Re: TLS Pool could add HTTPS to Privoxy

Rick van Rein <[email protected]> Fri, 25 Nov 2016 10:58:51 +0100
Newsgroups gmane.comp.web.privoxy.devel
Message-ID <[email protected]>
Hello Fabian & Privoxy Developers,

A while back, we talked about adding TLS to Privoxy through my TLS Pool
daemon.  If this is still of interest to Privoxy then it may be good to
know that funding for such things is currently available;I learnt that
NLnet is currently quite interested in TLS-related project inquiries,
and you might be able to collect some independent funding for such an
enhancement.

https://nlnet.nl/news/2016/20161201-call-en.html

I don't know if you had already seen this, but I wanted to make sure
you'd seen it.  The deadline for a project request would be December
1st; it is a low-threshold funding process aimed specifically at open
source projects.

FWIW, the TLS Pool has a facility for "on the fly" signing with a
signing cert that could be signed under a root cert installed by the
remote party.  Packaging is currently in progress.


Cheers,
-Rick
 


Fabian Keil wrote:
> Rick van Rein <[email protected]> wrote:
>
>> FWIW, the TLS Pool now has a demonstration HTTPS_PROXY that
>> shows how easy it is to setup TLS in an intervening proxy.
>> Browsers still seem to be missing flags or certificate attributes,
>> but that's trivial stuff; the fundamental interaction works like a charm.
>>
>> https://github.com/arpa2/tlspool/blob/master/tool/https_proxy.py
>
> Interesting.
>
>> This is Python; the C parallel is similiar.  If you guys/girls are
>> interested to integrate this form of TLS into Privoxy, then talk to me!
>
> FYI, I'm thinking about trying to raise some funding to work on TODO
> list item #16 ("Filter SSL encrypted content as well") within the next
> months.
>
> I'm not sure if using TLS pool is the best option, but I'll certainly
> look at it.
>
> Fabian

------------------------------------------------------------------------------