Unexpected PKI Behavior With CONNECT to Sites that Have HTTPS Inspection Disabled, Client Trust Not Used

Steven Smith <[email protected]> Thu, 14 Oct 2021 20:35:24 -0400
Newsgroups gmane.comp.web.privoxy.user
Message-ID <[email protected]>
I observe this unexpected behavior with Privoxy’s HTTP Inspection and would like to confirm before I submit a tracker issue at https://sourceforge.net/p/ijbswa/bugs/ <https://sourceforge.net/p/ijbswa/bugs/>.

When I disable https-inspection for certain websites, e.g.

> # No HTTPS Inspection on these websites
> {-https-inspection}
> .apple.com
> .icloud.com


I observe that clients attempting a CONNECT to these sites through Privoxy fail with TLS errors if the destination’s Root CA is not included in Privoxy’s trustedCAs.pem.

I believe that sites that match the -https-inspection rule should use the client’s chain of trust, not Privoxy’s trustedCAs.pem.

_______________________________________________
Privoxy-users mailing list
[email protected]
https://lists.privoxy.org/mailman/listinfo/privoxy-users