Newsgroups | gmane.comp.web.privoxy.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============6668695703899471237== Content-Type: multipart/signed; micalg=pgp-sha256; boundary="Sig_/D888b7AET_74lEQLKIOVDVW"; protocol="application/pgp-signature" --Sig_/D888b7AET_74lEQLKIOVDVW Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Rick van Rein <[email protected]> wrote: > On your TODO list I noticed item #16 on support of HTTPS. May I propose > 99% of the solution? >=20 > I'm working on a TLS Pool daemon, which concentrates all the sensitive > handling of credentials in a process separate from the application > logic. This process is initiated by passing sockets over a > POSIX-standard mechanism to the daemon, and have the daemon handle > handshaking, encryption and decryption. Interesting. =20 > Privoxy could be a plaintext filter in between an upstream and > downstream HTTPS connection. Downstream (to the client/browser) there > is a need to add a certificate on-the-fly, signed under a root cert that > the client would need to accept. This on-the-fly certification has been > specified for the TLS Pool and will be implemented soon. >=20 > Would this be a good solution for Privoxy? Without additional information that's hard to tell. Are you proposing to provide patches or that other people write them? I briefly looked at the tlspool repository and it's not obvious to me that it's free software. Where and what is the license? Fabian --Sig_/D888b7AET_74lEQLKIOVDVW Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJWbAu1AAoJEGkYIpGLojccGpYQAI4HxOowIkXGfNhHRd0MNFIa 2HUm8c1H4/f6qEmhrq+sBJQP4whqKqxWCaMxFz+oJTa5sxAzwBzqp6z/gaqBNF3A gHCn5Zafhn/p9XqEkmmnql8/lb24ZxesPhRB0firXOXyqU4tJTvFZAYIEcEpEULi 18eYjR1MHUgJ51Goq4W+Jtt4++hDx++Q7vM4mYelUM7tt+lUuIqyvamrXa3gUWxK zRdO+hCJED45IgpwXrzHYMDYcIoZ6s+K4a1XrabUk4jH1RMUYMjMQpEuQHlYRu7c 7shDQ5E88IwteUkWC9cCBZv6d3Y66UbjAiprFgdj3fDCsZat1wGiY7jRNR1JZPMm wQJobVCg/2KFulo4/4CCBDFbCz+/wF8iMnKsRTvz2uPrHVw3/KTuCzDG4iIdLmCK +Zwgd9xjVp534ZCvbfl75GN3U2GAptSQn3wG7xQJBxxruVIMEKnTzn3zD2uzX+B/ pDGPTnAywotkGBpEgTxHsM3wlg+hgtufNUXqEW2TTzgP/ESnwYZWsXEUWagTKkWC dwr30EBECW0wev8tpoFP/f0CmiY/cVvsLNzF4mPkcnXG48RuL3lzGYFwd+RKKdCE QfIeKTcG4bAEjxk9E3FABxZNAtzuraHBjFaEkcWBaDxq385BCf+gM+A1wuXsFjve 7naJ4ysRF7Y5m4WHqUMS =BXmu -----END PGP SIGNATURE----- --Sig_/D888b7AET_74lEQLKIOVDVW-- --===============6668695703899471237== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ --===============6668695703899471237== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ijbswa-developers mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/ijbswa-developers --===============6668695703899471237==--