Diladele Web Safety will export the self signed certificate as myca.der and you can import that as a root cert into firefox and chrome. Browsing seems to work with filtering, but this is an obnoxious workaround considering that the certificate that HSTS trusts is my self signed one now. Why aren't certificates set up in such a way that the proxy decrypts and creates a new connection where you get both certs, the original being I guess an intermediate cert? I suppose a self signed cert is the only option considering that I'm on a dynamic Spectrum cable IP.

Quoting mich...@robinson-west.com:

What is firefox complaining about that I can't have an exception for http strict transport security with Google? I'm aware that I'm using diladele Web Safety and I'm aware that I'm decrypting and replacing site foo cert with my own cert,
but I don't know any other way to effectively filter.

 -- Michael C. Robinson
_______________________________________________
PLUG mailing list
PLUG@pdxlinux.org
http://lists.pdxlinux.org/mailman/listinfo/plug
_______________________________________________
PLUG mailing list
PLUG@pdxlinux.org
http://lists.pdxlinux.org/mailman/listinfo/plug
  • [PLUG] HSTS michael
    • Re: [PLUG] HSTS Michael C Robinson

Reply via email to