Re: TLS Pool could add HTTPS to Privoxy

Fabian Keil <[email protected]> Sat, 12 Dec 2015 12:57:39 +0100
Newsgroups gmane.comp.web.privoxy.devel
Message-ID <[email protected]>
--===============6668695703899471237==
Content-Type: multipart/signed; micalg=pgp-sha256;
	boundary="Sig_/D888b7AET_74lEQLKIOVDVW";
	protocol="application/pgp-signature"

--Sig_/D888b7AET_74lEQLKIOVDVW
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

Rick van Rein <[email protected]> wrote:

> On your TODO list I noticed item #16 on support of HTTPS.  May I propose
> 99% of the solution?
>=20
> I'm working on a TLS Pool daemon, which concentrates all the sensitive
> handling of credentials in a process separate from the application
> logic.  This process is initiated by passing sockets over a
> POSIX-standard mechanism to the daemon, and have the daemon handle
> handshaking, encryption and decryption.

Interesting.
=20
> Privoxy could be a plaintext filter in between an upstream and
> downstream HTTPS connection.  Downstream (to the client/browser) there
> is a need to add a certificate on-the-fly, signed under a root cert that
> the client would need to accept.  This on-the-fly certification has been
> specified for the TLS Pool and will be implemented soon.
>=20
> Would this be a good solution for Privoxy?

Without additional information that's hard to tell.

Are you proposing to provide patches or that other people write them?

I briefly looked at the tlspool repository and it's not obvious to me
that it's free software. Where and what is the license?

Fabian

--Sig_/D888b7AET_74lEQLKIOVDVW
Content-Type: application/pgp-signature
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJWbAu1AAoJEGkYIpGLojccGpYQAI4HxOowIkXGfNhHRd0MNFIa
2HUm8c1H4/f6qEmhrq+sBJQP4whqKqxWCaMxFz+oJTa5sxAzwBzqp6z/gaqBNF3A
gHCn5Zafhn/p9XqEkmmnql8/lb24ZxesPhRB0firXOXyqU4tJTvFZAYIEcEpEULi
18eYjR1MHUgJ51Goq4W+Jtt4++hDx++Q7vM4mYelUM7tt+lUuIqyvamrXa3gUWxK
zRdO+hCJED45IgpwXrzHYMDYcIoZ6s+K4a1XrabUk4jH1RMUYMjMQpEuQHlYRu7c
7shDQ5E88IwteUkWC9cCBZv6d3Y66UbjAiprFgdj3fDCsZat1wGiY7jRNR1JZPMm
wQJobVCg/2KFulo4/4CCBDFbCz+/wF8iMnKsRTvz2uPrHVw3/KTuCzDG4iIdLmCK
+Zwgd9xjVp534ZCvbfl75GN3U2GAptSQn3wG7xQJBxxruVIMEKnTzn3zD2uzX+B/
pDGPTnAywotkGBpEgTxHsM3wlg+hgtufNUXqEW2TTzgP/ESnwYZWsXEUWagTKkWC
dwr30EBECW0wev8tpoFP/f0CmiY/cVvsLNzF4mPkcnXG48RuL3lzGYFwd+RKKdCE
QfIeKTcG4bAEjxk9E3FABxZNAtzuraHBjFaEkcWBaDxq385BCf+gM+A1wuXsFjve
7naJ4ysRF7Y5m4WHqUMS
=BXmu
-----END PGP SIGNATURE-----

--Sig_/D888b7AET_74lEQLKIOVDVW--


--===============6668695703899471237==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============6668695703899471237==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ijbswa-developers mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/ijbswa-developers

--===============6668695703899471237==--