Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.400 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-21-2008, 02:03 AM
Junior Member
 
Join Date: May 2006
Posts: 17
Default [NOTABUG] [7.350] Certificate error when i browse all HTTPS sites

Anytime I browse an HTTPS site when the HTTPS scanning is on I get the "There is a problem with this sites security certificate" error. Attached is a screenshot showing this in greater detail.
Attached Images
File Type: jpg error.jpg (64.6 KB, 26 views)
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #2 (permalink)  
Old 11-21-2008, 07:23 AM
Senior Member
 
Join Date: Nov 2008
Posts: 174
Default

You have to download the CA-Certificate from the ASG into your browser first. This means you have trust the ASG so it can act as "man-in-the-middle".
  #3 (permalink)  
Old 11-21-2008, 08:00 AM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,172
Default

To "repair" the chain of trust when using HTTPS scanning, the client browser must trust the "Signing CA" of the proxy. This CA can be managed at "HTTP/S Proxy".

Three options are available to get the public "Signing CA" certificate installed into the client browsers (or in the case of IE, Window's certificate management):

a) Have clients visit the URL "http://passthrough.fw-notify.net/cacert.pem". This will trigger certificate installation. The process varies from browser to browser.

b) Download the "Signing CA" in PEM format in WebAdmin (HTTP/S Proxy -> HTTPS CAs), then distribute it to clients using AD group policies (good for MS shops).

c) Have clients visit the End User Portal. It has a new menu entry "HTTPS proxy" which features a single button to install the "Signing CA".
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #4 (permalink)  
Old 11-21-2008, 01:52 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,065
Default

Yeah, I tried it... still have problems, but Tom has a PM with the details... may be a bug with something other than the certificate itself... good to know about the end-user portal option.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #5 (permalink)  
Old 11-22-2008, 09:17 PM
Senior Member
 
Join Date: Sep 2007
Posts: 117
Default

So is this not working properly? When I tried this procedure it seemed to work. The issue is that after I do it I can no longer get back into the webadmin while https proxy is on and I use the proxy. I keep getting this.

(Error code: ssl_error_bad_cert_domain

I accept the cert but can't login into the webadmin. I than have to turn the proxy off on the browser to get into webadmin.
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:33 PM.

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.