Unexpected PKI Behavior With CONNECT to Sites that Have HTTPS Inspection Disabled, Client Trust Not Used
Steven Smith <[email protected]> Thu, 14 Oct 2021 20:35:24 -0400
| Newsgroups | gmane.comp.web.privoxy.user |
|---|---|
| Message-ID | <[email protected]> |
I observe this unexpected behavior with Privoxy’s HTTP Inspection and would like to confirm before I submit a tracker issue at https://sourceforge.net/p/ijbswa/bugs/ <https://sourceforge.net/p/ijbswa/bugs/>.
When I disable https-inspection for certain websites, e.g.
> # No HTTPS Inspection on these websites
> {-https-inspection}
> .apple.com
> .icloud.com
I observe that clients attempting a CONNECT to these sites through Privoxy fail with TLS errors if the destination’s Root CA is not included in Privoxy’s trustedCAs.pem.
I believe that sites that match the -https-inspection rule should use the client’s chain of trust, not Privoxy’s trustedCAs.pem.
_______________________________________________
Privoxy-users mailing list
[email protected]
https://lists.privoxy.org/mailman/listinfo/privoxy-users